Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 10-11-2015, 00:45
giv's Avatar
giv giv is offline
VIP
 
Join Date: Jan 2011
Location: Romania
Posts: 1,663
Rept. Given: 803
Rept. Rcvd 1,283 Times in 561 Posts
Thanks Given: 228
Thanks Rcvd at 567 Times in 241 Posts
giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299
So from your picture i see that the differences come from the MZ header area (1), Section names (2), some author removed (3).
If the unpack is done correct the resources should be there and they can be manipulated except if a resource protection is used (encrypted or placed outside the main Virtual Space of the executable - in case of some protectors).
Edit:
Is a simple file to unpack and the file resources can be altered also. The OEP is a little bit lower than the end of the packer stub.
Code:
0041005E >  6A 00           PUSH 0x0
00410060    E8 7BFC0100     CALL super_pi.0042FCE0
Just see unpacked and modifyed file in attach.
See the "About" menu.

Edit 2.
I get the kkruchy homepage and grab the packer:
Quote:
http://www.farbrausch.de/~fg/kkrunchy/
Here is the packer itself unpacked.
Quote:
http://www37.zippyshare.com/v/l95rOKtU/file.html
The packer it have some nice features like import protection, OEP tricks, antidumps...
The unpacked file must be corrected in the size of sections . You can do that by yourself.
Attached Files
File Type: rar super_pi_mod_dump_SCY.rar (41.0 KB, 9 views)

Last edited by giv; 10-11-2015 at 01:32.
Reply With Quote
The Following 2 Users Say Thank You to giv For This Useful Post:
niculaita (10-11-2015), trodas (10-11-2015)
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
New Executable Debugger lucky7456969 General Discussion 0 02-24-2004 13:14
Dos executable cAtA General Discussion 3 05-20-2003 08:49


All times are GMT +8. The time now is 21:26.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )