Flag: Tornado!
Hurricane!
|
|
NsPacK v3.7 |
North Star (LiuXingPing) |
Compressor |
saphex |
January 10 2008 |
|
PE header |
no |
no |
[configurable, default = .nsp] |
N/A
|
|
Nothing special, just a simple compressor.
|
00000000 61 popa
00000001 9D popf
00000002 E9 ?? ?? ?? ?? jmp value |
|
00000000 9C pushf
00000001 60 pusha
00000002 E8 00 00 00 00 call 00000003
00000007 5D pop ebp
00000008 83 ED 07 sub ebp, 7
0000000B 8D ?? ?? ?? ?? ?? lea ecx, [ebp-value]
00000011 80 39 01 cmp byte ptr [ecx], 1
00000014 0F 84 ?? ?? ?? ?? jz value |
|
A easy way to uncompress NsPack using OllyDbg.
At entry point, add a breakpoint in the pusha instruction and
run the application. After it breaks, follow the ESP register
value in dump, add a hardware breakpoint with 4 bytes length
in the first bytes. Then run the application again. When it
breaks, the EIP will be at the transfer command.
Just single step it and EIP will be at the original entry point. |
|
|
|
There are 31,320 total registered users.
|
|