QuickUnpack

From aldeid
Jump to: navigation, search

Description

Quick Unpack is a generic unpacker that facilitates the unpacking process.

Installation

Usage example

Let's take the following malware:

C:\Documents and Settings\malware\Bureau>md5sum windowsxp2.exe
f04cb834ac843ad08a1a5c17e4f67ba3 *windowsxp2.exe

Once you have opened Quick Unpack, click on the "Open file" to select your executable and then click on the ">" icon as follows:

Quickunpack-001.png

There are 2 methods but the first one (Force OEP) should work just fine for our case. Then check the "use force unpacking" option and click "Full unpack".

Quickunpack-002.png

After a short while, you should see following screen:

Quickunpack-003.png

At this stage, Quick Unpack will attempt to automatically fix the PE headers and will save the unpacked executable under the name originalname__.exe if the original file was originalname.exe.

Ssh-img013.png
Warning
Beware that Quick Unpack runs the malware on the machine to be able to unpack it.

Comments

blog comments powered by Disqus