Location:
Search - PE Protector
Search list
Description: 原理:对Pe文件的.data节,.text节进行XOR加密,然后将带解密的Loader写入文件头和第一个段的开头之间,修改Entry Point使其指向Loader.
测试用例:使用vc6.0自动生成的mfc对话框应用程序。
参考文献:(1)def源码
(2)黑客调试技术揭秘
(3)yoda s protector源码
Platform: |
Size: 458407 |
Author: 东南 |
Hits:
Description: 原理:对Pe文件的.data节,.text节进行XOR加密,然后将带解密的Loader写入文件头和第一个段的开头之间,修改Entry Point使其指向Loader.
测试用例:使用vc6.0自动生成的mfc对话框应用程序。
参考文献:(1)def源码
(2)黑客调试技术揭秘
(3)yoda s protector源码
Platform: |
Size: 457170 |
Author: 东南 |
Hits:
Description: 原理:对Pe文件的.data节,.text节进行XOR加密,然后将带解密的Loader写入文件头和第一个段的开头之间,修改Entry Point使其指向Loader.
测试用例:使用vc6.0自动生成的mfc对话框应用程序。
参考文献:(1)def源码
(2)黑客调试技术揭秘
(3)yoda s protector源码-Principle: The Pe documents. Data section,. Text section to XOR encryption, and then will take declassified documents Loader write head and the first between the beginning of paragraph, modify Entry Point to point Loader. Test cases: the use of vc6. 0 automatically generated mfc dialog application. References: (1) def source (2) debug technology hackers Secret (3) yoda s protector source
Platform: |
Size: 457728 |
Author: 东南 |
Hits:
Description: 原理:对Pe文件的.data节,.text节进行XOR加密,然后将带解密的Loader写入文件头和第一个段的开头之间,修改Entry Point使其指向Loader.
测试用例:使用vc6.0自动生成的mfc对话框应用程序。
参考文献:(1)def源码
(2)黑客调试技术揭秘
(3)yoda s protector源码-Principle: The Pe documents. Data section,. Text section to XOR encryption, and then will take declassified documents Loader write head and the first between the beginning of paragraph, modify Entry Point to point Loader. Test cases: the use of vc6. 0 automatically generated mfc dialog application. References: (1) def source (2) debug technology hackers Secret (3) yoda s protector source
Platform: |
Size: 456704 |
Author: 东南 |
Hits:
Description: virtual machine protect, best pe protector in the net , allows you to wrap every exported function
Platform: |
Size: 1072128 |
Author: croner |
Hits:
Description: morphine 2.7 delphi source code, is Win32 protector for PE files
Platform: |
Size: 31744 |
Author: UnNamed053 |
Hits:
Description: AMProtector - advanced PE Packer with LZMA compression and strong AMPRNG encryption.
Platform: |
Size: 84992 |
Author: Alexander Myasnikov |
Hits:
Description: 加壳机(vc源码)源码在vc7+xp-sp2下编译通过
原理:对Pe文件的.data节,.text节进行XOR加密,然后将带解密的Loader写入文件头和第一个段的开头之间,修改Entry Point使其指向Loader.
测试用例:使用vc6.0自动生成的mfc对话框应用程序。
参考文献:(1)def源码
(2)黑客调试技术揭秘
(3)yoda s protector源码
存在问题:只对.data节,.text节加密,且其中不能包含Resource,Import Table.....等结构,通用性很差
下图为测试用例的section table和directory table。 工具打包源码。加壳机
试用例.
加壳机源码.
加壳机静态mfc
-Packers machine (vc source) source in vc7+ xp-sp2 compiled by Principle: The Pe file. Data section,. Text section to XOR encryption, decryption of the Loader and then written to a file with the first and the beginning of a paragraph between the modified Entry Point to point Loader. test case: automatically generated using vc6.0 mfc dialog application. References: (1) def source (2) hackers debug Uncovered (3) yoda' s protector Source problem: only. Data section,. Text section of encryption, and which can not contain Resource, Import Table ..... structure of , generic photo shows poor test case under the section table and directory table. Tool Package source. Packers machine trial cases. Packers machine source. Packers machine static mfc
Platform: |
Size: 497664 |
Author: 程光 |
Hits:
Description: It is about PE structure.
And it is about protector
Platform: |
Size: 380928 |
Author: jamesbond49 |
Hits:
Description: 讲述如何创建自己的外壳,采用VC++,简单易懂,是加壳学习的入门教程-Describes how to create your own shell, using VC++, easy to understand, is packed learning Tutorial
Platform: |
Size: 80896 |
Author: cc |
Hits:
Description: exe 文件PE开头保护 加密器 44 文件PE开头保护 加密器-exe file encryption devices to protect the beginning of PE
Platform: |
Size: 242688 |
Author: |
Hits: