UPX Packer
Content Leader: Jess Garcia - Last Updated: January 10, 2007
Gral Info
-
UPX: Ultimate Packer for eXecutables
Analysis
-
UPX PE Header has 3 sections:
-
UPX 0
-
UPX 1 - Where the decompressing routine is
-
End of the unpacking routine: JMP ; CALL ; POPAD ; JMP ; DB 00 ...
-
UPX 2 - Where the actual code is