![]() |
|
|
|
#1
|
|||
|
|||
|
To Crk:
Hello man, Quote:
Regards nimda2k3 |
|
#2
|
||||
|
||||
|
maybe im talking out of my ass here but...
>most important parts on execryptor are crypted.. it decrypts those parts
>when neccesary and needs to use it.. so you most decrypt each crypted >part by dumping from memory Seems to me the same kind of schema as used by ms to protect the components of os activation. What i did was to analyze how exactly the info for each encrypted part is stored and how it is decrypted by protector. Then write your own program to find all those parts in the .exe, decrypt them the same way, save back to .exe. I think much less work than messing around with ollydbg bpx'ing around and dumping memory 10000 times:P |
|
#3
|
|||
|
|||
|
sorry... guys... but...
I think you are all wrong. IF they do not lie at strongbit.com, there is no "decryption" at all. code is morphed one time, then the garbage runs - and it does NOT decrypts anything, but just does the same (among some side effects) that the original code did. so I am afraid that you can unpack it - but you will only increase the size, you won't make it any more readable. so that - unless you have a lookup table along with some quite complicated maths - you must trace/analyse/patch the garbage; disassembling it just makes no real sense. |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| EXECryptor | omega_red | General Discussion | 12 | 11-02-2005 08:34 |