Exetools

Exetools (https://forum.exetools.com/index.php)
-   General Discussion (https://forum.exetools.com/forumdisplay.php?f=2)
-   -   ACProtector (https://forum.exetools.com/showthread.php?t=3742)

jonwil 03-25-2004 22:07

ACProtector
 
Is there a way to unpack this? (e.g. a generic unpacker?)
How difficult is it?
What about programs like ProcDump, can they dump this?

dyn!o 03-25-2004 23:16

ACProtect
 
Of course it is and was done, several times - manually.

About difficulty - it's medium hard. In theory very similar to AsProtect.

About dumping - you can dump it by yourself but then you need to rebuild import table (manually) and jumps to perplex.

Good luck,
dyn!o

Shub-Nigurrath 03-25-2004 23:35

Hi,
a newbie question, is there any good tut around for doing such a thing manually? I digged somewhere but with no luck.

TIA

Jay 03-26-2004 00:09

waste of time
 
unpacking is a bit of a pointless exercise, all the apps I've seen protected with it are function limited and you are not going to enable them (well I don't know of anyone that has succeeded) you might just as well stick with EVACleaner. If you are set on unpacking, lownoise released a plugin (search the forum) for ollydb may be of help.

MrAnonymous 03-26-2004 04:09

If there function limited they most likely use encrypted sections, in which case your right theres nothing you can do about that without a real key on hand. Only app I use thats ACProtect is UltraFXP, and DiGERATi did a very good job on the loader with it functions great.

WhoCares 03-26-2004 10:51

The anti-debug trick of ACProtect is INT3/INT1 etc., easy to bypass.

The Import-Table-Destroy scheme of ACProtect is just like TELock, so we can recover IT/IAT without ReVirgin/ImpREC.

The stolen bytes of ACProtect needs patience to recover.

As MrAnonymous said, code-snippet-encryption needs a real key to decrypt and there may be too many snippets encrypted. crazy.

britedream 03-26-2004 15:06

the stolen bytes for acprotect perior to 1.20 is easy to find, trace after int3, when you stop at the code section look in the trace for ebp==esp, you will find the stolen and the address of your oep shown in trace as eax value.but 1.20 and up is different.

Shub-Nigurrath 03-26-2004 16:38

The strange think is that this protector seemed to not obtain attention..no one of the tools around support unacprotecting..or am I wrong?

britedream 03-26-2004 19:27

I think this is due to few programs protected with it.


All times are GMT +8. The time now is 03:24.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX