25 September 2007

Quick Unpack v2.0 Final

1 comments
At last I decided to release 2.0 final. Maybe there are still several bugs left but that what support is needed for In plans for future I want to change the engine for something astonishing (not sure if it will be public) and to make existing OEP-finders also work with DLLs. So stay tuned


v2.0 final
[!] fixed many bugs like missed import functions
[!] fixed several driver bugs like the one which didn't allow to pass some exceptions
[!] improved export feature now supports invalid functions
[!] many improvements (like 256x256 icon for Vista, thanks to Feuerrader ) and optimizations (like better memory handling)
[!] now Force.dll doesn't use GenOEP.dll, though some code was borrowed
[+] added so long-waited ability to use scripts. before using scripts it's strongly recommended to read the manual (Scripts.eng.txt file). script examples may be taken from Scripts folder (*.lua files), scripting language LUA manual also can be found there (LUA Manual.html), which parser was embedded in the program. BTW I know that Step button doesn't work like a charm but I wasn't able to make it better
[+] passing parameters to the application added
[+] import list from imprec feature added (now Quick Unpack supports both export and import of import functions in imprec-compatible files this allows to edit some functions or add new ones. keep in mind this option works with normally created files but if you put some garbage or format this file in unusual manner this may cause crash I was too lazy to parse the file with care)
[+] attach process feature added (this option allows to choose any module in a process for unpacking and has some features. if in processes listbox a process name is a full path with name you can attach to this process. if it is only name of the file you don't have enough rights to attach. you can't specify the OEP, the instruction the program was stopped is treated as the OEP. to use attach process feature one should load the program in any debugger and manually get to the OEP, when attach to that process with Quick Unpack. keep in mind that for smart import recovery you don't need the program to run, it can just be left in the debugger standing at the breakpoint. but to use smart import recovery with tracer you should put it in the infinite loop (EB FE) and run the program because the tracer uses current thread for tracing. if the program was put in the infinite loop don't forget to restore these two bytes in the dump. when attached tracing import is unreliable and very slow, so it's not recommended to use it). this feature allows to use Quick Unpack as a dumper and import recoverer (my attempt to replace PETools and ImpRec with one program )
[+] imprec plugin support added (this feature allows to use imprec tracer plugins in Quick Unpack to restore import functions. keep in mind when using attach to process feature the program must be run for the tracer to work)
[+] added UsAr's generic OEP finder. I modified it a bit
[+] added Human's generic OEP finder. I modified it a bit
[+] added deroko's generic OEP finder. I modified if a bit and took the GUI from Human's generic OEP finder. it's sometimes slow but rather powerful and be warned that this finder uses driver and the driver is unloadable till next reboot. uses deroko's Dream of every reverser engine so incompatible with win2k3 and kaspersky. for more information about this engine visit http://deroko.phearless.org
[-] no more old non-generic OEP finders

Download:
http://qunpack.ahteam.org/wp-content/uploads/2007/09/qunpack20.zip

Mirrors: http://www.hacker.com.cn/down/view_14702.html

Info: http://www.3800hk.com/Soft/zhly/19567.html
http://www.hacker.com.cn/down/view_14702.htm
http://www.0wei.com/thread-23679-1-1.html


Quick Unpack 2.0 final for Windows 2000/XP/2003/Vista
(c) stripper engine by syd
founded by FEUERRADER [AHTeam]
(c) coded by Archer

19:35:56 - Opened utorrent 1.7.5_fake2x_leecher.exe
Quick self analyze.... PECompact 2.xx
PESniffer EP Scan: PECompact v2.xx
PEiD scanning... PECompact 2.x -> Jeremy Collake

if 2 difficult: Unpecomp2.exe

so some mods can look and see now that the files there and in history by all known coders do not have any call homes integrated/added but in the original uT/bT the stats.domain.com is disappeared in the later builds or we are all blind and do not more found it since all builds beginning from late August.

apple juice, eMule.0.48a.Titandonkey.v4.11-Bin, eMule.0.48a.Razorback3.Next.Generation.v4.11, eMule.v0.48a.Wikinger-Mod, sun power,... and the rest of apple juice
based ExeStealth V2.76 to prepare plugin required.

copy OEPFinders files from the older version in addition for full support of known unpacking types

more tools:
Homepage: http://qunpack.ahteam.org/
http://www.hacker.com.cn/down/list_232.html

VMUnpacker V1.3

1 comments

VMUnpacker V1.3

This tool based on the technology of virtual machine, it could unpack various known & unknown packers. It is suitable for unpacking the protected Trojan horse in virus analyses, and because all codes are run under the virtual machine, so they will not take any danger to your system..

