Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 01-13-2005, 00:57
H22H
 
Posts: n/a
Question Hiding protector signature !

Hi,

Can I hide the remove the protector signature from the protected files .. so no one will be able to know which protector I use ?? and for that they have to unpack it manually .

Thanks
Reply With Quote
  #2  
Old 01-13-2005, 02:27
lifewire
 
Posts: n/a
I don't think that there is a general way, it is not something that like "all protectors have a dword at location this and this and this dword is 123 for this protector, 456 for that protector, etc". All have their own characteristics, and different protector identifiers use different characteristics too.
Reply With Quote
  #3  
Old 01-13-2005, 07:25
Kyrios Kyrios is offline
Friend
 
Join Date: Feb 2003
Posts: 48
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
Kyrios Reputation: 0
Morphine ??
Reply With Quote
  #4  
Old 01-13-2005, 08:31
Crudd[RET] Crudd[RET] is offline
Friend
 
Join Date: Aug 2004
Posts: 28
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
Crudd[RET] Reputation: 0
Check out this thread: http://exetools.com/forum/showthread.php?t=6226
Its only a few days old. And dont forget about the search function .
Crudd [RET]
Reply With Quote
  #5  
Old 01-13-2005, 16:16
spokey
 
Posts: n/a
That was indeed the same question as i did ask a few days ago, but like Crudd already said, it aint that easy to just remove the section name with a PE editor because most packers/protecters do use crc check in the protected files, so when you remove the section name you also have to fix the crc.

Some protectors offer you the option to give their section a blank or another name, but most signature detecting tools dont look to the section name but to an internal signature or code patterns. (if i did understand it right)
Reply With Quote
  #6  
Old 01-14-2005, 17:58
Relayer
 
Posts: n/a
EXECryptor 2.x can't detected tools like PEID and can't produce stable signatures in protected exe's
Reply With Quote
  #7  
Old 01-14-2005, 23:16
hinte
 
Posts: n/a
some file identifiers uses a few started bytes form executrable to find out the protector type, if you want to hide this you can manually change the first code (that is hard to do) or you can write own protector , tha's the way too
but now, PE identifilers uses more advanced techniqes to detect the protector..
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
ASPR 2.xx OEP hiding bug KaGra General Discussion 1 08-27-2005 19:52
hiding stuff SLIM SLIM General Discussion 4 01-26-2003 21:04


All times are GMT +8. The time now is 01:12.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )