jump to navigation

the page of debuggers updated October 14, 2009

Posted by reversengineering in NEWS.
1 comment so far

look here for more info
http://reversengineering.wordpress.com/debuggers/

Trial Reset version 3 , 3.2 & 3.4 October 14, 2009

Posted by reversengineering in OTHER, TOOLS.
add a comment

VB Decompiler Pro 7.6 October 14, 2009

Posted by reversengineering in Decompilers, TOOLS.
add a comment

Highest respect to the GPcH
only for testing
if u like it buy it
http://letitbit.net/download/7265.ff7edf2a366aeb6f0ae16de2d/VB_Decompiler_Pro_7.6.rar.html

Unpacker ExeCryptor RC2 October 14, 2009

Posted by reversengineering in TOOLS, UNPACKERS.
add a comment

http://letitbit.net/download/0229.0ec181aaf5ad1e8a17e074379/Unpacker_ExeCryptor_RC2.rar.html

dup 2.19 October 14, 2009

Posted by reversengineering in OTHER, TOOLS.
add a comment

http://letitbit.net/download/4461.4bf7acf1da8a214c89e38d1a8/dup2.rar.html

Quick Unpack 2.2 October 14, 2009

Posted by reversengineering in TOOLS, UNPACKERS.
add a comment

by tPORt
http://letitbit.net/download/0314.0278e133219167ad3bddefe1f/Quick_Unpack_2.2.Tool.tPORt.rar.html

3 new tutors October 14, 2009

Posted by reversengineering in MUPS, Themida, execryptor.
add a comment

http://rapidshare.com/files/292880306/execryptor_and_themida_unpacking_toturial.rar
thanx fly to them

new olly moded October 14, 2009

Posted by reversengineering in DEBUGGER, TOOLS.
add a comment

http://rapidshare.com/files/292876972/odbg110_UST_2bg.rar

RLPack 1.21 VM Code Translater 1.0, Unpacking RLPack 1.21 October 14, 2009

Posted by reversengineering in MUPS, other protectors and packers.
add a comment

from:http://qunpack.ahteam.org/?p=427
thanx flys to FEUERRADER [AHTeam]
http://letitbit.net/download/4943.ae4c808bb8edc9332bd23413f/Unpacking_RLPack_1.21_Main_Executable.rar.html

odbg110 moded by Sabre-Gold October 14, 2009

Posted by reversengineering in DEBUGGER, TOOLS.
add a comment

http://rapidshare.com/files/292875278/odbg110_Sabre-Gold.rar

OllyICE v1.10 October 14, 2009

Posted by reversengineering in DEBUGGER, TOOLS.
add a comment

new olly modified
http://rapidshare.com/files/292873292/odbg110_OllyICE_v1.10.rar

ArmaG3ddon v1.7 October 14, 2009

Posted by reversengineering in OTHER, TOOLS.
add a comment

ArmaG3ddon v1.7
Current Release: September 2009 v1.7
+ Fixed a problem resolving PE section names
+ Updated Arteam Import Reconstructor (Nacho_dj) version 1.5.0 September 2009
Includes:
+ New approach to get overlay offsets
http://www.accessroot.com/arteam/site/download.php?view.262
http://letitbit.net/download/3260.34501ca88a42e7a38bed86741/ArmaG3ddon_v17_by_CondZero.rar.html

Exeinfo PE v0.0.2.5 Final October 14, 2009

Posted by reversengineering in DETECTOR, TOOLS.
add a comment

Exeinfo PE v0.0.2.5 Final – 526 Sign
2009-09-27
added Import/Export viewer , external detectors MENU – Ctrl key, new GUI icons,exe runner Menu 30 items
Size : 590 KB
http://exeinfo.fortunecity.com/exeinfope.zip
http://letitbit.net/download/8471.c8bbf1243c0003f1c789e9f47/exeinfope.zip.html

