|
Yeah, At offset 54401 You can see the following bytes: 60 E9 DC 05 00. So, You've correctly identified AsProtect (version 1.1 precisely). But... But after dumping the first protector we can see it's still "PeEncrypt'ed" (by JunkCode, ver 4.0 -the latest as I suppose). As You wrote, the exe runs fine but NOTICE IT'S NOT FULLY UNPROTECTED. Well, this is a freaky protection. With XP/NT/2000 You could easily run ANY debuger and the encryption is the simplest I've ever seen... bla bla.... Ok. hope that helped You at least a little bit.
Greetings.
|