This product is free software; you can download it, install it, copy it and distribute it noncommercially; If you want use it for commercial sale, copy and distribute, you must get the warranty and permission of DSWLAB before(for example, if the anti-virus company want to use it to analyses the Trojan horse in batches, he must get mandate and permission of DSWLAB before).

By testing, this version could support 61 kinds packers (include more than 300 versions).
¡¡¡¡The detailed list:
¡¡¡¡
upx 0.5x-3.01 All Version
BeRoEXEPacker
aspack 1.x--2.x All Version
PEcompact 0.90--1.76 2.06--2.79 All Version
fsg v1.0 v1.1 v1.2 v1.3 v1.31 v1.33 v2.0 All Version
vgcrypt v0.75
nspack 1.4--4.1 All Version
expressor v1.0 v1.1 v1.2 v1.3 v1.4 v1.501
npack v1.5 v2.5 v3.0
dxpack v0.86 v1.0
!epack v1.0 !epack v1.4
bjfnt v1.2 v1.3
mew5 mew v1.0 v1.1
packman v1.0
PEDiminisher v0.1
pex v0.99
petite v1.2 v1.3 v1.4 v2.2 v2.3 All Version
winkript v1.0
pklite32
pepack v0.99 v1.0
pcshrinker v0.71
wwpack32 1.0--1.2
upack 0.1--0.399
rlpack 1.11--1.19
exe32pack v1.42
kbys v0.22 v0.28
yoda's protector v1.02 v1.025 v1.03.2 v1.03.3
yoda's crypt v1.1
yoda's crypt v1.2 v1.3 v1.xModify
XJ
exestealth 2.72--2.76
hidepe v1.0 v1.1
jdpack v1.01 v2.1 v2.13
jdprotect 0.9b
PEncrypt v3.0 v3.1 v4.0
Stone's PE Crypt v1.13
telock v0.42 v0.51 v0.60 v0.70 v0.71 v0.80 v0.85 v0.90 v0.92 v0.95 v0.96 v0.98 v0.99
ezip
hmimys_pack v1.0
lamecrypt v1.0
depack
polyene v0.01
dragonArmour
EP Protector v0.3
PackItBitch
trojan_protect
anti007 v2.5 v2.6
mkfpack
yzpack v1.1 v2.0
spack method1 spack method2
naked packer v1.0

upolyx v0.51
stealthPE v1.01 stealthPE v2.2
mslrh v0.31 v0.32
mslrh v0.2 == [G!X]'s Protect
morphine v1.3 morphine v1.6 morphine v2.7
rlpack full edition
EXEFog v1.1
ASDPack
PEBundle
Neolite


VM Unpack Engine SDK£º

The commercial VM Unpack Engine SDK will be provided solemnly (VM Unpack Engine SDK).

Use VM Unpack Engine SDK, the developer does not need to care about the unpacked course and method, only needs to transmit the data to VMUE SDK, VMUE will finish analyzing and unpacking automatically. VMUE supports to send the result of unpacking to the file and memory at the same time, and returns OEP after unpacking directly, It help you unpack packers in your products and tools.

Rebuild PE file after unpacking, such as repair the import table, Overlay, etc. offer the essential condition that rebuilding can running EXE program.

