تقييم الموضوع :
  • 0 أصوات - بمعدل 0
  • 1
  • 2
  • 3
  • 4
  • 5
How to Compare PE of two File?
#6
(11-06-2023, 08:14 PM)mounirsoltan كتب : لقد حاولت استعماله مع هذا البرنامج (Webcam Surveyor) في محاولت كشف الباتش من خلال مقارنة ملفين dll الاصلي للوندوز و الاخر ملف الباتش لكن لم انجح لقد قمت بارفاق ملفات المقارنة مع العلم الملفين غير محميان ربما يستطيع احد عمل شرح فيديو.

I took a quick look into your files, and it seems that the two dlls are completely different
The Original one is written in Pure Basic, while the patched one is written in  C++, which explains the different sizes.
furthermore the patched dll has been written from scratch on focusing to export Specifique functions perhaps to get the software running in a simulated environment.
the comparison is not possible in this case as the files are completely different
patches like that are made after analyzing the behaviour of the program and understanding what the dll will export to the main executable and and write your own dll which returns only the necessary bytes to the main executable
أعضاء أعجبوا بهذه المشاركة : mounirsoltan , rce3033 , KaMaN99


الردود في هذا الموضوع
How to Compare PE of two File? - بواسطة KaMaN99 - 09-06-2023, 08:24 AM
RE: How to Compare PE of two File? - بواسطة SeGNMeNT - 09-06-2023, 09:41 AM
RE: How to Compare PE of two File? - بواسطة KaMaN99 - 09-06-2023, 12:11 PM
RE: How to Compare PE of two File? - بواسطة samoray - 09-06-2023, 01:19 PM
RE: How to Compare PE of two File? - بواسطة mounirsoltan - 11-06-2023, 08:14 PM
RE: How to Compare PE of two File? - بواسطة samoray - 17-06-2023, 09:35 AM
RE: How to Compare PE of two File? - بواسطة mounirsoltan - 17-06-2023, 11:15 AM
RE: How to Compare PE of two File? - بواسطة Cyperior - 17-06-2023, 01:52 PM

التنقل السريع :


يقوم بقرائة الموضوع: بالاضافة الى ( 2 ) ضيف كريم