Understanding what API-functions are used in EXECryptor by kioresk - نسخة قابلة للطباعة +- الفريق العربي للهندسة العكسية (https://www.at4re.net/f) +-- قسم : ENGLISH FORUM (https://www.at4re.net/f/forum-6.html) +--- قسم : General Discussion (https://www.at4re.net/f/forum-13.html) +--- الموضوع : Understanding what API-functions are used in EXECryptor by kioresk (/thread-390.html) |
Understanding what API-functions are used in EXECryptor by kioresk - M!X0R - 12-11-2018 Posted By dj-siba 20-10-2007, 03:33 PM
إقتباس :Understanding what API-functions are used in EXECryptor by kioresk إقتباس :Looking what’s going on in this procedure, we’ll found out that there is some API function used. But the problem is that EXECryptor uses hashs (created from API-function’s names) insead of using API-functions directly. Let’s think that we don’t know how to detect running driver and what is this function. إقتباس :So, our hash is 0EF9F7D01 and we need to find out what is the name of used function - no problem, we open list of API-functions and hashs and search for 0EF9F7D01. إقتباس :Aha!, it’s CreateFileA function (just as you already thought). Ok, let’s rename that function and look what we have in result: إقتباس :Nice, huh. إقتباس :Download it from
إقتباس :Hope, it will be usefull for you
|