Thread: Unknown packer
View Single Post
Old 04-20-2018, 11:58 AM
visions_of_eden visions_of_eden is offline
Join Date: Nov 2010
Posts: 13

Made some progress ,

after partially unkpacking the exe i found that the paker used is non standard and comes from some russian forum member called Dr.Golova . Anybody ever headr about it ?

The exe first decrypts itself by doing repeated XORs mixed with crappy code, then jump to the real packer dinamically created , after fixing relocations and imports .
Reply With Quote