Sh4DoVV tools January 10, 2009
Posted by reversengineering in OTHER, TOOLS.4 comments
Armadillo Detacher special for Debug-Blocker & Copy-MemII
Sh4DoVV Enigma 1.5x-1.6x Generic Loader
by Sh4DoVV
http://rapidshare.com/files/181251204/Sh4DoVV_Armadillo_Detacher.rar.html
http://rapidshare.com/files/181251856/Sh4DoVV_Generic_Enigma_1.5x-1.6x_Loader.rar.html
New NEWFOLDER.EXE (part1) January 10, 2009
Posted by reversengineering in RCE vs BadWares.2 comments
hi
today somebody give me an usb mobile disk and tell me check it for virus and etc….i check it by NOD32(3750) and nothing ,everything seems fine !! but when i see closer to files i find new badware( worm or virus…. !)
summary of this file and my observation without any tools but i have 2 windows
:
size :386 kb
other name of this file : solary.exe , p.exe
waht happend if we execute it:
1-it generates itself by names that likes to all folder/subfolder on ur hard drive for example u have windows folder or system 32 ; u will have windows.exe ,system32.exe …
if u have 100 folders and subfolders u will have 100 foldername.exe and subfoldername .exe
2-it delets ur task mananger and all IMPORTANT CONTOROL PANEL
LIKE:
D:\WINDOWS\system32\sysdm.cpl
D:\WINDOWS\system32\wscui.cpl
D:\WINDOWS\system32\appwiz.cpl
D:\WINDOWS\system32\inetcpl.cpl
msconfig
&…
3-and replace notepad.exe to D:\WINDOWS\regedit.exe and delete it.
4-also disable all in ur registry:)
5-remove RUN and SEARCH bar from start menu .
6-and creates AUTORUN.INF to all root of ur harddrive and etc.
…everything is clear for cleaning
for deleted files u have to copy them in right place
i hope u never see this
Downadup worm January 9, 2009
Posted by reversengineering in RCE vs BadWares.1 comment so far
Name : Worm:W32/Downadup.AL Detection
Names : Worm:W32/Downadup.AL Net-Worm.Win32.Kido Aliases : Worm:Win32/Conficker (Microsoft) Mal/Conficker (Sophos) W32/Conficker.worm.gen (Symantec)
Type: Worm
Category: Malware
Platform: W32
Summary
A standalone malicious program which uses computer or network resources to make complete copies of itself. May include code or other malware to damage both the system and the network.
for more info :
http://www.f-secure.com/v-descs/worm_w32_downadup_al.shtml
http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx
Also about AUTORUN.inf, this worm build it on USB drive :
http://www.f-secure.com/weblog/archives/00001575.html
new section will be add. January 9, 2009
Posted by reversengineering in NEWS.add a comment
hi guys
how are u ((+FA )ton goode !) , i hope u well 
i think about a new section or page to adding on this blog . in my old blog i had something about it ….
http://reverseengineering.blog.com/ADVISORY/
http://reverseengineering.blog.com/ANTI%20ROOT-KIT/
http://reverseengineering.blog.com/VIRUS%20ANALYSIS/
…. but today i feel we need this but that will be different …..so i will add that.
i will happy if u share ur ideas or help us to developing this section like always 
best regards
Themida Winlicense ID +peid plugin January 8, 2009
Posted by reversengineering in DETECTOR, OTHER, TOOLS.1 comment so far
http://vip-file.com/download/4eb420890566/Themida-Winlicense-ID.zip.html
http://vip-file.com/download/a2f4a7457252/peid-plugin-Themida-Winlicense-ID.zip.html
Requset files January 8, 2009
Posted by reversengineering in Request.add a comment
Kaspersky Key Finder V1.5.2d
Kaspersky 2009 Trial Remover
Kaspersky Tria Reset
Microsoft Office Enterprise 2007 Highly Compressed 1.43 MB
these files aren’t tested by me
http://rapidshare.com/files/181083716/Kaspersky_2009_Trial_Remover_downarchive.rar
http://rapidshare.com/files/181089138/Kaspersky_Key_Finder_V1.5.2d.rar
http://rapidshare.com/files/181093987/Microsoft_Office_Enterprise_2007__Highly_Compressed__1.43_MB.rar
http://rapidshare.com/files/181095407/Kaspersky_Trial_Reset.rar
Stats: Reverse Engineering b10g | REM January 7, 2009
Posted by reversengineering in NEWS.add a comment

Anti-Reverse Engineering Guide January 7, 2009
Posted by reversengineering in E-BOOK, RCE.1 comment so far
An individual reading this should have a solid understanding of ASM, how computers handle memory, the Win32 Debugging API, and at least some knowledge of Windows internals. This code most likely will not work on any *nix platform due to the fundamental differences of the Operating Systems. Any other knowledge in the field of reverse engineering is also a plus. One great thing about learning and implementing anti-debugging is that you also develop your reversing skills, which is a great plus to anyone interested in the field. Along with the other mentioned subjects, an interested reader should also be familiar with the tools used for binary application reversing such as OllyDBG, WinDBG, SoftICE, IDA Pro, and others.
