24 February 2008

µTorrent 1.8 alpha 8682

0 comments
µTorrent 1.8 Build 8682µTorrent Version 1.8 alpha build 8682 changelog
2008-02-24:
- Fix: crash when right-clicking category view

2008-02-23: Version 1.8 alpha (build 8680)
- Feature: support 'failure reason' in scrape response
- Feature: optional piece progress bar
- Change: (yet another) new installation dialog
- Change: More informative error message for misc. autoupdate errors
- Change: Return to 1.7-style RSS errors
- Change: remove 1000 files warning in create torrent
- Change: Turn off sparse files and turn on compact allocation by default on Vista, because it has a terrible bug
- Change: don not enable a feed when Update Feed is selected
- Change: send rejects to FAST extension peers that request the same piece again before it's sent
- Change: grey out Update Feed when feed is disabled
- Change: change Toggle Feed to Enable/Disable Feed
- Change: update free space on focus change in create torrent
- Change: some RSS speed optimizations for large history and feed item counts
- Fix: Tab order issues in Add Feed dialog
- Fix: magnet URI download directory is now default download directoy
- Fix: Display of "&" characters in title of folder browsing dialog on Windows versions less then Vista, and give Vista version a title
- Fix: Preferences tab order
- Fix: Longstanding bug where dialogs that inside tab controls did not have the proper background when using XP themes
- Fix: Issue where it would stay as admin user after autoupdating through a normal user
- Fix: element not found and 99% cpu bug with partfiles
- Fix: piece picker bug that would cause it to start more equally rare pieces than needed
- Fix: key sort order with extension handshake
- Fix: download bar toggle
- Fix: external IP detection with NAT-PMP and non-conforming routers (like the Airport Extreme...)
- Fix: rare "invalid packet length" bug with encrypted connections
- Fix: Feed names not displaying unicode characters properly in category view
- Fix: Element Not Found when using partfiles with compact allocation

Downloads

uncompressed
False positive must be lower as the original upx version 3.00 compressed.

See section, res,... and construction in a good hex viewer!

http://download.utorrent.com/beta/utorrent-1.8-alpha-8682.uncompressed.exe (549 KB)
utorrent-1.8-alpha-8682.trim.exe (504.50 KB) /keep overlay /internal crc correct
utorrent-1.8-alpha-8682.rebuild.exe (506.00 KB)
utorrent-1.8-alpha-8682.uncompressed-rebuild.exe (573.11 KB)

Compression Comparison:

utorrent-1.8-alpha-8682.WinUPack039.exe (246.32 KB) - stability ?
utorrent-1.8-alpha-8682.XComp 0.98-LZMA.exe (248.75 KB) - (~246.27 KB is possible)
utorrent-1.8-alpha-8682.trim-XComp0.98-LZMA.exe (248.76 KB)
utorrent-1.8-alpha-8682.uncompressed-rebuild-XComp0.98-LZMA.exe (249.25 KB)
utorrent-1.8-alpha-8682.trim-PEC2.8b5.exe (251.00 KB)
PEC2.80B5: /Cl:9 /Wl:No /Dt:Small /Cic:No /Ri:No
utorrent-1.8-alpha-8682.upx.exe (255.80 KB) Original UPX 3.00 (higher UPX Versions as 3.00 can produce more false positive by utorrent.exe / bittorrent.exe, see LZMA lib also by using XComp with utorrent.exe/bittorrent.exe)
utorrent-1.8-alpha-8682.upx302.exe (255.80 KB)
--best --ultra-brute --all-methods --all-filters
utorrent-1.8-alpha-8682.yzpack12-LZMA.exe (262.87 KB)
utorrent-1.8-alpha-8682.rebuild-XComp-LZSS.exe (273.36 KB)
utorrent-1.8-alpha-8682.trim-XComp0.98-LZSS.exe (273.37 KB)
utorrent-1.8-alpha-8682.nPack11.exe (283.50 KB)
utorrent-1.8-alpha-8682.yzpack2b.exe (290.45 KB)
utorrent-1.8-alpha-8682.FSG20.exe (290.75 KB)
utorrent-1.8-alpha-8682.rebuild-XComp0.97-LZRW.exe (311.79 KB)
utorrent-1.8-alpha-8682.trim-XComp0.97-LZRW.exe (311.79 KB)

Ignore the AV scanner results which shown Packer.XComp, Packer.byDwing (UPack), Packer.YZPack, Packer.FSG.A, Packer.RLPack and some other Packers as a Virus. It's a False Positive.
These Antivirus Scanner can not scan inside the packed file. A Product fault by some Antivirus Programs. Changing to a better AV Security Solution will fix it.


