Thanks for posting PEScrambler <http://pauldotcom.com/PEScrambler_v0_1.zip>guys, I was one of the guys asking for it. I've locked the slides for my anti-forensics class this Saturday, but I'll try to remember to mention this tool. That said, I'm not sure it's working right. For example, as a test I do: PEScrambler.exe -i hfs.exe -o x.exe
but checking the hashes of x and hfs, it seems x is just an exact copy. Any ideas? Thanks, Adrian
_______________________________________________ Pauldotcom mailing list [email protected] http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom Main Web Site: http://pauldotcom.com