http://vip-file.com/download/6e2909425819/Anti-Reverse-Engineering-Guide.rar.html
Unpacker_ExeCryptor_2.x.x_v1.0_RC2 January 7, 2009
Posted by reversengineering in TOOLS, UNPACKERS.add a comment
What’s new:
v1.0 release candidate 2
————————
* Fixed bug in import rebuilding
* Added dynamic OEP search method
* Added manifest and file version information
* Added support for unpacking dll files with stripped relocations
* Fixed other minor bugs
http://vip-file.com/download/6ac381781913/Unpacker-ExeCryptor-2.x.x-v1.0-RC2.zip.html
PROTECTiON iD v6.1.3 January 7, 2009
Posted by reversengineering in DETECTOR, TOOLS.add a comment
faster, more accurate, still better and no more beta – xmas release #2
Core Code changes:
- new: width-RESIZEABLE main window
- new: user can now choose what protection scans to skip
- new: added in new configuration item allowing the user to specify if iso, ccd, mds
etc modules are to be treated as discs (and therby subject to a sector scan)
- new: ability to scan inside microsoft cab files has been implimented
- update: we are now v0.6.1.3
- update: faster scanning core 
- update: configuration window has a new look
- update: better 64 bit file handling support added
- update: appended data detection tweaked a little
- update: now if pid is running and an exe is scanned from the context menu, the main
window will change to the log window (looks better.. suggested by loki)
- update: lnk file resolving is now complete, if user has selected to resolve links,
the system handles this all automatically
- update: window position is now centred if a previous window location was not recorded
- update: adjusted ia64/x64 vs. machine check portion of code (thx to teddy rogers)
- update: configuration – windows product key showing is now a configuration item
- update: configuration – now ‘themes’ and ‘flat mode’ can not be selected at the same time,
this is how it should be as themes override flatmode etc… so now only one can
be selected, and the other is ‘auto unselected’ (suggested by syk0)
- update: configuration – addedin code to enable/disable the ‘protection report bubble’ after a scan is completed
- update: Memory Optimiser – the progress bar should get to the start again when user
clicked on Optimize and Purge was successful
- update: Memory Optimiser – code heavily updated, to work in chunks (if largest size requested is not available),
so, end result – more reliable, faster and optimised
- update: misc tools – added in quick uninstall tab
- update: misc tools – added in CD/DVD Filter Driver scanner tab
- update: misc tools – added in Windows Error Code Resolver tab
- update: misc tools – added in CPU Info tab
- update: misc tools – added in windows directory in the system info output
- update: misc tools – added in Folder Locations scanner
- update: misc tools – system information window now reports graphic device names (geforce, etc),
username & computername and terminal services availability also reported
- update: misc tools – windows install date (from registry) is now reported in the misc tools ’system info part’,
windows install date (from folder) is now also reported.