VMUE SDK includes the following part mainly:

Relevant dynamic or static link libraries
VMUE SDK technological white paper and the document about the interface of SDK
Codes of calling VMUE SDK
Packer's signature library in binary
Other auxiliary routines and codes

Homepage: http://www.dswlab.com/d3.html

Download: http://download.pchome.net/utility/antivirus/trojan/download_66883.html
(required IE, website will reject Firefox DL requests)

old Version VMUnpacker V1.2

1237905 Bytes
MD5 :9ae1be34ca2926e276c80d6c304ca25e
www.dswlab.com


upx 0.5x-3.00 All Version
BeRoEXEPacker
aspack 1.x--2.x All Version
PEcompact 0.90--1.76 2.06--2.79 All Version
fsg v1.0 v1.1 v1.2 v1.3 v1.31 v1.33 v2.0 All Version
vgcrypt v0.75
nspack 1.4--4.1 All Version
expressor v1.0 v1.1 v1.2 v1.3 v1.4 v1.501 / 网友称闪电壳
npack v1.5 v2.5 v3.0
dxpack v0.86 v1.0
!epack v1.0 !epack v1.4
bjfnt v1.2 v1.3
mew5 mew v1.0 v1.1
packman v1.0
PEDiminisher v0.1
pex v0.99
petite v1.2 v1.3 v1.4 v2.2 v2.3 All Version
winkript v1.0
pklite32
pepack v0.99 v1.0
pcshrinker v0.71
wwpack32 1.0--1.2
upack 0.1--0.32 0.33--0.399
rlpack 1.11--1.14 1.15--1.18
exe32pack v1.42
kbys v0.22 v0.28 / 网友称涛涛压缩器
yoda's protector v1.02 v1.025 v1.03.2
yoda's crypt v1.1
yoda's crypt v1.2 v1.3 v1.xModify / 网友修改版
XJ / 国产仙剑望海潮壳
exestealth 2.72--2.76
hidepe v1.0 v1.1
jdpack v1.01 v2.1 v2.13
jdprotect 0.9b
PEncrypt v3.0 v3.1 v4.0
Stone's PE Crypt v1.13
telock v0.42 v0.51 v0.60 v0.70 v0.71 v0.80 v0.85 v0.90 v0.92 v0.95 v0.96 v0.98 v0.99
ezip
hmimys_pack v1.0
lamecrypt v1.0
depack
polyene v0.01
dragonArmour
EP Protector v0.3
PackItBitch
trojan_protect / 木马彩衣 //国内常用的木马伪装工具
anti007 v2.5 v2.6
mkfpack
yzpack v1.1 v2.0
spack method1 spack method2
naked packer v1.0

upolyx v0.51
stealthPE v1.01 stealthPE v2.2
mslrh v0.31 v0.32
mslrh v0.2 == [G!X]'s Protect
morphine v1.3 morphine v1.6 morphine v2.7
rlpack full edition

download

Testfile sarim's x1000 Leecher mod yoda's Protector V1.03.3 -> Ashkbiz Danehkar Support
Unpack successfully!
Output path: .... /1000x_unpacked.exe
File before: 1000x.exe (268 KB)
File unpacked: 1000x_unpacked.exe (580 KB)

Welcome to use this software and feedback the question to support#dswlab.com

If you have any question in using, send us email and we will try to help; please post the unpacked program in mail; it is better that you post the packed tool of the program.
Email: support#dswlab.com.


Supercop£ºKill various kinds of Trojan horse completely, protect the security of system in an all-round way.
more free tools download£ºhttp://www.dswlab.com
Specialized desktop and safe products of content http://www.unnoo.com

Archived older unpacking goods: http://www.xfocus.net/tools/

Tool download contains english and chinese version. Tool unpacking is done for check if virus inside exe protected files.
see intro: http://scheinsicherheit.pytalhost.de/procedure2.htm
PCHOME download1 download2

http://wordpress.com/tag/unpacking/

>>> End Of Section Leecher mods <<<

0 comments
The question is why should we eat the food what we get if everyone can cook by self!?

