jump to navigation

OllyMoreMenu-v1.3c January 24, 2009

Posted by reversengineering in OLLY'S PLUGINS, TOOLS.
add a comment

This plugin added in ollydbg in the menubar more menu´s with your favorite tools for quickstart.

Use:

Install in the Olly Plugins Folder

- for add new menu entry go in add menu and add you favorite tools if ok add this plugin new menu´s in ollydbg menubar for quickstart

http://vip-file.com/download/7ff9a6246046/OllyMoreMenu-v1.3c.7z.html

PhantOm Plugin 1.54 January 24, 2009

Posted by reversengineering in OLLY'S PLUGINS, TOOLS.
1 comment so far

Plug-in for concealment OllyDbg (plugin with the driver). Helps from following methods of detection:

// driver – extremehide.sys

[+] NtQueryInformationProcess.
[+] SetUnhandledExceptionFilter.
[+] OpenProcess.
[+] Invalid Handle.
[+] NtSetInformationThread.
[+] RDTSC.
[+] NtYieldExecution.
[+] NtQueryObject.
[+] NtQuerySystemInformation.
[+] Windows hide.
[+] GetProcessTimes.
[+] NtSetContextThread.

// plugin – PhantOm.dll

[+] PEB BeingDebugged.
[+] PEB NtGlobalFlag.
[+] GetStartupInfo.
[+] Process Heaps.
[+] GetTickCount.
[!] Protect DRx.
[!] Hide DRx.
[!] Fake Windows version.
[!] Custom Handler.
[+] BlockInput

Whats new: – 1.20

[*] Added own handling of exception (C0000005).
[*] Added option for the title change of the main window.
[*] Added own handling of exception (OUTPUT_DEBUG_STRING_EVENT).
[*] int 3 at EP correctly removed.
[*] Added interception of BlockInput. (WinXP only)
[*] Added own handling of exception (C0000094).
[*] Added hiding of GetStartupInfo.
[*] Fixed bug with changing the options of the plugin.
[*] Added more defense of the driver from detection.

http://vip-file.com/download/0fb19f513060/PhantOm-Plugin-v1-.54.7z.html

Imm_PhantOm Plugin 1.54 January 24, 2009

Posted by reversengineering in Immunity Debugger, TOOLS.
add a comment

Plug-in for concealment OllyDbg (plugin with the driver). Helps from following methods of detection:

// driver – extremehide.sys

[+] NtQueryInformationProcess.
[+] SetUnhandledExceptionFilter.
[+] OpenProcess.
[+] Invalid Handle.
[+] NtSetInformationThread.
[+] RDTSC.
[+] NtYieldExecution.
[+] NtQueryObject.
[+] NtQuerySystemInformation.
[+] Windows hide.
[+] GetProcessTimes.
[+] NtSetContextThread.

// plugin – PhantOm.dll

[+] PEB BeingDebugged.
[+] PEB NtGlobalFlag.
[+] GetStartupInfo.
[+] Process Heaps.
[+] GetTickCount.
[!] Protect DRx.
[!] Hide DRx.
[!] Fake Windows version.
[!] Custom Handler.
[+] BlockInput

http://vip-file.com/download/8d00af885300/PhantOm-Plugin-v1.54.7z.html

ProtectionID v6.1.6 2k9 January 24, 2009

Posted by reversengineering in DETECTOR, TOOLS.
3 comments

v6.1.6

Core Code changes:

- new: enabled the PE Stuff dialog (still in early stages)
- new: smbios reporting added (misc tools portion)
- update: pid entrypoint code optimised
- update: updated resizing core, and squashed a few bugs
- update: false positive with some anti virus programs is now fixed (gdata and avast)
- update: folderwatch, task manager, cd/dvd filter driver report, services report and folder
locations all have right click context menus allowing the data to be saved to file
- update: uninstaller code tweaked – various fixes on some entries that would not uninstall
- update: update portion is now tweaked, a bit better and more futureproof
- update: windows 7 is now detected right and everything is functional (we are windows 7 compatible)

- bugfix: gui issue when run from context menu (log window will be shown)
- bugfix: file open doing nothing bug fixed – happened on WinXP with no service packs
- bugfix: folderwatch – bugfix in window handler, could have caused a lockup in 9x/me systems

detection additions / changes

- new: check_protectdisc.asm – added ProtectDisc exact v9.0.0, v9.1.0 & v9.2.0 detection
- new: check_g4wl.asm – added Games for Windows Live detection (xlive)
- new: check_steam.asm – added Steam (basic stub) detection
- new: check_activemark.asm – added ActiveMARK v6.50.767 detection

