21 March 2012


Would it be possible to upload the ruby script for the encryption/decryption to github like you did with the previous scripts ?

Correct on both points. We'll get those corrected ASAP. Thanks for the feedback!


Great walkthrough esp for us who rarely get to do this and are thus woefully rusty and never see the cool new tricks. Thanks very much.

Just thought I'd also mention a couple of what I think are typos.
1. "Finally, the malware takes the 0xA0 value and adds..." -- I believe it should be 0xF0.
2. "Finally, we take the rightmost 4 bytes and convert..." -- I believe it should be nibbles, or two bytes, or whatever you want to call it.

Thanks again