We close the section Leecher Mods and jump direct to unpacking / creating patches etc. Reverse engineering over, so we are able to provide the tools to everyone can do its own mod. As seen in Sarmin's aka snake doctor aka S... (names), as seen in emule, all mods based on Apple Juice etc...
  • You will found here and on other places detail instructions how to edit code (hexeditor)
  • How to dissamble with ollydbg and other stuff.
  • What is to do to create this and that to change a to z.
  • How you can make your own mod and change others, create patches.
  • About User Agent (UA) torrent client id's a good source is RatioMaster 1.7.5 updated release (spoof / UA ID extended)
    by open the *.client files (for example utorrent_1.6.1_build_(483).client > = -UT161B- / uTorrent/161B(483*) so you can put for example btuga_218.client id into uTorrent (*ref %d point to version, rem it in uT/BT6 out) or every client of your choice BitComet/BitSpirit,... by replacing the UA in winhex or any hexeditor. User-Agent: BTuga/Revolution-2.6 / prefix= R26--- *%d
It's maybe for some Visitors to difficult but Downloads of Leecher Mods for P2P you found on every corner in the net. How to operate P2P clients etc.. for this answers exist forums everywhere.

24 September 2007

µtorrent 1.7.5 Leecher Pack with User Agent uT 1.6

1 comments
 I love utorrent I love uT EdiTion no Installer

µtorrent 1.7.5 mult10_leecher.exe
- upload reported to tracker with multiplicator 10

µtorrent 1.7 mult100 leecher.exe
- upload reported to tracker with multiplicator 100

µtorrent 1.7 mult1000 leecher.exe
- upload reported to tracker with multiplicator 1000

µtorrent 1.7.5 mult10_seeder.exe
- upload reported to tracker with multiplicator 10
- download not reported to tracker
- you shown as seeder
- complete flag not send to tracker (no snatchlist entry)

µtorrent 1.7.5 fake2x_leecher.exe
- upload reported to tracker with 2 infront of real upload

µtorrent 1.7.5 fake2x_seeder.exe
- upload reported to tracker with 2 infront of real upload
- download not reported to tracker
- you shown as seeder
- complete flag not send to tracker (no snatchlist entry)

µtorrent 1.7.5 noreport.exe
- upload and download not reported to tracker
- complete flag not send to tracker (no snatchlist entry)
- you will shown as 0 % finished

µtorrent 1.7.5__report.exe
- only upload reported to tracker
- you shown as seeder
- complete flag not send to tracker (no snatchlist entry)

µtorrent 1.7.4__stealth.exe
- you are not shown on tracker during filetransfer (no peerlist entry)
- Caution: works not on all tracker !!!

µtorrent 1.7.5__DHT.exe
- private flag will be ignored
- DHT always enabled

CALL HOME IN ALL MODS REMOVED !!!

Download:

µtorrent 1.7.5 LP EMU 1.6 extra.rar (2.3 MB) - Mirror

Temporärer Beitrag, der zur Formaterkennung verwendet wurde (7fc87fce-bb87-4682-9382-f26fcba699f0)

0 comments

Dies ist ein temporärer Beitrag, der nicht gelöscht wurde. Löschen Sie diesen Beitrag manuell. (10c0d9cf-19d2-43c6-8f7f-1597e40aefe9)

23 September 2007

BitComet Custom lite - Download v1.5

0 comments
Custom BitComet is a free download for BitComet kernel-based, customizable dedicated resources for downloading. To be specific document provides customizable interface for downloading client, to facilitate the realization of large-scale online games and download the streaming software. BitComet download of customized integrated BitComet algorithm prototype combines BT's efficient distribution and the stability P2SP downloading, code more concise, very low memory and CPU consumption, greatly increasing the efficiency of the download to guarantee the quality of the download, save server bandwidth.

Features completely free, users simple, single-button download, and very stupid.
By BitComet core stability, high efficiency and low occupancy resources.
Using BT server technology significantly save bandwidth, servers can not support the addition of thousands of users downloaded at the same time.
P2P using distributed technology ensures the quality that each user can download a success.
BT seamlessly combines the efficient distribution and the stability P2SP download, while ensuring the efficiency and quality of services distributed, even users of the network can also use BT can guarantee download speed.
The system can be high, easy customization simple, custom compression for subsequent download size of only about 800KB.

info and mirrors: http://www.anxz.com/down/3305.html
Download: BitCometLiteMaker_1.5.exe (1.21 MB) (PECompact)
Full: BitCometLiteMaker_1.5_unpacked.exe

Archive