2 ms·
It's very common for malware (or other code that doesn't want to be reverse engineered) to be decrypting itself in the that initialization loop to generate the
by chas 14y ago
It's very common for malware (or other code that doesn't want to be reverse engineered) to be decrypting itself in the that initialization loop to generate the code that is jumped to. It is also very common for malware to use exception handling as control flow, which could also explain a nonsense jump.
- jiggy2011 14y agoThat certainly makes sense, I wonder if it is encrypted using any proper scheme or something simple like XOR? If it is strong encryption I suppose the thing to do would be to capture the key in memory, but that would require more patience than I have.
- Sapient 14y agoUsually it doesn't matter, you just let the exe decrypt itself, then grab the decrypted code and rebuild the PE with it.