40Hex Number 6 Volume 2 Issue 2 File 004 NOLITE v1.0 By DecimatoR of PHALCON/SKISM PD War Collection Program 1 This program will remove the PKLITE header from .EXE and .COM for two reasons. A) To make the file un-decompressable, which dosen't mean much if you have the registered version of PKLITE. B) More importantly, makes the PKLITEd file unscannable to virus scanners, such as McAfees' Virus Scan etc... Does this by overwriting the header with random text from memory. Parameters are simple: NOLITE filename.ext (Extension MUST be included!) Will remove the header from PKLITEd files. It will not remove the header if it is not a genuine PKLITE file. Note: This program is based on PKSMASH, which was written by Hellraiser. Unfortunately, a bug surfaced in that program, which caused it to lock up sometimes. So I wrote this to replace PKSMASH, and stole HR's dox. ---DecimatoR Cut out the following code, call it NOLITE.HEX, then DEBUG < NOLITE.HEX ------------- Rip here ---------- Slice here ---------- Mince Here ---------- n nolite.com e 0100 4D 5A 53 00 03 00 00 00 09 00 FB 00 FF FF 46 00 e 0110 00 04 00 00 00 01 F0 FF 50 00 00 00 03 01 9A 07 e 0120 8A 15 20 83 C4 06 B8 0D 00 50 B8 01 00 50 9A 2F e 0130 89 15 20 83 C4 04 C7 06 38 6B 00 00 8B E5 5D C3 e 0140 55 8B EC 83 EC 02 FF 36 16 35 E8 C4 19 83 C4 00 e 0150 7A 01 03 00 01 00 20 00 09 00 FF FF 00 00 00 00 e 0160 00 00 00 01 00 00 3E 00 00 00 01 00 FB 30 6A 72 e 0170 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e 0180 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e 0190 B8 38 01 BA 3D 00 8C DB 03 D8 3B 1E 02 00 73 1D e 01A0 83 EB 20 FA 8E D3 BC 00 02 FB 83 EB 19 8E C3 53 e 01B0 B9 C3 00 33 FF 57 BE 48 01 FC F3 A5 CB B4 09 BA e 01C0 36 01 CD 21 CD 20 4E 6F 74 20 65 6E 6F 75 67 68 e 01D0 20 6D 65 6D 6F 72 79 24 FD 8C DB 53 83 C3 2D 03 e 01E0 DA BE FE FF 8B FE 8C CD 8B C5 2B EA 8B CA D1 E1 e 01F0 D1 E1 D1 E1 80 EC 10 80 EF 10 8E C0 8E DB F3 A5 e 0200 FC 8E DD 07 06 BF 00 01 33 F6 AD 95 BA 10 00 EB e 0210 2C 90 AD 95 B2 10 EB 35 AD 95 B2 10 EB 36 AD 95 e 0220 B2 10 EB 3B AD 95 B2 10 EB 5D AD 95 B2 10 EB 5E e 0230 AD 95 B2 10 EB 5F AD 95 B2 10 72 08 A4 D1 ED 4A e 0240 74 F4 73 F8 33 C9 33 DB D1 ED 4A 74 C5 D1 D3 D1 e 0250 ED 4A 74 C4 D1 D3 85 DB 74 17 D1 ED 4A 74 BF D1 e 0260 D3 80 FB 06 72 0B D1 ED 4A 75 04 AD 95 B2 10 D1 e 0270 D3 2E 8A 8F 5E 01 80 F9 0A 74 74 33 DB 83 F9 02 e 0280 74 2A D1 ED 4A 74 9D 72 23 D1 ED 4A 74 9C D1 D3 e 0290 D1 ED 4A 74 9B D1 D3 D1 ED 4A 75 04 AD 95 B2 10 e 02A0 D1 D3 80 FB 02 73 15 2E 8A BF 6E 01 AC 