PE id Signatures see: Exeinfo PE http://www.exeinfo.go.pl it detect with Anti Cheat Mechanism up to all kinds of packer, compressor detector + shows unpack info and hints to see how a file is done.
(PEiD doesn't recognize new(er) Files for example utorrent 1.7.7 Original uncompressed from utorrent website show Armadillo 1.x instead of Microsoft Visual C++ ver 7 - not packed -)

Unpacker: RL!de + sdk + kit + extras (updated latest version):
RL!de+sdk+kit.zip

Sandboxie - Trust No Program!
http://www.sandboxie.com

Tired of dealing with rogue software, spyware and malware?
Tired of spending countless hours removing unsolicited software?
Try Sandboxie.
When you run a program on your computer, data flows from the hard disk to the program via read operations. The data is then processed and displayed, and finally flows back from the program to the hard disk via write operations. For example, if you run the Freecell program to play a game, it starts by reading the previously recorded statistics, displaying and altering them as you play the game, and finally writing them back to disk for future reference.
Sandboxie changes the rules such that write operations do not make it back to your hard disk. Protecting your Freecell statistics using Sandboxie may be a good idea when a less qualified player comes along, but you will probably want to play most of your games outside the sandbox. On the other hand, you may want to run your Web browser inside the sandbox most of the time. This way any incoming, unsolicited software (spyware, malware and the like) that you download, is trapped in the sandbox. Changes made to your list of Favorites or Bookmarks, hijacking of your preferred start page, new and unwanted icons on your desktop -- all these, and more, are trapped in and bound to the sandbox. You could also try a new toolbar add-on, browser extension or just about any kind of software. If you don't like it, you throw away the sandbox, and start again with a fresh sandbox. On the other hand, if you do like the new piece of software, you can re-install it outside the sandbox so it becomes a permanent part of your system. Sandboxie intercepts changes to both your files and registry settings, making it virtually impossible for any software to reach outside the sandbox. Sandboxie traps cached browser items into the sandbox as a by-product of normal operation, so when you throw away the sandbox, all the history records and other side-effects of your browsing disappear as well.
Sandboxie is free so you really don't have to look around for an alternative.

However, if you still don't like or can't use Sandboxie for whatever reason, here are some alternatives.
Anti-Virus Software, Anti-Spyware Tools
These tools scan your computer files and registry settings looking for known viruses and unsolicited software (spyware). Such tools can only remove some viruses and spyware but also produce a lot of false positive alerts. They can be wrong or right or not identify, and usually only after that software has made its way into your computer. Contrast this with the Sandboxie approach, which keeps the viruses and spyware trapped in the sandbox, and makes them disappear when you throw away the sandbox.
Untrusted Browsing
The ActiveX mechanism lets Web sites run little programs in your computer. These are mostly well-natured programs, for example automatic download managers or automatic toolbar installation. Some not-so-well-natured Web sites use this mechanism to install spyware into your computer. You could browse with ActiveX disabled (by turning it off, or by switching to a browser that doesn't offer support for ActiveX), but you would be trading security over functionality. With Sandboxie, you can keep ActiveX turned on, and have both security and functionality.

Version news: http://www.sandboxie.com/index.php?VersionChanges#v_3_22

Sandboxie.v3.22 32bit (393.31 KB) - Sandboxie.v3.22 32bit+64bit (707.37 KB)

A Trojan makes online connections out and incoming. A good Firewall in extension to a NAT tells you not only a short overview of these connections. The full trace log with details for example by browsing the web, not just the domains, DNS, Ip's but the full url's to and from destinations up to the file extensions by request in the internet online traffic. With a connection monitor it shows you if something is wrong on all protocols. It will alert you if a component from your hard disk starts to make or receive connections and you can tracing the ways, set the access control, terminate single connections, add them to your own black list, forbid applications to go online. For example if a picture program go online its suspicious it have no messenger, email or web browser except it have picture upload function to your ftp website in the menu. If a program begins to do online update you can capture the url and download the update file if you want an update manual. Also you can block online updates.

µTorrent is a lightweight and efficient BitTorrent client for Windows - Version 1.7.7 micro compression Test

2 comments
Packers in latest Versions used with max compression settings

- not packed -
utorrent-trim.exe 420.00 KB
utorrent-rebuild.exe 424.50 KB

- Compression Test packed -
utorrent-RLPack-aplib.exe 235.95 KB - APLIB -
utorrent-RLPack-lzma.exe 214.63 KB - LZMA -
utorrent-aspack212.exe 223.00 KB
utorrent-org-upx300.exe 214.80 KB - Original -
utorrent-nspack.exe 211.50 KB
utorrent-pec28b5.exe 210.50 KB - LZMA -
utorrent-xcomp098.exe 209.27 KB - LZMA -

(PEiD doesn't recognize new(er) Files for example utorrent 1.7.7 original uncompressed from utorrent website show Armadillo 1.x instead of Microsoft Visual C++ 7 - not packed -)

VundoFix 6.7.08

2 comments
VundoFix is a removal tool for Virtumonde - aka Winfixer.