OllyDbg 2.0 beta October 14, 2009

Posted by reversengineering in DEBUGGER, TOOLS.
add a comment

The second beta. I’ve planned that it will come with the more or less complete help file. Unfortunately, I had no time to write it. Therefore there will be also the third beta release… soon.
There are many – over 20 – bugfixes in the beta 2, some of them are really critical. As promised, there are no significant changes, with two exceptions. The recognition of UNICODE strings is vastly improved, they are no longer limited to ASCII subset (option “Use IsTextUnicode()”. Also I recognize strings in the UTF-8 format. By the way, if you have some small sample program with the free source that uses UTF-8 strings, please send it to me (together with the screenshot of displayed strings) so that I will be able to test OllyDbg.
The second new feature is in the run trace. New option “Pause when EIP points to modified command” helps, for example, to find the real entry point of the SFX-ed code. Just don’t forget to create backup first (or use another new option, Auto backup user code)!
http://ollydbg.de/
http://letitbit.net/download/1694.1da1c69e6c064d7a68f1029c7/odbg200j.rar.html

DJ Java Decompiler 3.11.11.95 October 14, 2009

Posted by reversengineering in Decompilers, TOOLS.
add a comment

With DJ Java Decompiler you can decompile java CLASS files and save it in text or other format. It’s simple and easy.
DJ Java Decompiler is Windows 95/98/Me/NT/2000/XP/2003/Vista/7 decompiler and disassembler for Java that reconstructs the original source code from the compiled binary CLASS files (for example Java applets). DJ Java Decompiler is able to decompile complex Java applets and binaries, producing accurate source code. DJ Java Decompiler is a stand-alone Windows application; it doesn’t require having Java installed! DJ Java Decompiler is not just Java decompiler and disassembler but it is also a fully featured Java editor using the graphic user interface with syntax-coloring. Using DJ Java Decompiler is easy. Select Open and load your desired class file, or just double-click the CLASS file you want to decompile. DJ Java Decompiler supports drag-and-drop functions for OLE. You will see the source code instantly! In Windows Explorer Right mouse-button pop-up menu available too. You can decompile or disassembler a CLASS files on your computer hard disk or on a network drive that you have a connection to (you must have a full access rights or just change the default output directory for .jad files). You don’t need to have the Java Virtual Machine or any other Java SDK installed. But this latest release is able to compile, run, create JAR archives and run applets outside of the context of a Web browser when JDK is installed. With DJ Java Decompiler you can decompile more than one java class file at one time. This release enables users to decompile “dead” parts of code.

http://members.fortunecity.com/neshkov/dj.html
http://www.neshkov.com/djdec311.zip
http://rapidshare.com/files/292881737/djdec311.zip

Keygener Assistant v1.1 October 14, 2009

Posted by reversengineering in OTHER, TOOLS.
add a comment

http://letitbit.net/download/2474.2e32f867ffffcf16d49f00f77/keygener_Assistant_v1.1.
rar.html

6 new olly plugins October 14, 2009

Posted by reversengineering in OLLY'S PLUGINS, TOOLS.
add a comment

hi
HOlly v0.2
LabelArgs v0.1
MUltimate Assembler v0.3
ODbgScript v1.75.3
Olly Advanced v1.27
Plugins Manager v1.2
StrongOD v0.2.6.415

http://letitbit.net/download/6309.6577fabcf64e4c420746565f5/olly_plugins.rar.html

new olly moded October 14, 2009

Posted by reversengineering in DEBUGGER, TOOLS.
add a comment

hi
new olly modified by ygs
http://letitbit.net/download/4503.c4afaf17c8458cbfa2a66c99f/odbg110_YPOGEiOS.rar.html

Enigma unpacking October 14, 2009

Posted by reversengineering in MUPS, other protectors and packers.
add a comment

hi again
http://rapidshare.com/files/292872147/Enigma_1.6x__Find_OEP___IAT_Repair_.rar

thanx fly to Ahmadmansoor

wordpress filtered October 14, 2009

Posted by reversengineering in NEWS.
add a comment

hi all
i couldn’t login to blog becuz here in my country its filter (https://…wp-admin)!!!
i used some tricks ,tools and other way till today , now i find new thing :)
i will approve all ur comment
thanx for ur supporting my blog
i will post some new tools , tutors ….

hi to all June 6, 2009

Posted by reversengineering in NEWS.
11 comments

hi my freinds

after along time i came here and approve ur nice comments and if i have times i will upload ur request’s files

i’m still alive in this world :) but u know …..

i will update blog as soon as possible but i know u find ur way in these years

have phun …good luck …best wishes

best regards

Tria Reset 3.4 Final reup February 27, 2009

Posted by reversengineering in OTHER, Request, TOOLS.
6 comments

http://letitbit.net/download/f9a602709469/Trial-Reset-34Final.rar.html

letitbit is ok now February 26, 2009

Posted by reversengineering in NEWS.
add a comment

hi

i test letitbit today and see its work fine ;) all files online now and u can dl it

all files of 26 feb posts February 26, 2009

Posted by reversengineering in Request, TOOLS.
add a comment

plus more ….

