View Single Post
  #1  
Old 01-30-2005, 04:25
crkelbery
 
Posts: n/a
Resources....tools or manually??

I just want to sing a praise for the Resources Tab in Stud_PE. It helped me with an unpacked upx which Resource Hacker was not able to analyze.
I realized that if we want to take a look into the resources, it's recommended using more than one tool, because when Exescope doesn't see a thing, maybe ResHack can help us or ever some other ones...
One more thing: these tools look into the resources section and can show us images like bitmaps that were compiled being RES files, isn't it?

So my question is: What about that images that no resource editor "sees" but that lies inside the exe in its original form: for example, here we have the beginning of a BITMAP whose size is: 4EF6h. If we take HexWorkshop, we copy 4ef6h bytes (look that F6 4E after the BM header) and paste it in image.bmp, we'll be get the original image.
.00408CC0: 6C 74 00 00-F7 4E 00 00-42 4D F6 4E-00 00 00 00 lt �N BM�N
.00408CD0: 00 00 36 00-00 00 28 00-00 00 4F 00-00 00 54 00 6 ( O T
.00408CE0: 00 00 01 00-18 00 00 00-00 00 C0 4E-00 00 12 0B �N
.00408CF0: 00 00 12 0B-00 00 00 00-00 00 00 00-00 00 FF FF ��
.00408D00: FF FF FF FF-FF FF FF FF-FF FF FF FF-FF FF FF FF ����������������
.00408D10: FF FF FF FF-FF FF FF FF-FF FF FF FF-FF FF FF FF ����������������
Reply With Quote