- update: misc tools – tweaked x64 os detection code, so its a lot more reliable
- update: misc tools – windows product key reporting now also handles x64 systems
- update: nfo viewer – extra checking now added – zip, rar and mz executables will NOT be displayed,
instead, a warning message is displayed
- update: process view – added in check for terminate, dump, priority change..
if selected process is pid, the menu items are disabled (for safety and security)
- update: svf checking now reports current offset on the line when processing
- update: sfv processing now works with quoted filenames
- update: winspy – process name is now also reported (if we could obtain it.. )
- update: log window in cd/dvd operations now has a context menu, allowing for…
clear log
copy selection to clipboard
copy log to clipboard
save selection (txt)
save selection (csv)
save log (txt)
save log (csv) – bugfix: admin reflection / reporting was incorrect on 9x/ME systems
- bugfix: ‘admin shield’ icon is now moved, it looked out of place if the other progress bars
showing cpu usage etc were turned off.. (reported by loki)
- bugfix: Export as .txt doesn’t work properly, only the first file does get saved
- bugfix: event bug fixed, which sometimes resulted in pid sticking at about 35% cpu
- bugfix: pause/resume in the queue window was sometimes wrong for the text (reported by r!co)
- bugfix: Fixed SFV bug – Click on make, don’t select any files and press abort.
You can’t use the complete SFV feature as it’s all greyed out (reported by Blazkowicz)
- bugfix: sfv output for large files (mb, gb etc) was VERY wrong, its since corrected
- bugfix: fixed ‘disappearing window’ problem
- bugfix: ‘large icons’ issue fixed in 9x
- bugfix: sfv – abort now works
- bugfix: sfv – output issue should be 110% fixed now (new buffering system used)
- bugfix: task manager -> potential stack bug fixed
- bugfix: configuration – shortcut creation was broken
- bugfix: nfo viewer – fixed potential memory leak on drag/drop
- bugfix: bug in the code checking for digital signatures (found by blazi)
code now performs a sanity check on accessed memory areas
detection additions / changes
- new: check_activemark.asm – added version detection for v6.3.562
- new: check_alawar.asm – added Alawar Try & Buy Activation detection
- new: check_hexalock.asm – added HexaLock Copy Protection detection
- new: check_protectdisc.asm – added more Protect DiSC v8 subversions
- new: check_securom.asm – added in detection for sll modules + SecuROM Matroschka Package
- new: check_acprotect.asm – added ACProtect v2.1, v2.1.1 and v2.1.2 detection
- new: check_angelscrypter.asm – added Angel’s Crypteur v0.2 detection
- new: check_antidote.asm – added AntiDote v1.4 SE detection
- new: check_armadillo.asm – added version detection v6.00 or newer
- new: check_atreprotector.asm – added AT4RE Protector v1.0 detection
- new: check_avlock.asm – added AVLock detection
- new: check_budcrypter.asm – added BUD Crypter detection
- new: check_coolcrypt.asm – added COOLcryptor 0.9 detection
- new: check_cryptwoz.asm – added CryptWOZ v1.0 detection
- new: check_darkcrypt.asm – added DarkCrypt v1.2 (Private Version) detection
- new: check_dcrypt.asm – added DCrypt Private v0.9b detection
- new: check_dotfixniceprotect.asm – added DotFix NiceProtect v1.0 detection
- new: check_dotnetreactor.asm – added dotNet Reactor v3.3 (or newer) detection
- new: check_enigmaprotector.asm – added version grabber for Enigma Protector
- new: check_execrypt.asm – added ExeCRyPT v1.0 [ReBirth] detection
- new: check_exefog.asm – added EXEFog v1.1 detection
- new: check_exewrapper.asm – added ExeWrapper v3.0 (533Soft) detection
- new: check_expressor.asm – added ExPressor v1.6 detection
- new: check_fakuscrypter.asm – added Fakus Crypter detection
- new: check_fastfilecrypt.asm – added FastFileCrypt v1.6 Public detection
- new: check_fatalzcrypt.asm – added Fatalz Crypt v2.14a detection
- new: check_flashbackprot.asm – added Flashback Protector v1.0 detection
- new: check_gieprotector.asm – added Gie Protector v0.2 detection
- new: check_imppacker.asm – added IMP-Packer v1.0 detection
- new: check_kcryptor.asm – added K!Cryptor v0.11 detection