VundoFix is a freeware removal tool for many of the known variants of Trojan.Vundo, Trojan.Conhook and other similar infections.

Vundofix Screenshot

http://www.atribune.org/public-beta/VundoFix.exe

To use Vundofix:
- Download the file and then double-click *VundoFix.exe* to run it.
- Put a check next to *Run VundoFix as a task.
- You will receive a message saying vundofix will close and re-open in a minute or less. Click *OK*
- When VundoFix re-opens, click the *Scan for Vundo* button.
- Once it's done scanning, click the *Remove Vundo* button.
- You will receive a prompt asking if you want to remove the files, click *YES*
- Once you click yes, your desktop will go blank as it starts removing Vundo.
- When completed, it will prompt that it will shutdown your computer, click *OK*.
- Turn your computer back on.

VundoFix 6.7.08
File Size: 129KB
Language: English
OS: Win2000/XP/2003
License: Free
Homepage: http://www.atribune.org/

More Info: http://vundofix.atribune.org/



Another great Freeware tool is Multi Temp File Cleaner 'ATF-Cleaner'

This program is for XP and Windows 2000 only

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser

Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

This will remove all files from the items that are checked so if you have some cookies you'd like to save. please move them to a different directory first.

Notes for Windows Vista users:

On Windows Vista that "Windows Temp" is disabled, to empty "Windows Temp" ATF-Cleaner must be "Run as an Administrator"
Prefetch has been disabled on Windows Vista. As I'm not sure the effects that emptying prefetch on Windows Vista will have for the time being it I won't enable that function.

Homepage: http://www.atribune.org/content/view/25/2/
Download: http://www.atribune.org/public-beta/ATF-Cleaner.exe

I thought it's a good object to make a small compression ratio test:
original upx 2.91 packed size: 49,50 KB
uncompressed: 292,00 KB
PE trimmed: 280,50 KB
YZPack 2.0b compressed: 52,20 KB
XComp 0.98 compressed in lzma mode: 44,67 KB ( ~ 44,42 KB is possible )
FSG v2.0 compressed: 52.82 KB
PECompact 2.80 Beta 5 compressed: 45.50 KB (max settings, longest comp time from all except upx with max comp settings)
UPX 3.02w compressed: 45.50 KB (all possible combinations, longest compression time from all)
Remark: VirtualProtect

22 February 2008

IE7Pro 2.1 RC1 for x64 and x86

0 comments
Changelog:

1. Change IE7Pro icon
2. Optimize inline search hotkey
3. Support download dailymotion video

Download:

IE7Pro 2.1 RC1 x86
MD5:7e845331aa97592c0a7b697ad6a30d6c


IE7Pro 2.1 RC1 x64
MD5:3278e2f5207dcd5f84efa44d6186dfdd

Report Bugs to this forum

support x64 win2k3, win2k6, win xp x64, IE 6, IE 8 Alpha's tested.
on 2k3 svr: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; WOW64)
2k6 pre: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; WOW64)



Extras: Easy Homepage
Ad Blocker Latest: filter.ini
or convert: http://easylist.adblockplus.org/

Windows XP SP3 Build 3311 RC2 Direct Download

1 comments
MICROSOFT WINDOWS XP SERVICE PACK 3 v.3311

OS String: Build 2600.xpsp.080212-0005 (Service Pack 3, v.3311)
Files Version: 5.1.2600.3311 (xpsp.080212-0005)


Windows XP SP3 RC2 build v.3311 English
Windows XP SP3 RC2 build v.3311 Deutsch

Digital Signature Date: February 12, 2008
Digital Signature Dienstag, 12. Februar 2008 21:10:42

Windows Service Pack 3 Build 3311 stand alone installer

German:
http://www.download.windowsupdate.com/msdownload/update/software/svpk/2008/02/windowsxp-kb936929-sp3-x86-deu_899afd304b10725603494bbb2145176d5cd0fd8c.exe
XP SP3 v.3311 German 312 MB
MD5: E8D6D28195E3BD8772E7EA9684D138D5
SHA1: 899afd304b10725603494bbb2145176d5cd0fd8c

