Detect-It-Easy/db/PE/XComp.2.sg
2014-06-01 23:42:39 +02:00

22 lines
637 B
Text

// DIE's signature file
init("packer","XComp");
function detect(bShowType,bShowVersion,bShowOptions)
{
if(PE.getNumberOfImports()==1
&&PE.getNumberOfImportThunks(0)==5
&&PE.getImportFunctionName(0,0)=="GetProcAddress"
&&PE.getImportFunctionName(0,1)=="LoadLibraryA"
&&PE.getImportFunctionName(0,2)=="VirtualAlloc"
&&PE.getImportFunctionName(0,3)=="VirtualFree"
&&PE.getImportFunctionName(0,4)=="VirtualProtect")
{
if(PE.compareEP("68........9c60e8$$$$$$$$e8$$$$$$$$5b5d833b00"))
{
bDetected=1;
}
}
return result(bShowType,bShowVersion,bShowOptions);
}