8A D8 56 e 02B0 8B F7 2B F3 FA F3 26 A4 FB 5E EB 81 D1 ED 4A 75 e 02C0 04 AD 95 B2 10 D1 D3 80 FB 08 72 DB D1 ED 4A 75 e 02D0 04 AD 95 B2 10 D1 D3 80 FB 17 72 CB D1 ED 4A 75 e 02E0 04 AD 95 B2 10 D1 D3 81 E3 DF 00 86 DF EB BD AC e 02F0 02 C8 80 D5 00 3C FF 75 82 5B 8B EB 83 C3 10 33 e 0300 C0 AC 91 E3 0E AD 03 C3 8E C0 AD 97 26 01 1D E2 e 0310 F9 EB EC AD 03 C3 FA 8E D0 AD 8B E0 FB AD 03 D8 e 0320 53 AD 50 8E C5 8E DD 33 C0 8B D8 8B C8 8B D0 8B e 0330 E8 8B F0 8B F8 CB 03 00 02 0A 04 05 00 00 00 00 e 0340 00 00 06 07 08 09 01 02 00 00 03 04 05 06 00 00 e 0350 00 00 00 00 00 00 07 08 09 0A 0B 0C 0D 00 00 00 e 0360 3A 00 00 F5 01 B8 23 00 8E C0 E8 CF 00 E8 00 00 e 0370 C7 00 83 FA 01 B4 09 BA 5C 00 CD 21 74 0A BA 87 e 0380 55 00 00 0C 09 E9 07 01 33 C9 E8 E7 40 01 00 8B e 0390 D7 B0 02 B4 3D 10 73 03 E9 EE 00 28 40 A3 0C 00 e 03A0 B9 39 51 59 41 83 F9 64 75 39 15 2A CB 2A DD 12 e 03B0 8B 09 A5 1E 1A 01 00 BA 0E 12 3F 28 50 12 80 3E e 03C0 08 50 75 D9 B9 0B B6 52 11 0F 11 BE 07 BF 49 81 e 03D0 38 10 F3 A6 3A 00 74 0C 5A 52 52 8A 5C B0 1A 42 e 03E0 1A EB B3 A2 6A 0A 33 D2 0A 0E 16 95 43 10 59 49 e 03F0 30 27 5B 35 0D B4 40 58 31 91 24 0F 16 5A 0F 72 e 0400 6E A5 1F 35 49 01 09 16 B4 3E 3D 00 40 64 90 8A e 0410 04 3C 20 74 06 3C 09 74 02 3C 0D C3 01 40 27 4A e 0420 01 C3 32 ED 8A 0E 80 00 41 BE 81 01 00 73 4C 01 e 0430 E8 DE FF 75 03 46 E2 F8 51 E3 03 00 A4 FC F3 A4 e 0440 06 1F 59 33 DB E3 0F BE 18 C6 02 85 18 04 C6 04 e 0450 00 43 1C F4 89 1E 29 A1 36 C0 2E E3 0C 3B 0E 00 e 0460 B0 0C 73 06 FC AE 75 FD E2 FB C3 BA FD 21 01 E0 e 0470 B4 4C A0 0B 7E 00 4B 4C 49 54 45 A0 01 20 43 6F e 0480 70 72 2E 47 8B 0D 0A 36 00 4E 4F 5F 28 63 29 20 e 0490 31 39 39 32 20 00 00 44 65 63 69 6D 61 74 6F 52 e 04A0 20 50 48 41 4C 43 4F 00 00 4E 2F 53 4B 49 53 4D e 04B0 0D 24 0A 20 20 52 65 6D 6F 70 42 76 65 73 20 50 e 04C0 93 73 69 67 6E 01 14 2A 75 72 65 20 66 72 6F 6D e 04D0 05 69 A5 0A 6C 1C 2E 52 28 55 73 DC 66 65 3A 20 e 04E0 59 3C 17 A1 4C 27 6D 65 3E 1A 24 1D 3A 05 4E 6F e 04F0 08 40 77 61 55 66 6F 75 00 00 6E 64 20 2D 20 6E e 0500 6F 74 68 69 6E 67 20 64 6F 6E 36 25 65 07 32 45 e 0510 72 5F 72 4B A1 1A 2C 74 81 70 74 20 A0 E0 28 73 e 0520 75 63 63 6C 73 66 75 6C 74 7A 22 53 10 21 AB A4 e 0530 5A 40 4E 72 C6 69 AA 52 44 48 19 74 A0 01 40 79 e 0540 65 64 21 24 FF 01 00 00 01 01 00 00 00 00 00 00 e 0550 00 00 01 1A 1A 1A 1A 1A 1A 1A 1A 1A 1A 1A 1A 1A rcx 055F w q ------------- Rip here ---------- Slice here ---------- Mince Here ---------- Downloaded From P-80 International Information Systems 304-744-2253