View Single Post
  #3  
Old 10-11-2015, 00:45
giv's Avatar
giv giv is offline
VIP
 
Join Date: Jan 2011
Location: Romania
Posts: 1,663
Rept. Given: 803
Rept. Rcvd 1,283 Times in 561 Posts
Thanks Given: 228
Thanks Rcvd at 567 Times in 241 Posts
giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299
So from your picture i see that the differences come from the MZ header area (1), Section names (2), some author removed (3).
If the unpack is done correct the resources should be there and they can be manipulated except if a resource protection is used (encrypted or placed outside the main Virtual Space of the executable - in case of some protectors).
Edit:
Is a simple file to unpack and the file resources can be altered also. The OEP is a little bit lower than the end of the packer stub.
Code:
0041005E >  6A 00           PUSH 0x0
00410060    E8 7BFC0100     CALL super_pi.0042FCE0
Just see unpacked and modifyed file in attach.
See the "About" menu.

Edit 2.
I get the kkruchy homepage and grab the packer:
Quote:
http://www.farbrausch.de/~fg/kkrunchy/
Here is the packer itself unpacked.
Quote:
http://www37.zippyshare.com/v/l95rOKtU/file.html
The packer it have some nice features like import protection, OEP tricks, antidumps...
The unpacked file must be corrected in the size of sections . You can do that by yourself.
Attached Files
File Type: rar super_pi_mod_dump_SCY.rar (41.0 KB, 9 views)

Last edited by giv; 10-11-2015 at 01:32.
Reply With Quote
The Following 2 Users Say Thank You to giv For This Useful Post:
niculaita (10-11-2015), trodas (10-11-2015)