HelpPacking DLL In Executable

Posts 1–15 of 23 · Page 1 of 2
Packing DLL In Executable
Hello guys.
I know it's possible to pack a DLL file into an EXE file, just not sure how to do it and what I need.

The exe file is an injector, and I want it to inject the DLL.
I need to pack it the binary way. So when I want to retrieve it I wouldn't have problems.
And also because I don't have the DLL source code.
VC++ 2010 express ships without a resource editor (which is what you need.) You'll need to find a third-party resource editor:
ResEdit Resource Editor - free resource editor for Win32

Once you do, it will generate a resource script (.rc). When you compile it will generate a resource header which you can include in to your source files (the header just defines the IDs for all the resources you include). You'll need to use the resource IDs to find the resource using the windows resource APIs found here:
Resource Functions

Try to work it out yourself, if you can't, just say and I will try and figure it out for you (it looks pretty straight forward though.) I haven't done this yet with the latest version of visual studios express edition.
You can also use a byte array.
Unless you want to extract it later to the disk you wont be able to load it from memory with any common api's. You will have to make your own PE Loader to map the dll into the process ( resolve sections, load dependencies, TLS callbacks, etc... ) really a pain in the ass.
I don't have the VC++ 2010 express edition, I have the professional one. I don't know where to edit the resource code, I have the already made templates which are adding icon or changing file's version etc.
EDIT: found out how to edit it.

The main reason for doing this is TO NOT extract the DLL to the disk, so this way it won't be leechable. But I guess it's difficult to do so?

I found this on the web:
http://stackoverflow.com/questions/9...l-in-mfc-c-exe

But does this make the DLL on the hard disk?
Cause when I try, it makes a DLL who weighs 0KB.

EDIT: I managed to make it work, but this is not what I'm looking for, as I said above, I don't want it to write the file to the disk.

EDIT: Maybe if there is some way to remove the DLL after I inject? I can't do it normally cause it says it's opened by the process.
Quote Originally Posted by Jabberwock View Post
I don't have the VC++ 2010 express edition, I have the professional one. I don't know where to edit the resource code, I have the already made templates which are adding icon or changing file's version etc.
EDIT: found out how to edit it.

The main reason for doing this is TO NOT extract the DLL to the disk, so this way it won't be leechable. But I guess it's difficult to do so?

I found this on the web:
embed DLL in MFC C++ EXE? - Stack Overflow

But does this make the DLL on the hard disk?
Cause when I try, it makes a DLL who weighs 0KB.

EDIT: I managed to make it work, but this is not what I'm looking for, as I said above, I don't want it to write the file to the disk.

EDIT: Maybe if there is some way to remove the DLL after I inject? I can't do it normally cause it says it's opened by the process.
As stupid as this sounds, you can't use the windows PE loader if you don't write it to disk in some way or form. Well, maybe if you do one of the following:
1) Use a named pipe and try and detour the PE loader's checks for a path on disk rather than a path to a named pipe.
2) Catch a call to CreateFile and return a handle to your named pipe instead of whatever file it would otherwise open. (Might not work, this is a slippery slope if you choose this path.)
3) Create your own PE loader (probably your best bet, but ofc it is a bit of work.) Tbh it would probably take you a day or two to get done if you are willing to invest some time.

I would try #2 first :S Then if that doesn't work, go to #3.
Sorry for the nooby question, what does PE loader stands for?

And there isn't a way to just unload the DLL after I inject it so I can delete the DLL?
(Still looking for the easier methods)
Quote Originally Posted by Jabberwock View Post
Sorry for the nooby question, what does PE loader stands for?

And there isn't a way to just unload the DLL after I inject it so I can delete the DLL?
(Still looking for the easier methods)
A PE Loader is the module that sets up an executable (.exe) or dynamically linked library (.dll) or kernel driver (.sys) etc... in memory before it executes. It isn't as simple as copying the file in to memory and executing. Relocations need to occur if the library wasn't loaded at its desired base address (address it was compiled to be loaded at); imports need to be resolved, sections need to be allocated with proper size & permissions etc... It is a lot of work to write your own.

