jump to navigation

RL dePacker V1.4 , Unpacker for Petite 2.1 and 2.2 [old posts] August 2, 2008

Posted by reversengineering in TOOLS, UNPACKERS.
1 comment so far
hi
Generic unpacker support 92 packers

aUS [Advanced UPX Scrambler] 0.4 – 0.5
ASPack 1.x – 2.x
AHPack 1.x
AlexProtector 1.x
ARMProtector 0.x
BJFNT 1.3
BeRoEXEPacker 1.x
CryptoPeProtector 0.9x
CodeCrypt 0.16x
dot Fake Signer 3.x
dePack
eXPressor 1.2.x – 1.5.x
EZip 1.0
EP Protector 0.3
Escargot 0.x
EXEStealth 2.x
FSG 1.xx & 2.0
Goat’s PE Mutilator 1.6
hmimys-Packer 1.x
HidePX 1.4
HidePE 2.1
JDPack 1.x
JDProtect 0.9
KByS Packer 0.2x
Krypton 0.x
LameCrypt 1.0
MEW 1.x
nSPack 2.x – 3.x
nPack 1.x
NeoLite 1.x – 2.0
NWCC
OrIEN 2.1x
PECompact 1.x – 2.x
PeX 0.99
PC Shrink 0.71
Polyene 0.01
PackMan 0.0.0.1 & 1.0
PE Diminisher 0.1
PolyCrypt PE 2.1.5
PeTite 1.x
PEStubOEP 1.6
PELockNT 2.x
PePack 1.0
PC PE Encryptor alpha
PackItBitch
PEncrypt 4.0
PEnguinCrypt 1.0
PeLockNt 2.x
PeLock 1.0x
Perplex PE-Protector 1.x
PKLITE32 1.x
RLP 0.6.9 – 0.7.x
RLPack Basic Edition 1.x
RLPack Modifier Edition 1.x
ReCrypt 0.15 – 0.80
Stone`s PE Encryptor 2.0
StealthPE 2.1
Software Compress 1.x
SPLayer 0.08
ShrinkWarp 1.4
SPEC b3
SmokesCrypt 1.2
Simple UPX-Scrambler
SimplePack 1.x
SLVc0deProtector 1.x
tELock 0.x
UPX 0.8x – 2.x
UPXRedir
UPXCrypt
UPX Inkvizitor
UPXFreak 0.1
UPolyX 0.x
UPXLock 1.x
UG Chruncher 0.x
UPX-Scrambler RC 1.x
UPX Protector 1.0x
UPXShit 0.06 & 0.0.1
UPXScramb 2.x
VirogenCrypt 0.75
WWPack32 1.x
WinUPack 0.2x – 0.3x
Winkript 1.0
yC 1.x
yZPack 1.x – 2.x
32Lite 0.3a
!EP (ExE Pack) 1.x
[G!X]`s Protector 1.2

http://letitbit.net/download/3c4e1d538294/RL-dePacker.V1.4.rar.html
Unpacker for Petite 2.1 and 2.2 coded by mirz :) .

What’s new in version 0.2b:

- I corrected verification of signature ( now it should work fine :) )
; ? = 2 bajty
;[PEtite v2.1=B8????6A?68????64FF35????648925????669C6050]
;[PEtite v2.2=B8????68????64FF35????648925????669C6050]
- I corrected reconstruction of import symbols

( Now it rebuilds such functions as LeaveCriticalSection etc. )
- unpack dll :)
- new dialog box :)
- manifest.xml is from MSDN library.

I tested him on several programs packed by me.

How unpetite 0.2b work:
(files *.exe)
1. run program
2. It stops on access violation
3. then it searches jump to OEP
4. rebuild import symblos
5. dump and save file as unpacked.exe

(files *.dll)
1. ntdll.KiUserException is patched
2. loading of dll
3. It stops on access violation
4. then it searches jump to OEP and reconstruction of ntdll.KiUserException
5. rebuild import symblos
6. dump and save file as unpacked.dll

All notes, problems and errors send under address e-mail mirz@o2.pl .
Don’t forget, that program can have some errors else:)

Some programs, which was using for tests:

- xmplay (thx bart)
- Cruehead Crackme1
- hexedit Geoffrey Prewett
- Lit 1.21 Marek Szyku翅
- RegCleaner4.3 by Juoni Vuorio
- CloneCD 5.2.6.1
- Winamp 5.08d
- WinIso v5.3
- WinRar 3.4

http://letitbit.net/download/870fc1296769/unpetite.en.rar.html

undetecteding a worm or… [old blog] August 2, 2008

Posted by reversengineering in RCE.
6 comments

undetecteding a worm or…

hi
http://rapidshare.com/files/43783036/vid2.avi.1
http://rapidshare.com/files/43782943/vid2.avi.2
for joining the parts use:
http://rapidshare.com/files/44765472/Create_vid2.exe

MUP EXECryptor 2.5 [old blog] August 2, 2008

Posted by reversengineering in MUPS, execryptor.
add a comment

IDA Signatures [OLD POST] August 2, 2008

Posted by reversengineering in OTHER, TOOLS.
add a comment

all IDA Signatures

IDA Signatures
http://rapidshare.com/files/38014929/all_sig_4_ida_3y_REM.rar

hide toolz [ALL] August 2, 2008

Posted by reversengineering in OTHER, TOOLS.
Tags: , ,
4 comments

HideToolz (ultimate crackers tools hider)

HideToolz is intended for hiding crackers tools from different protection trying define their presence.