- new: check_kgbcrypter.asm – added KGB Cypter v1.0a detection
- new: check_leetcryptor.asm – added 1337 Cryptor v2 detection
- new: check_lilithcrypter.asm – added Lilith Crypter detection
- new: check_maxtocode.asm – added MaxtoCode .Net Encryption detection
- new: check_minke.asm – added Minke v1.0.1 Executable Crypter detection
- new: check_moneycrypter.asm – added Money Crypter detection
- new: check_morphna.asm – added Morphna Beta 2 detection
- new: check_mortalteamcrypter.asm – added Mortal Team Crypter v2 detection
- new: check_mpress.asm – added MPRESS NET compressor detection
- new: check_mushroomcrypter.asm – added Mu$hr00M CryPtOR v1.0 detection
- new: check_nme.asm – added NME Executable Crypter v1.1 detection
- new: check_npack.asm – added nPack v1.1.500.2008 Beta detections
- new: check_obfuscatornet.asm – added Macrobject Obfuscator.NET detection
- new: check_privateexe.asm – added version detection for v2.00 – v2.25 and v2.30 – v2.70
- new: check_puricrypt.asm – added Puri Crypt v1.2 detection
- new: check_quickpacknt.asm – added QuickPack NT v0.1 detection
- new: check_rcryptor.asm – added RCryptor v1.6d detection
- new: check_rdgpack.asm – added RDG Pack Lite Edition v0.2 detection
- new: check_rdgtejoncrypter.asm – added RDG Tejon Crypter v0.3 detection
- new: check_rlp.asm – added ReversingLabs Protector v0.7.4 beta detection
- new: check_rlpack.asm – added RLPack v1.20 detection
- new: check_roguepack.asm – added RoguePack v3.3 detection
- new: check_russiancryptor.asm – added Russian Cryptor v1.0 detection
- new: check_securepe.asm – added SecurePE v1.5 detection
- new: check_secureshade.asm – added Secure Shade v1.8 detection
- new: check_snoopcrypt.asm – added SnoopCrypt detection
- new: check_thinstall.asm – added THInstall detection
- new: check_tstcrypter.asm – added TsT Crypter detection
- new: check_undergroundcrypter.asm – added UndergroundCrypter v1.0 detection
- new: check_unlimitedcrypter.asm – added UnLimited Crypter v1.0 detection
- new: check_unopix.asm – added UnoPiX v0.94 detection
- new: check_upxlock.asm – added UPX Lock v1.01 – v1.02 detection
- new: check_weruscrypter.asm – added Werus Crypter v1.0 detection
- new: check_wildtangent.asm – added Wild Tangent v2.1 Activation detection
- new: check_windofcrypt.asm – added WindOfCrypt detection
- new: check_wingscrypt.asm – added Wingscrypt v2.0 detection
- new: check_winutilitiesexeprot.asm – added WinUtilities EXE Protector v2.1 detection
- new: check_wlcrypt.asm – added WL-Crypt v1.0 detection
- new: check_xenocode.asm – added XenoCode .NET protector detection
- new: check_xenocode.asm – added XenoCode Postbuild 2007 + 2008 for .NET detection
- new: check_xhackercryptor.asm – added xHacker Cryptor detection
- new: check_xshell.asm – added XShell v1.5 detection
- new: check_zprotect.asm – added ZProtect v1.4.3 detection
- new: check_zylomwrapper.asm – added Zylom Wrapper Crypted Game.exe detection
- new: license_nalpeiron_scan.asm – added Nalpeiron Licensing Service detection
- new: installer_install4y.asm – added Install4j Wizard Module detection
- new: installer_installshield.asm – added InstallShield v12 BETA Version detection
- new: installer_squeezesfx.asm – added Squeeze Self Extractor Module detection
- new: installer_trymediadownload.asm – added Trymedia Systems Download Manager detection
- new: msi and 7zip file type reporting is now done to the log window (similar to the .rar, zip etc reporting)
- new: added in quick detection for starforce protected pdf file
- update: check_aspack.asm – added additional check for ASPack 2.x to avoid a false positive
when scanning a file wrapped by FlashBack with ASPack entrypoint signature
- update: check_codelok.asm – improved detection
- update: check_dotnetreactor.asm – some parts recoded to be more generic & faster
- update: check_execryptor2.asm – improved detection with heuristic checks
- update: check_laserlok.asm – updated to handle older (v3) versions of laserlok
- update: check_passlock2000.asm – improved detection
- update: check_reflexivearcade.asm – executables builds are now reported (if found)
- update: check_safedisc.asm – updated to detect safedisc lite