- new: check_breakpointcrypter.asm – added Breakpoint Crypter v0.0.79 detection
- new: check_expressor.asm – added exPresor v1.6.1 (Pro) detection
- new: check_fearzcrypter.asm – added fEaRz Crypter v2.2.0 detection
- new: check_hellcrypter.asm – added HellCrypter v1 detection
- new: check_kratoscrypter.asm – added Kratos Crypter detection
- new: check_npack.asm – added nPack v1.1.800.2008 + unknown version detection
- new: check_obsidium.asm – added Obsidium v1.3.6.1 detection
- new: check_pespin.asm – added PeSpin v0.1 (x64) detection
- new: check_rdgpack.asm – added RDG Pack Lite Edition v0.4 detection
- new: check_roguepack.asm – added RoguePack v4.0 Beta 1 detection
- new: check_rlpack.asm – added RLPack v1.21 detection
- new: check_simplecrypter.asm – added Simpl3 CrYpT3R detection
- new: check_xcrypter.asm – added X-Crypter v2.01 detection
- new: check_zprotect.asm – added in *generic* ZProtect detection

- new: dongle_softdog.asm – added SoftDog Dongle detection

- update: check_protectdisc.asm – removed protection level output (basic/pro) when detecting v9
(this version is all ‘Pro’, no more ‘Basic’ v9 games)
- update: check_activemark.asm – ActiveMark v6.1.335 detection rewritten
(thx Nacho_dj for reporting a bug in American McGee’s Grimm Bundle)

CD/DVD/Image file/sector scan

- update: sector scan updated to handle various movie protections
(css/cpmm, cprm, aacs hddvd, aacs bd), this code is still in the experimental stage,
and needs testing, but seems to work :)

[i] Init cd/dvd sector scan for Drive O
[i] Detected CSS / CPMM Protection! (0×00000001)
[i] Region Lock Detected -> RegionBitMask: 00000002
[.] Region(s) allowed : 2 (Drive region will need to be changed, you have 2 changes remaining,
your current region is : 1)
- Scan Took : 0.828 Second(s)

- bugfix: fixed bug in cddvd sector scanning code (register got trashed) – not critical..

http://vip-file.com/download/f8fbbf77849/ProtectionID-v6.1.6-2k9.rar.html

Kernel Detective v1.2 January 24, 2009

Posted by reversengineering in DETECTOR, OTHER, TOOLS.
3 comments

Kernel Detective is a free tool that help you detect, analyze, manually modify and fix some Windows NT kernel modifications. Kernel Detective gives you the access to the kernel directly so it’s not oriented for newbies. Changing essential kernel-mode objects without enough knowledge will lead you to only one result … BSoD !

Kernel Detective gives you the ability to :
1- Detect Hidden Processes.
3- Detect Hidden Threads.
2- Detect Hidden DLLs.
3- Detect Hidden Handles.
4- Detect Hidden Driver.
5- Detect Hooked SSDT.
6- Detect Hooked Shadow SSDT.
7- Detect Hooked IDT.
8- Detect Kernel-mode code modifications and hooks.
9- Disassemble (Read/Write) Kernel-mode/User-mode memory.
10- Monitor debug output on your system.

Now Support Vista Service Pack 1 (Build 6001) .
[+] Added Hidden/Suspicious Threads Detection .
[+] Added Smart Process Termination Technique .
[*] Improved Handles Detection .
[*] Improved Processes Detection .
[*] Improved Drivers Detection .
[*] Improved User-mode Memory Reader On Vista .
[!] Fixed bug in IAT Hooks Detection

http://vip-file.com/download/d5bcb775250/Kernel-Detective-v1.2.zip.html

Themida-Winlicense ID 1.1 Support EXE / DLL / OCX January 24, 2009

Posted by reversengineering in DETECTOR, OTHER, TOOLS.
add a comment

Themida-Winlicense ID 1.1 Support EXE / DLL / OCX
Author: goldsun

Supported versions: 1.0.0.8 – 2.0.5.0 or higher

Detects exact Themida-Winlicense version.
How to use: drag a themida protected file and drop it over the exe or use the PEiD plugin.

http://vip-file.com/download/4eb420346113/Themida-Winlicense-ID.zip.html