If someone want's to have a quick look through the internals of the .sdll and .sexe files that you can dump with the great DumpFile405: VV1LD/DumpFile405 source
I modified a great editor to be able to directly open dumped decrypted sexe or sdll files (tested with 4.05 files, file extension must be .sdll or .sexe).
It is meant for viewing only.
If you save the files within the editor it will save the file without the original header.
Download: dnSpy-SDLL-SEXE-MOD.zip (15 MB)
Additionally I created a small console app that cuts away the head of the file and saves it in a subfolder \output with the original filename.
Just drag and drop one or multiple selcted files from the explorer onto the cut4096.exe.
Then you can open the files in the original editor
(but NOT in the modified one if the extension still is .sdll as it would cut the file again).
Download: cut4096.zip (3 KB)
The .sexe/.sdll file contains an embedded dotnet file with pe header.
The values in the pe header don't add the 4096 byte from the additional header.
It is meant for viewing only.
If you save the files within the editor it will save the file without the original header.
Download: dnSpy-SDLL-SEXE-MOD.zip (15 MB)
Additionally I created a small console app that cuts away the head of the file and saves it in a subfolder \output with the original filename.
Just drag and drop one or multiple selcted files from the explorer onto the cut4096.exe.
Then you can open the files in the original editor
(but NOT in the modified one if the extension still is .sdll as it would cut the file again).
Download: cut4096.zip (3 KB)
The .sexe/.sdll file contains an embedded dotnet file with pe header.
The values in the pe header don't add the 4096 byte from the additional header.