1) Hiding processes from all possible ring3 methods of the finding.
2) Hiding windows from enumeration and searching for on the known name.
3) Protection processes from opening on the known pid (as well as from indirect methods of the opening).
4) Parental process emulation (for all visible processes runned from hidden, will be emulated parental process explorer.exe)
5) Protection from rebooting windows (and log all rebooting attempts).
6) Protection from formatting the disk (and log all formatting attempts).

Attention: access of the hidden processes unrestricted, and they can see the real system state.
For impossibility of the finding HideToolz file on disk, is recommended rename file and pack its any packer.
hide toolz 1.6

http://letitbit.net/download/13757c18730/HideToolz-1.6.rar.html

v. 2.0
translate form rus>eng:
Ready to release a new CD. The innovations introduced :
1) Protection against SetWindowsHookEx for hidden processes.
2) Access parent to the child (if hidden) foliage at the start of its first flow.
3) Anti-anti debugging (one option), which includes the following :
1-Protection from the debug port of the two-Protection
2-from ThreadHide From Debugger
3-validating hendlov transmitted ZwClose
4)Added compatibility with glucnam and curves KIS6 (yes otsohnut the hands of those who wrote)
5) Fixed small bugs. In updating the old version to the new, obligatory restart.

http://letitbit.net/download/2acc8d32086/hidetoolz-V.2.7z.html

hide toolz 2.1

http://letitbit.net/download/173265228053/HideToolz-V2.1.rar.html

http://letitbit.net/download/bb43c7707362/HideToolz2.1-DRIVERLOADED.rar.html

news link August 2, 2008

Posted by reversengineering in DETECTOR, TOOLS.
Tags:
add a comment

addTLS August 2, 2008

Posted by reversengineering in OTHER, TOOLS.
add a comment

http://letitbit.net/download/5a8ada138656/addTLS.rar.html

WinLicense 1.8x 1.9x Unlock-Hardware-Dependance August 2, 2008

Posted by reversengineering in MUPS, Themida.
add a comment

BY shoooo

size :2.8 (with files)

http://letitbit.net/download/07997c532372/WinLicense-1.8x—1.9x—Unlock-Hardware-Dependance-.7z.html

Bypass Hardware Breakpoint Protection August 2, 2008

Posted by reversengineering in MUPS, RCE.
add a comment

http://letitbit.net/download/1438ef782168/Bypass-Hardware-Breakpoint-Protection.pdf.html

UnKK 1.0 – Unpacker for kkrunchy 0.23a2 +src August 2, 2008

Posted by reversengineering in TOOLS, UNPACKERS.
add a comment


http://letitbit.net/download/a04cb3680016/unkk.zip.html

news link August 2, 2008

Posted by reversengineering in OTHER, TOOLS.
add a comment

Total Commander v7.04 Multilingual

http://rapidshare.com/files/134227479/Total.Commander.v7.04.Multilingual.WinALL.Regged-BLiZZARD.rar

pe explorer 1.99 r3

http://rapidshare.com/files/134227298/pe_explorer_1.99_r3.rar

ViEmu for Visual Studio v2.1.27

http://letitbit.net/download/4228cb179035/ViEmu.for.Visual.Studio.v2.1.27.Incl.Keyfilemaker-EMBRACE.rar.html

nPack-2008

http://letitbit.net/download/3a9d6c996884/nPack-2008.rar.html

ExeCryptor InlinePatching 2.2.x-2.3.x August 2, 2008

Posted by reversengineering in MUPS, execryptor.
add a comment

hi
another nice article we must read
by T-Rex
target :D VR Studio Pro 1.25 Eng version

http://letitbit.net/download/5a312e669569/ExeCryptor-Inline-Patching.pdf.html

Superior Patch Generator 1.1 August 2, 2008

Posted by reversengineering in OTHER, TOOLS.
add a comment

Here is version 1.1 of my AM 6.x inline generator. This tool uses the Superior Method of Inline Patching for the most reliability in getting a working inline (especially for v6.3). Check it out and tell me what you think.
by Nieylana
http://letitbit.net/download/4e2ae0679271/SuperiorPatchGenerator.rar.html

EgyCrypter August 2, 2008

Posted by reversengineering in OTHER, TOOLS.
add a comment

http://letitbit.net/download/bbe3a1603815/080730EgyCrypter.rar.html

LAG Loader Generater 1.2 August 2, 2008

Posted by reversengineering in OTHER, TOOLS.
add a comment

1.2 update
+ fix boundimport resolve bug
+ fix load check bug
+ use advanced thread control
+ add autosave/autoload config

http://letitbit.net/download/94190d2184/Lag-Loader1.2.zip.html

DK Binder v1.0 August 2, 2008

Posted by reversengineering in MUPS, OTHER, TOOLS.
add a comment

DK Binder v1.0
Coded by D4rK aka Stranger21 in delphi 7.

Options:
-unlimited files support
-run or not
-Choose extract path
-Run or not if on VM
-RC4 Encryptions for files
-Show/Hide option
-Parameters support

http://letitbit.net/download/9d0d65751439/080730DKBinder.rar.html