- update: check_securom.asm – updated to handle VERY old versions & updated to detect a modified paul.dll
- update: check_solidshield.asm – minor modifications, but results in better reporting
- update: check_starforce.asm – updated to handle the new variant (v5.5) and also report bitness of the exe
- update: check_sysiphus.asm – optimized detection
- update: check_themida.asm – updated to handle dll protected Themida files
- update: check_vmprotect.asm – added new generic detection code (catches now dlls we missed before)
- update: check_upx.asm – improved to be ‘more generic’
- update: check_vob.asm.asm – updated to handle older version (4 or less)
- update: dongle_guardant.asm – added reporting of old Guardant Dongle Protections
- update: dongle_hasphlenvelope.asm – improved detection
- update: license_sentinellm – improved for better detection
- update: installer_7zip.asm – improved detection
- bugfix: check_telock.asm – fixed v1.0 detection
- bugfix: check_yzpack.asm – fixed bug resulting in non detections
- bugfix: installer_installshield.asm – fixed possible non detections
CD/DVD/Image file/sector scan
- new: b6i image added into the supported file list
- new: added in ‘Extract Boot Sector’, now the boot sector from the cd/dvd can
be ‘extracted’ to a file.. for use with something else maybe 
- new: cddvd_cactus.scan.asm – Cactus Audio detection added to file scan in cddvd module
- new: cddvd_protectdisc.scan.asm – added in sector scan module for protectdisc / protectcd
- update: if a disk is detected as being protected when making the iso, the user will be prompted to continue or not
- update: sector stuff – updated handler to handle udf format disks (BEA01 header instead of CD001)
- update: sector scan – tweaked sector scan for tages a little
- update: sector scan – tweaked the safedisc detection code
- update: sector scan – updated to now NOT stop if a sector 16 read failure happened
- update: sector scan – securom scan updated to handle version 4.x (and probably lower),
which used a different ‘fingerprint’ and some minor tweaks / fixes
- update: sector scan – starforce + starforce keyless scan was heavily updated..
reducing probability of false positives as well as catching some we missed before
- bugfix: sector scan – codelok scan fixed
Download here:
http://pid.gamecopyworld.com/ProtectionID_v6.1.3_2k8_xmas.rar
AutoRuns for Windows v9.37 January 7, 2009
Posted by reversengineering in OTHER, TOOLS.add a comment
AutoRuns for Windows v9.37 By Mark Russinovich and Bryce Cogswell Published: December 19, 2008 Introduction This utility, which has the most comprehensive knowledge of auto-starting locations of any startup monitor, shows you what programs are configured to run during system bootup or login, and shows you the entries in the order Windows processes them. These programs include ones in your startup folder, Run, RunOnce, and other Registry keys. You can configure Autoruns to show other locations, including Explorer shell extensions, toolbars, browser helper objects, Winlogon notifications, auto-start services, and much more. Autoruns goes way beyond the MSConfig utility bundled with Windows Me and XP. Autoruns’ Hide Signed Microsoft Entries option helps you to zoom in on third-party auto-starting images that have been added to your system and it has support for looking at the auto-starting images configured for other accounts configured on a system. Also included in the download package is a command-line equivalent that can output in CSV format, Autorunsc. You’ll probably be surprised at how many executables are launched automatically! http://download.sysinternals.com/Files/Autoruns.zip
StrongOD v0.2.1.267 [20090107] January 7, 2009
Posted by reversengineering in OLLY'S PLUGINS, TOOLS.add a comment
http://vip-file.com/download/7ae084949790/StrongOD-v0.2.1.rar.html
eXPressor.v1.6.0.1.Professional January 7, 2009
Posted by reversengineering in PROTECTOR, TOOLS.add a comment
this program is suitable for creating lock for softwares which you want to ship with cd or dvd.
keygen is created bt Fighting For Fun (FFF).
http://www.cgsoftlabs.ro/zip/eXPressor.zip
this keygen is created for professional version.
