Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That certainly makes sense, I wonder if it is encrypted using any proper scheme or something simple like XOR?

If it is strong encryption I suppose the thing to do would be to capture the key in memory, but that would require more patience than I have.



Usually it doesn't matter, you just let the exe decrypt itself, then grab the decrypted code and rebuild the PE with it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: