jump to navigation

happy new year 2009 is staring now December 31, 2008

Posted by reversengineering in NEWS.
5 comments

happy new year

سا ل نو میلادی مبارک

PE Explorer v1.99 R5 FULL December 18, 2008

Posted by reversengineering in OTHER, TOOLS.
1 comment so far

http://vip-file.com/download/d473ef664967/PE-Explorer-v1.99-R5-FULL.rar.html

ArmInline v0.96ff December 18, 2008

Posted by reversengineering in TOOLS, UNPACKERS.
add a comment

Bugfix: A couple of bug reports filtered in over the years, all pertaining to the Nanomite loader. Two fairly important fixes were made, so I thought I’d publish them

http://vip-file.com/download/c4c4ab235065/Armadillo-ArmInline-0.96ff.zip.html

Request files Reup. December 18, 2008

Posted by reversengineering in OLLY'S PLUGINS, OTHER, Request, Scripts, TOOLS.
add a comment

hi my friends

http://vip-file.com/download/c6ed40102967/HideSyser-v-1.94.rar.html
http://vip-file.com/download/99ab99480277/Thinstall-Package–Extractor.rar.html
http://vip-file.com/download/3b8847955758/VMProtect-1.7-IAT-Repair.txt.html
http://vip-file.com/download/997828206045/MagicHideOllyDbg-v-1.01.rar.html
http://vip-file.com/download/2c3ae6798317/Themida—WinLicence-1.x.x—2.x.x-CodeEncrypt-Repair.txt.html

سلامی دوباره December 18, 2008

Posted by reversengineering in NEWS, پارسی.
1 comment so far

سلام به همه دوستان و برو بچ با صفا که همیشه مورد لطف شان بودیم و ما را همیشه شرمنده می سازند

خدا پشتو پناهتون

این چند وقت که نیومدم کلی این نت تغییر کرد

لت ایت بیت که ایران و تحریم کرد برای همین دیگه باید با پروکسی از سایتش دانلود کرد

بعدش اینترنت خودم در نامه بازی های رانژه و تغییر سرویس و غیره سرویس شد

:)

بعدش هم کل اینترنت ایران

خلاصه

اگر الان با کمی مشکل از نظر فایلهای قدیم و اخبار جدید و… مواجه هستید به نظر من برای پوست مان خوب باشه

بیشتر ادما هم الان میرن تو خواب زمستونی و کریسمس و غیره که باعث میشه اوضاع همه چی اروم به نظر بیاد

:)

خوب فعلن با شما خداحافظی میکنم تا یکم زیر افتاب زمستون برنزه بشم

!!!!!

سربلند و پیروز باشید

Thinstal Package Extractor December 9, 2008

Posted by reversengineering in OTHER, TOOLS.
10 comments

http://letitbit.net/download/99ab99101406/Thinstall-Package–Extractor.rar.html

new scripts December 9, 2008

Posted by reversengineering in Scripts, TOOLS.
3 comments

http://letitbit.net/download/e06f9c89948/MFC-Conditional-Breakpoint.txt.html
http://letitbit.net/download/2c3ae6144854/Themida—WinLicence-1.x.x—2.x.x-CodeEncrypt-Repair.txt.html

MagicHideOllyDbg 1.01 December 9, 2008

Posted by reversengineering in OLLY'S PLUGINS, TOOLS.
1 comment so far

Here’s a quick list of MagicHideOllyDbg’s function:

- erases debug-heap padding
- erases BeingDebugged flag in the PEB
- erases NtGlobalFag in the PEB
- adjusts heap flags to default values
- disables kernel32!OutputDebugStringA() function
- forces kernel32!CheckRemoteDebuggerPresent() to always return an error
- forces kernel32!UnhandledExceptionFilter() to ignore debugger presence
- forces kernel32!Process32NextW() to return immediately
- forces ntdll!NtSetInformationThread() to ignore HideThreadFromDebugger class
- forces ntdll!NtQueryInformationProcess() function to ignore ProcessDebugPort class
- intercepts ntdll!NtQuerySystemInformation() function but does nothing with it
- randomises “CPU – ” text in OllyDbg

http://letitbit.net/download/997828455996/MagicHideOllyDbg-v-1.01.rar.html

HideSyser Plugin 1.94 December 9, 2008

Posted by reversengineering in OTHER, TOOLS.
1 comment so far

Syser is a wonderfull tool but not have a lot of plugins for it. I make one plugin (in a beta stage) that have 2 functions:

- Use “gta” or “getaddr” command in Syser control panel for get a kernel function memory address, ex.”gta DbgPrint” and you get the memory entry point. Only works with Kernel exported functions (Kernel and Hal).

- Use “hide” command to hide Syser against NtCreateFile (a lot of programs try find Syser using it)
- Use “unhide” command to unhide Syser against NtCreateFile

It is a POC. Only tested in Windows XP Proffesional SP2/SP3 in VMWare and without VMWare with success

For install put in the %SystemFolder%\drivers\plugin\386i and reboot Syser
http://letitbit.net/download/c6ed40972286/HideSyser-v-1.94.rar.html

dup2.19 beta 4 December 9, 2008

Posted by reversengineering in OTHER, TOOLS.
add a comment

Version:

Features:
-multiple file patcher
-create Offset and Search&Replace patch/loader
-compare files (RawOffset and VirtualAddress) with different filesize
-registry patcher, also for loaders
-attach files to patcher
-get filepaths from registry
-usage of CRC32 and filesize checks
-patching packed files
-compress patcher with your favorite packer
-saving projects
-use custom skin in your patcher
-add music (Tracker Modules: xm,mod,it,s3m,mtm,umx,v2m,ahx,sid) to patcher
-and many more…
http://diablo2oo2.di.funpic.de/stuff/dup2.beta.rar

Armadillo-6.x-HWID-Changer December 9, 2008

Posted by reversengineering in OTHER, TOOLS.
2 comments

This Is A Simple Tool For Changing Armadillo 6.0.x Hardware ID In Standard Protection Mode
Armadillo Is A Bad Protector , Because You Can Crack It Without Any User And Key
Next Time I Release My Tool For Armadillo Cracking
http://vip-file.com/download/8af781236861/Sh4DoVV-Armadillo-6.x-HWID-Changer.rar.html

Tola Patching Engine December 9, 2008

Posted by reversengineering in OTHER, TOOLS.
add a comment

http://s2.ipicture.ru/uploads/081208/BfTTGhSDJY.png

http://vip-file.com/download/5da9b2328045/Tola.rar.html

VMProtect 1.7 IAT Repair December 9, 2008

Posted by reversengineering in Scripts, TOOLS.
add a comment

http://vip-file.com/download/3b8847487035/VMProtect-1.7-IAT-Repair.txt.html

VMware ThinApp 4.0.1-2837 December 9, 2008

Posted by reversengineering in OTHER, TOOLS.
add a comment

” ..This a maintenance release that addresses a number of known issues. It also delivers some nice
additions to utilities within the ThinApp Suite including the ThinReg application..”

- The following features have been added for this release :

The thinreg.exe utility has been enhanced, facilitating file type association. It also includes support for DDE, extra verbs, and MIME type registration.

Enhanced support for double-byte applications and double-byte locales.

Enhanced support for 16-bit MSDOS programs.

Support for control panel extensions. Some applications, such as QuickTime or the mail applet for Microsoft Outlook 2007, have control panel extensions that you can now see in a ThinApp environment.

Ability to register files other than .exe files. For example, if you install an application that installed a README file or has another link to documentation, you can access those files.

Protocol registration. If an application invokes SMTP or HTTP, ThinApp starts any virtual applications that can handle the tasks. If ThinApp cannot locate virtual applications, ThinApp invokes native applications to handle the tasks.

ThinApp includes the RequiredAppLinks parameter in the Package.ini file. Previously, the user had to manually add this parameter.

ThinApp makes the MSI build template accessible to users to customize the MSI database.

User documentation has been restructured to start with basic functionality targeted at the novice user, building towards advanced functionality regarding deployment and customizations.

Log Monitor now supports the ability to pause and resume trace file capture.

Application link now supports multi-level links, such that application A links to application B, which links to application C, and so on.

Special entrypoints cmd, regedit and iexplore are marked with an asterisk (*) to denote these are not virtual applications. Rather, they load respective native EXEs in virtual environment.

Isolation mode can now be specified at the root of registry (for example, for HKCU, HKLM).

Stub executables changed to improve security and interaction with roaming profiles and system-installed applications.

Support for creating MSI distribution larger than 2GB (requires separate CAB file to be distributed).

Support for creation of compressed trace files.

Support for running ThinApp application on GoGlobal platform.

Support packaging application wrapped with the “Shrinker” packer.

…and more :
vmware.com/support/thinapp4/doc/releasenotes_thinapp401.html
http://rapidshare.com/files/171695546/4.0.1-2837.zip

VMProtect Professional v1.70.4 December 9, 2008

Posted by reversengineering in PROTECTOR, TOOLS.
1 comment so far

It is a new generation of software protection. Protected parts of code are executed on a virtual machine which makes it really difficult to analyze and crack the protected software. The built-in disassembler and a MAP file allow you to quickly select the necessary parts of the code protected against cracking.
Supported compilers:

* Delphi
* Borland C Builder
* Visual C/C++
* Visual Basic (native)
* Virtual Pascal

Supported formats (x32 and x64):

* EXE
* DLL
* BPL
* OCX
* SYS

Supported operating systems:

* Windows 95/98/ME
* Windows NT
* Windows 2000
* Windows XP
* Windows 2003
* Windows Vista
http://letitbit.net/download/eb56d2635613/VMProtect-Pro1.70.4.CracKed.by.Nooby.rar.html

http://vip-file.com/download/eb56d2292157/VMProtect-Pro1.70.4.CracKed.by.Nooby.rar.html

Exeinfo ver. 0.0.2.1 – ( 451 sign ) December 9, 2008

Posted by reversengineering in DETECTOR, TOOLS.
2 comments

Exeinfo for Win32 by A.S.L.
ver. 0.0.2.1 – ( 451 sign )
http://letitbit.net/download/8d8b61949380/Exeinfo-PE-v0.0.2.1.rar.html

http://vip-file.com/download/8d8b61969353/Exeinfo-PE-v0.0.2.1.rar.html

Detemida 1.0.0.4 December 9, 2008

Posted by reversengineering in OTHER, TOOLS, Themida.
1 comment so far

- Identifing programs proteced by major Themida/WinLicense releases.
- Decode/View Watermarks
- POC to all antivirus companies that Themida protected programs are identical, even with all “Hide from PE Scanners” option on or even heavily DIYed.
- End of hope to those people who wanted to use Themida to protect trojans from antivirus.

http://letitbit.net/download/e49b87485016/Detemida1.0.04.rar.html

http://vip-file.com/download/e49b87440555/Detemida1.0.04.rar.html

letitbit problem! December 9, 2008

Posted by reversengineering in Uncategorized.
3 comments

hi guys

i think u have problem with letitbit becuz For some countries free dowload was closed (persia,….) I think you must use proxy….

req. link December 9, 2008

Posted by reversengineering in DEBUGGER, Request, TOOLS.
add a comment

http://letitbit.net/download/2f637f644947/SYSKERNDEBUG.1.99.1900.1095.rar.html