http://vip-file.com/download/50236f397802/eXPressor.v1.6.0.1.Professional-KEYGEN-FFF.zip.html
PhantOm Plugin v1.51 January 7, 2009
Posted by reversengineering in OLLY'S PLUGINS, TOOLS.1 comment so far
http://vip-file.com/download/066172511319/PhantOm-Plugin-v1.51.7z.html
see this link :”download with Very Slow Speed “
Dotnet Msil Dumper 0.4 January 7, 2009
Posted by reversengineering in .NET, TOOLS.add a comment
The idea of this tool is to achieve two objects:
1 – It will dump the body of every Method (Function, Procedure) called by the executable assembly you select, The dumping occurs whenever compiler enters that method, for example if you Click some button and this button calls method “CheckLicense” then you will find a file named “CheckLicense.txt” in the “\Dump” folder.
2 – It will show you in details the methods being called and also the modules that your application loads so it could be used as a simple tracing utility for .net assemblies.
I wrote this tool to help me rebuild assemblies protected with JIT hooking technique, those assemblies can’t be explored in Reflector because their methods’ body is encrypted and only decrypted in runtime when the method is called so you will see no code in reflector, I assumed that I will have access to the encrypted MSIL code of the methods using Profiling APIs, there was a 50% chance of success but it turned out to be only useful against certain protections like the one that LibX coded which depends on System.Reflection.Emit.DynamicMethod to excute protected methods.
you can find more on LibX protection here
hxxp://www.reteam.org/board/showthread.php?t=799
———————————————-
What’s NEW ?
1- fixed a major bug that could cause an overflow while dealing with huge functions
2- The “Log loading modules” has been fixed and can be disabled now to increase speed.
———————————————-
To do :
In next release I will add the ability to dump native compiled code of MSIL functions on the fly. I hope it’s worth the effort
http://portal.b-at-s.info/download.php?view.36
winhex 15.1 sr 8 January 7, 2009
Posted by reversengineering in HEX EDITOR, TOOLS.add a comment
WinHex is a universal hexadecimal editor, particularly helpful in the realm of computer forensics, data recovery, low-level data processing, and IT security. An advanced tool for everyday and emergency use: inspect and edit all kinds of files, recover deleted files or lost data from hard drives with corrupt file systems or from digital camera cards.
Features include:
- Disk editor for hard disks, floppy disks, CD-ROM & DVD, ZIP, Smart Media, Compact Flash, …
- Powerful directory browser for FAT, NTFS, Ext2/3, ReiserFS, CDFS, UDF
- RAM editor, providing access to other processes’ virtual memory
- Data interpreter, knowing 20 data types
- Editing data structures using templates (e.g. to repair partition table/boot sector)
- Concatenating and splitting files, unifying and dividing odd and even bytes/words
- Analyzing and comparing files
- Particularly flexible search and replace functions
- Disk cloning, with a specialist license also under DOS
- Drive images & backups (optionally compressed or split into 650 MB archives)
- Programming interface (API) and scripting (professional & specialist licenses only)
- 128-bit encryption, checksums, CRC32, hashes (MD5, SHA-1, …)
- Erase (wipe) confidential files securely, hard drive cleansing to protect your privacy
- Import all clipboard formats, incl. ASCII hex values
- Convert between binary, hex ASCII, Intel Hex, and Motorola S
- Character sets: ANSI ASCII, IBM ASCII, EBCDIC, (Unicode)
- Instant window switching. Printing. Random-number generator.
- Supports files >4 GB. Very fast. Easy to use.