DownloadLink: http://rapidshare.com/files/202799005/26_feb_2009_uploaded.rar

EXECryptor And CrC Check. February 26, 2009

Posted by reversengineering in MUPS, execryptor.
3 comments

EXECryptor And CrC Check. tutur by phpb

ExcpHook 0.0.5-rc2 February 26, 2009

Posted by reversengineering in OTHER, TOOLS.
add a comment

The source code / binary is also available as a part of http://code.google.com/p/openrce-snippets/

ExcpHook is an open source (see license.txt) Exception Monitor for Windows made by Gynvael Coldwind (Team Vexillium).
Currently supported Windows versions: XP SP2 and XP SP3
Please note that this is ALPHA version.

ExcpHook Exception Monitor is an exception monitor, made for Windows XP. The monitoring part is kernel-level (technically, in a driver), so in opposite to user-land monitors, ExcpHook does not have to be a debugger for the monitored processes, nor it doesn’t have to change their environment/code/data in anyway. Additionally, ExcpHook is not tied up with one process – it monitors every process in the system, letting the user filter out the interesting processes by providing a part of the image name of the process.

Well, thats it, any comments are welcomed ;)

— Changelog:
0.0.4 -> 0.0.5-rc2
* Fixed 100% CPU eating bug
* Rewritten the code to use IOCTL insted of Write/Read
* Added driver status checking mechanism
* Commented the source code, made it more readable
* Fixed multiCPU/multicore race condition possibility
* Fixed BSoD on some systems when patching the kernel
* Added some more spinlocks here and there
* Fixed BSoD on some kernel versions, the signature seeking
mechanism has been changed to a more decent one
* Added general/control register logging/display
* Added image name acquiring from EPROCESS
* Added one-instatnce-at-a-time limit (this is needed due to design)
* Added disasembly display (using diStorm lib)
* Added some more minor things

— Example of usage:
c:\Tools\ExcpHookMonitor_0.0.5-rc1>ExcpHook.exe excp_
ExcpHook Exception Monitor v0.0.5-rc2 by gynvael.coldwind//vx
(use -h or –help for help)
Filtering results only to ones containing “excp_”
Loading driver…OK
Opening device…OK
Requesting info on driver…OK
Driver: ExcpHook driver v0.0.5-rc2 by gynvael.coldwind//vx.
Driver status: All OK
Entering loop… press ctrl+c to exit

— Exception detected —
PID: 1440 First Chance: YES
Exception code: 10000004 (KI_EXCEPTION_ACCESS_VIOLATION)
Exception addr: 0040130a
Image (from OpenProcess): c:\Tools\ExcpHookMonitor_0.0.5-rc1\TestSuite\excp_accviol.c.exe
Image (from EPROCESS) : excp_accviol.c.
Param count : 2
Params:
00000000 88776655
Access Violation Type : READ
Accessed Memory Address: 88776655
Eax: 00401360 Edx: 77c51ae8 Ecx: 00401360 Ebx: 00004000
Esi: 7c90d950 Edi: 0006a19c Esp: 0022ff60 Ebp: 0022ff78
Eip: 0040130a
EFlags: 00010247
CF: 1 PF: 1 AF: 0 ZF: 1 SF: 0 TF: 0
IF: 1 DF: 0 OF: 0 NT: 0 RF: 1 VM: 0
AC: 0 ID: 0
IOPL: 0 VIF: 0 VIP: 0

Stack:
77c2aead 0006a19c 003e29f0 00401305 00000010 00000002 0022ffb0 00401237
00000001 003e2498 003e29f0 00404000 0022ffa4 ffffffff 0022ffa8 00000001