English:
http://www.download.windowsupdate.com/msdownload/update/software/svpk/2008/02/windowsxp-kb936929-sp3-x86-enu_9afedbd6b2941bf568c27046d6688e6ccb5ce018.exe
XP SP3 v.3311 English 315 MB
MD5: 043391FB959D5623BD42EA376452F203
SHA1: 9afedbd6b2941bf568c27046d6688e6ccb5ce018

Japanese:
http://www.download.windowsupdate.com/msdownload/update/software/svpk/2008/02/windowsxp-kb936929-sp3-x86-jpn_683ab4e349c40edb8f6750d3b87bd69218641ed1.exe
XP SP3 v.3311 Japanese 324.5 MB

Windows XP Service Pack 3, v.3311


capture driver + a tool to leech all the rest content in folders, skip web server 'directory listing denied restrictions':
http://www.download.windowsupdate.com/msdownload/update/software/svpk/2008/02/


Mirror Build 3311 English - ENU
Mirror Build 3311 German - DEU
TCPIP.SYS Maximum Connection Limit 50 > Unlimited for P2P - Patch

using xp-AntiSpy.exe - Homepage: http://www.xp-antispy.org


As by all SP3 Build before after install the AMD Power Managment Driver get lost and needs to reinstall from Windows Update Site
Advanced Micro Devices - Other Hardware - AMD Processor

Advanced Micro Devices - Other

Please use RefControl to replace send referer with root domain name or disable referer.

Source maybe: http://blog.chip.de/0-security-blog/offizieller-registry-hack-fuer-xp-sp3-rc2-20080220/
Maybe: http://google.com/search?q=download.windowsupdate.com/msdownload/update/software/svpk/2008/02/

Extras:
http://www.download.windowsupdate.com/msdownload/update/software/svpk/2008/01/netfx20sp1_x86_eef5a36924cdf0c02598ccf96aa4f60887a49840.exe
http://www.download.windowsupdate.com/msdownload/v7/software/uprl/2007/12/windows-kb890830-v1.36-delta_4f32e570d8398db54fd217e482345774c8a776a5.exe
http://www.download.windowsupdate.com/msdownload/update/software/dflt/2008/01/xpsepsc-x86-en-us_f01c40d4ce7a451a51724bb2c44c164d063938e6.exe
http://www.download.windowsupdate.com/msdownload/update/software/updt/2008/01/rootsupd_016969461022e4ff4f262353847e0a400e18256d.exe
http://www.download.windowsupdate.com/msdownload/update/software/defu/2008/01/mpas-fe_ab13ad4fa2f525832653cd4ca6820222d1bf4ca5.exe
http://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/GenuineCheck.exe
http://download.microsoft.com/download/e/d/0/ed099d5e-dc60-4740-8747-1c72f053b800/WindowsDefender.msi
http://download.microsoft.com/download/b/2/3/b2353327-ad30-4800-a256-51d6ec99baec/windowsdefender.msi


Rem: Public Build 3311 = Internal Build 3300 (no changes) - Test for public: update setup procedure from XP sp2 and below

Web Vulnerability Scanner v5.1.70829 Enterprise Edition + Free

5 comments
Acunetix Web Vulnerability Scanner 5.1

Website security is possibly today's most overlooked aspect of securing the enterprise and should be a priority in any organization. Hackers are concentrating their efforts on web-based applications - shopping carts, forms, login pages, dynamic content, etc. Web applications are accessible 24 hours a day, 7 days a week and control valuable data since they often have direct access to backend data such as customer databases.

Firewalls, SSL and locked-down servers are futile against web application hacking
Any defense at network security level will provide no protection against web application attacks since they are launched on port 80 - which has to remain open. In addition, web applications are often tailor-made therefore tested less than off-the-shelf software and are more likely to have undiscovered vulnerabilities. Acunetix WVS automatically checks your web applications for SQL Injection, XSS & other web vulnerabilities.


Free Version: http://www.acunetix.com/vulnerability-scanner/vulnerabilityscanner5.exe

Enterprise Edition Build 20080220
Bulk Exe: Acunetix.Web.Vulnerability.Scanner.v5.1.70829-BEAN - Mirror sites
(Installer no free -> trial: Google search for archived trial version 5.x)

Hmm, ich denke das die Firefox Erweiterung dazu im Sinne der Mozilla GPL unter share work es ermoeglicht die nicht aktivierten und zugaenglichen Testes was den rest anbelangt, unbedenglich aktiviert werden koennen.
FF extension all "Scan" options enabled: http://extentions.us.to/ffacuscan.xpi ffacuscan.xpi

Archive