&more
Homepage – http://www.winhex.com
http://vip-file.com/download/e52d5c906531/files.rar.html
happy new year 2009 is staring now December 31, 2008
Posted by reversengineering in NEWS.5 comments
happy new year
سا ل نو میلادی مبارک
PE Explorer v1.99 R5 FULL December 18, 2008
Posted by reversengineering in OTHER, TOOLS.1 comment so far
http://vip-file.com/download/d473ef664967/PE-Explorer-v1.99-R5-FULL.rar.html
ArmInline v0.96ff December 18, 2008
Posted by reversengineering in TOOLS, UNPACKERS.add a comment
Bugfix: A couple of bug reports filtered in over the years, all pertaining to the Nanomite loader. Two fairly important fixes were made, so I thought I’d publish them
http://vip-file.com/download/c4c4ab235065/Armadillo-ArmInline-0.96ff.zip.html
Request files Reup. December 18, 2008
Posted by reversengineering in OLLY'S PLUGINS, OTHER, Request, Scripts, TOOLS.add a comment
hi my friends
http://vip-file.com/download/c6ed40102967/HideSyser-v-1.94.rar.html
http://vip-file.com/download/99ab99480277/Thinstall-Package–Extractor.rar.html
http://vip-file.com/download/3b8847955758/VMProtect-1.7-IAT-Repair.txt.html
http://vip-file.com/download/997828206045/MagicHideOllyDbg-v-1.01.rar.html
http://vip-file.com/download/2c3ae6798317/Themida—WinLicence-1.x.x—2.x.x-CodeEncrypt-Repair.txt.html
سلامی دوباره December 18, 2008
Posted by reversengineering in NEWS, پارسی.1 comment so far
سلام به همه دوستان و برو بچ با صفا که همیشه مورد لطف شان بودیم و ما را همیشه شرمنده می سازند
خدا پشتو پناهتون
این چند وقت که نیومدم کلی این نت تغییر کرد
لت ایت بیت که ایران و تحریم کرد برای همین دیگه باید با پروکسی از سایتش دانلود کرد
بعدش اینترنت خودم در نامه بازی های رانژه و تغییر سرویس و غیره سرویس شد
بعدش هم کل اینترنت ایران
خلاصه
اگر الان با کمی مشکل از نظر فایلهای قدیم و اخبار جدید و… مواجه هستید به نظر من برای پوست مان خوب باشه
بیشتر ادما هم الان میرن تو خواب زمستونی و کریسمس و غیره که باعث میشه اوضاع همه چی اروم به نظر بیاد
خوب فعلن با شما خداحافظی میکنم تا یکم زیر افتاب زمستون برنزه بشم
!!!!!
سربلند و پیروز باشید
Thinstal Package Extractor December 9, 2008
Posted by reversengineering in OTHER, TOOLS.10 comments
http://letitbit.net/download/99ab99101406/Thinstall-Package–Extractor.rar.html
new scripts December 9, 2008
Posted by reversengineering in Scripts, TOOLS.3 comments
http://letitbit.net/download/e06f9c89948/MFC-Conditional-Breakpoint.txt.html
http://letitbit.net/download/2c3ae6144854/Themida—WinLicence-1.x.x—2.x.x-CodeEncrypt-Repair.txt.html
MagicHideOllyDbg 1.01 December 9, 2008
Posted by reversengineering in OLLY'S PLUGINS, TOOLS.1 comment so far
Here’s a quick list of MagicHideOllyDbg’s function:
- erases debug-heap padding
- erases BeingDebugged flag in the PEB
- erases NtGlobalFag in the PEB
- adjusts heap flags to default values
- disables kernel32!OutputDebugStringA() function
- forces kernel32!CheckRemoteDebuggerPresent() to always return an error
- forces kernel32!UnhandledExceptionFilter() to ignore debugger presence
- forces kernel32!Process32NextW() to return immediately
- forces ntdll!NtSetInformationThread() to ignore HideThreadFromDebugger class
- forces ntdll!NtQueryInformationProcess() function to ignore ProcessDebugPort class
- intercepts ntdll!NtQuerySystemInformation() function but does nothing with it
- randomises “CPU – ” text in OllyDbg
http://letitbit.net/download/997828455996/MagicHideOllyDbg-v-1.01.rar.html
HideSyser Plugin 1.94 December 9, 2008
Posted by reversengineering in OTHER, TOOLS.1 comment so far
Syser is a wonderfull tool but not have a lot of plugins for it. I make one plugin (in a beta stage) that have 2 functions:
- Use “gta” or “getaddr” command in Syser control panel for get a kernel function memory address, ex.”gta DbgPrint” and you get the memory entry point. Only works with Kernel exported functions (Kernel and Hal).