Code:
[0040130a] a1 55667788 MOV EAX, [0x88776655]
[0040130f] 8945 fc MOV [EBP-0x4], EAX
[00401312] b8 00000000 MOV EAX, 0×0
[00401317] c9 LEAVE
[00401318] c3 RET
[00401319] 90 NOP
[0040131a] 90 NOP
[0040131b] 90 NOP
[0040131c] 90 NOP
[0040131d] 90 NOP
[0040131e] 90 NOP
[0040131f] 90 NOP
[00401320] 55 PUSH EBP
[00401321] b9 c0304000 MOV ECX, 0×4030c0
[00401326] 89e5 MOV EBP, ESP
[00401328] eb 14 JMP 0×40133e

Hash & Crypto Detector 1.1 February 26, 2009

Posted by reversengineering in OTHER, TOOLS.
add a comment

* HCD detects most common Hash & crypto Algorithmes and compilers for PE files.
* It can currently detect more than 90 different signatures .
* HCD is special in some aspects when compared to other identifiers already out there!

############################################################################################

1. It has a superb GUI and the interface is really intuitive and simple.
2. The rate of detection is very good.
3. Shell integration, Command line support.
4. Always on top And Drag’n'Drop capabilities.
5. Extra scanning techniques used for even better detections.
6. Total Scan able to find duplicate signatures and determine the location VA.
7. Save Log allows you to choose the place of keeping or copying the result.

NW PE Builder February 26, 2009

Posted by reversengineering in PACKER, TOOLS.
add a comment

Simple and easy to use PE Editor.

Rebel.NET 1.3.0.1 February 26, 2009

Posted by reversengineering in .NET, TOOLS.
add a comment

Rebel.NET is a rebuilding tool for .NET assemblies which is capable of adding and replacing methods and streams.

It’s possible to replace only a limited number of methods or every method contained in a .NET assembly. The simplicity of Rebel.NET consists in the replacing process: one can choose what to replace. For instance, one may choose to replace only the method code, instead of its signature or method header.

The interface of Rebel.NET is quite a simple one. As input it requires a .NET assembly to be rebuilded and a Rebel.NET rebuilding file. The Rebel.NET file contains the data that has to be replaced in the original assembly.

Rebel.NET can also create a Rebel.NET file from a given assembly. This is a key functionality, since some times the data of the original assembly has to be processed first to produce a Rebel.NET file for the rebuilding of the assembly. This sort of “report” feature can also be used to analyze the methods of an assembly, since reading the original data from a .NET assembly isn’t as easy as reading a Rebel.NET file. It’s possible to choose what should be contained in the Rebel.NET file.

All the Rebel.NET features can used through command line, which comes very handy when an automated rebuilding process is needed.

Rebel.NET is, mainly, a very solid base to overcome every .NET protection and to re-create a fully decompilable .NET assembly. As such, Rebel.NET has to be considered a research project, not an encouragement to violate licensing terms.

ActiveMARK Version Viewer 1.2 February 26, 2009

Posted by reversengineering in DETECTOR, TOOLS.
1 comment so far

ActiveMARK Version Viewer 1.2 – 2009/01/14 – Bilingual edition (English/Spanish)

Updated for the new version AM6.50.767.

History
——-

*** version 1.1 – 2008/08/14 – Bilingual edition (English/Spanish)

When checking an ActiveMARK license file, it shows the Activation Code.

*** version 1.0 – 2008/04/13 – Bilingual edition (English/Spanish)

Tool for detecting if a target is protected with ActiveMARK protection.

Available for any kind of file.

Running on an executable will launch it with the proper arguments to show the version by using the ActiveMARK internal engine.

It permits a static analysis (not executing anything), by checking ‘Do not launch executables’ checkbox. This option will prevent your system from getting neither new hidden registry entries that the protection adds to your system, nor hidden files, too, both of them being used by the protection for memorize the trial uses of the target.

For getting the possibility of use from a contextual menu, check ‘Add to contextual menu’ checkbox.

It detects if your system language is english or spanish before showing you all strings.

I hope you enjoy it :)

Nacho_dj / ARTeam

Coded & Developed by Nacho_dj / ARTeam