Most anti-viruses will FREAK OUT if you try to use your own PE loader to inject code from memory anyway (a lot of malware used a very similar method to launch an executable from memory before windows 7 & vista.) You can free a library after it has been loaded by using FreeLibrary API.

However, most hacks aren't designed to just be released (well, I'm not sure what the DLL does, so it may or may not work.)
Thanks for the quick reply.

The DLL is designed to create some threads in the process, change some memory addresses and they are in infinity loops.
I guess I can't free the DLL if the script within it is infinity am I right?
Quote Originally Posted by Jabberwock View Post
Thanks for the quick reply.

The DLL is designed to create some threads in the process, change some memory addresses and they are in infinity loops.
I guess I can't free the DLL if the script within it is infinity am I right?
If it is doing anything in that infinite loop, then no, it probably isn't safe to free it. If it installs any detours either, it isn't safe to free it then either.

It probably does install a detour; so you'll have to leave it installed.
About the PE Loader, can you give me a link where I can learn how to do it?
Are you sure I won't need to have the DLL source code to use it?
I've gone through the liberty of writing a PE loader for you, however at the momment it still has a few bugs I will need to pan out (I am going to bed now, but when I wake up I'll take another look at it.) I will post it in the MPGH C++ section when I'm done.

Regards to a tutorial of how to write one, you're probably better off looking reading the win internals docs on the PE file format or going through MSDN. The PE file format is poorly documented by Microsoft (some whole structures defined in the winnt header are missing a description in the MSDN doc.) However, they're usually documented if you look at reverse engineering websites.
Quote Originally Posted by radnomguywfq3 View Post
The PE file format is poorly documented by Microsoft (some whole structures defined in the winnt header are missing a description in the MSDN doc.) However, they're usually documented if you look at reverse engineering websites.
Most of it is really well documented (the 98-odd page PE/COFF specification document available from microsoft details a hell of a lot of the PE). I managed to write a Manual Map (Pe loader) function of my own using .NET, but never got around to properly porting it to C++. It sure is fun dealing with dynamic linkage to Windows SxS modules!
Quote Originally Posted by radnomguywfq3 View Post
I've gone through the liberty of writing a PE loader for you, however at the momment it still has a few bugs I will need to pan out (I am going to bed now, but when I wake up I'll take another look at it.) I will post it in the MPGH C++ section when I'm done.

Regards to a tutorial of how to write one, you're probably better off looking reading the win internals docs on the PE file format or going through MSDN. The PE file format is poorly documented by Microsoft (some whole structures defined in the winnt header are missing a description in the MSDN doc.) However, they're usually documented if you look at reverse engineering websites.
Are you for real? Why would you do that? I mean you said it yourself it is hard to code...

"You must spread some Reputation around before giving it to Jetamay again."

If you are going to release it then I'm going to release the signature scanning I built for AVA, as a gratitude for this community. I'll release it at AVA's Source Code section.
Quote Originally Posted by Jason View Post


Most of it is really well documented (the 98-odd page PE/COFF specification document available from microsoft details a hell of a lot of the PE). I managed to write a Manual Map (Pe loader) function of my own using .NET, but never got around to properly porting it to C++. It sure is fun dealing with dynamic linkage to Windows SxS modules!
Lies, especially about code relocation. There are so many undocumented code relocation types and even more data structures. I had to go around to tons of windows REing communities to figure out how some of these structures worked.

At least relative to how MSDN documents their other APIs, the documentation of the PE format is poor.
create a resource file and add the following:

resource_type resource_id resource_path

then later, use something like this code:
Using Resources
but instead of updating, just write it to a file.
Posts 1–15 of 23 · Page 1 of 2

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us