Jump to content

Recommended Posts

Posted

I have and old program and I tried to reshack it but it says it's compressed by an EXE Compressor... How can I see with which one was it compressed (because there are dozen of them)?

Please help ( if you can ) ?


Posted (edited)

PEID, or my favorite PE Tools

if you use PE Tools, go to the Tools menu and choose PE Sniffer.

after you figure out what packed it, you'll need to find a way to unpack it.

if you're lucky it's just UPXed.

Edited by #rootworm
Posted (edited)

It's not UPXed I tested that. Where in PE Tools can I see the compression?

[edit] I found out it was packed by ASPack v2.15 :D Terror [/edit]

Edited by TM0d
Posted (edited)

i've had some pretty good luck with Quick Unpack 1.03, you might give it a try.

the newest version is actually 1.05 so it's hard to track down the 1.03 version, but the older one is much more stable.

the only downside is that it hardly ever finds the correct OEP, so you'll have to figure that out yourself.

(it's pretty much the same OEP detection as PE Tools, so don't rely on that either)

Edited by #rootworm

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...