- Use “hide” command to hide Syser against NtCreateFile (a lot of programs try find Syser using it)
- Use “unhide” command to unhide Syser against NtCreateFile
It is a POC. Only tested in Windows XP Proffesional SP2/SP3 in VMWare and without VMWare with success
For install put in the %SystemFolder%\drivers\plugin\386i and reboot Syser
http://letitbit.net/download/c6ed40972286/HideSyser-v-1.94.rar.html
dup2.19 beta 4 December 9, 2008
Posted by reversengineering in OTHER, TOOLS.add a comment
Version:
Features:
-multiple file patcher
-create Offset and Search&Replace patch/loader
-compare files (RawOffset and VirtualAddress) with different filesize
-registry patcher, also for loaders
-attach files to patcher
-get filepaths from registry
-usage of CRC32 and filesize checks
-patching packed files
-compress patcher with your favorite packer
-saving projects
-use custom skin in your patcher
-add music (Tracker Modules: xm,mod,it,s3m,mtm,umx,v2m,ahx,sid) to patcher
-and many more…
http://diablo2oo2.di.funpic.de/stuff/dup2.beta.rar
Armadillo-6.x-HWID-Changer December 9, 2008
Posted by reversengineering in OTHER, TOOLS.2 comments
This Is A Simple Tool For Changing Armadillo 6.0.x Hardware ID In Standard Protection Mode
Armadillo Is A Bad Protector , Because You Can Crack It Without Any User And Key
Next Time I Release My Tool For Armadillo Cracking
http://vip-file.com/download/8af781236861/Sh4DoVV-Armadillo-6.x-HWID-Changer.rar.html
Tola Patching Engine December 9, 2008
Posted by reversengineering in OTHER, TOOLS.add a comment
http://s2.ipicture.ru/uploads/081208/BfTTGhSDJY.png
http://vip-file.com/download/5da9b2328045/Tola.rar.html
VMProtect 1.7 IAT Repair December 9, 2008
Posted by reversengineering in Scripts, TOOLS.add a comment
http://vip-file.com/download/3b8847487035/VMProtect-1.7-IAT-Repair.txt.html
VMware ThinApp 4.0.1-2837 December 9, 2008
Posted by reversengineering in OTHER, TOOLS.add a comment
” ..This a maintenance release that addresses a number of known issues. It also delivers some nice
additions to utilities within the ThinApp Suite including the ThinReg application..”
- The following features have been added for this release :
The thinreg.exe utility has been enhanced, facilitating file type association. It also includes support for DDE, extra verbs, and MIME type registration.
Enhanced support for double-byte applications and double-byte locales.
Enhanced support for 16-bit MSDOS programs.
Support for control panel extensions. Some applications, such as QuickTime or the mail applet for Microsoft Outlook 2007, have control panel extensions that you can now see in a ThinApp environment.
Ability to register files other than .exe files. For example, if you install an application that installed a README file or has another link to documentation, you can access those files.
Protocol registration. If an application invokes SMTP or HTTP, ThinApp starts any virtual applications that can handle the tasks. If ThinApp cannot locate virtual applications, ThinApp invokes native applications to handle the tasks.
ThinApp includes the RequiredAppLinks parameter in the Package.ini file. Previously, the user had to manually add this parameter.
ThinApp makes the MSI build template accessible to users to customize the MSI database.
User documentation has been restructured to start with basic functionality targeted at the novice user, building towards advanced functionality regarding deployment and customizations.
Log Monitor now supports the ability to pause and resume trace file capture.
Application link now supports multi-level links, such that application A links to application B, which links to application C, and so on.
Special entrypoints cmd, regedit and iexplore are marked with an asterisk (*) to denote these are not virtual applications. Rather, they load respective native EXEs in virtual environment.
Isolation mode can now be specified at the root of registry (for example, for HKCU, HKLM).
Stub executables changed to improve security and interaction with roaming profiles and system-installed applications.
Support for creating MSI distribution larger than 2GB (requires separate CAB file to be distributed).
Support for creation of compressed trace files.
Support for running ThinApp application on GoGlobal platform.
Support packaging application wrapped with the “Shrinker” packer.
…and more :
vmware.com/support/thinapp4/doc/releasenotes_thinapp401.html
http://rapidshare.com/files/171695546/4.0.1-2837.zip