Quote:
Originally Posted by 168Atomica
what i did is that i used the unpacked cabal file to copy the pe header.
as to your question, imprec will only recognize that you entered a "possible" oep. but i do not depend on imprec. as i have said in majority of my posts in this thread, OEP looks similar with many applications. all you need to do is recognize it.
try to pack and unpack many windows utilities using yoda packer and you will know what i mean. (notepad, calc, char map) if you cannot unpack what you packed... youre goin nowhere...
|
One of the most intelligent statements so far, and of course being able to understand the basic practices of looking around, comparing and trial&error when overcoming problems, just thought id throw in little upload in that may help some people. Also, Molebox should be removed, and yes Atomics statement of not needing to repack is correct, hence why questions relating to repacking where ignored xD
LordPE should be used, ill leave your imaginations to deduce google for plugins is a good idea ;) learn to read the flow of whats going on in the exe, the stack for example is full of useful information at times...
Guide of intrest for people:
[Only registered and activated users can see links. Click Here To Register...]
[Only registered and activated users can see links. Click Here To Register...]
[Only registered and activated users can see links. Click Here To Register...]