Exetools  

Go Back   Exetools > General > General Discussion

Notices

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #1  
Old 05-29-2005, 09:20
D-Jester's Avatar
D-Jester D-Jester is offline
VIP
 
Join Date: Nov 2003
Location: Ohio, USA
Posts: 269
Rept. Given: 39
Rept. Rcvd 61 Times in 41 Posts
Thanks Given: 0
Thanks Rcvd at 4 Times in 4 Posts
D-Jester Reputation: 61
Question Execryptor...WTF?

I ran accross this program while searching for ringtones for my cell.
Its a flash utility for some mobile phones.
Since its shareware I downloaded it for a "closer inspection."

PEiD identifies it as UPX, but upon inspection of the section names and upacking code this is clearly not UPX.

I assume the real packer has been obfuscated by DotFix Fakesigner.

It is able to detect Ollydbg during unpacking somehow (Even Using Teeyaroot's Invisible Plugin). Program uses alot of SEH:

LOCK INT3
INT3
Single Step
Etc...

when Olly is detected the program crashes itself.

If the program is running (not under a debugger) and you try to load Olly, it terminates Olly (WM_TIMER message sent every second).

I haven't come accross this protector before (maybe a home brew?)
Can anyone identify the real packer?

Many thanks if anyone can answer that question.

[URL REMOVED BECAUSE TARGET WAS IDENTIFIED]
__________________
Even as darkness envelops and consumes us, wrapping around our personal worlds like the hand that grips around our necks and suffocates us, we must realize that life really is beautiful and the shadows of despair will scurry away like the fleeting roaches before the light.

Last edited by D-Jester; 05-31-2005 at 09:33.
Reply With Quote
 


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 00:41.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )