Log in

View Full Version : Trouble Unpacking Netsky-Q FSG 1.0 and UPX 0.80 - 1.24 DLL -> Markus & Laszlo


black_falcon
June 15th, 2011, 20:47
I am trying to unpack Netsky-Q Worm (MD5 Hash :3018e99857f31a59e0777396ae624a8f). PEiD shows the packer as FSG 1.0 -> dulek/xt and the only way that i found to unpack this is a manual unpacking technique by kienmanowa of REA. In this technique we introduce a breakpoint and run this malware sample to that point and use OllyDump to change the Characteristics and Entry Point. But OllyDump is not allowing me to edit the Characteristics. Can anybody help me out with this?

Another problem i face is trying to unpack the same worm (MD5 Hash :0a9ffa57d65083c92e0d3d69b00f2f0d) which is packed with UPX 0.80 - 1.24 DLL -> Markus & Laszlo and i couldn't find a technique to unpack this one.