04 October 2008

Unpacking StuFF

0 comments
The Chinese have updated OD plugin:
OllyDBG v1.10 plugin - StrongOD v0.18

Temptress Moon Shadow by sea [CUG]
====================================================================

[2008.09.18 v0.18]
1, to repair the Ctrl + G calculation rva, offset when a small BUG
2, when the program is not running the state, Detach before running program
3, restoration of the original data OD zone copy BUG
4, repair od after the CPU running very high occupancy rate BUG
5, you can set it to skip some of the exception handling

[2008.09.02 v0.17]
1, to skip some of the improper handling of the abnormal OD
2, correctly handle the instructions int 2d

[2008.08.31 v0.16]
1, joined the drive to protect the process, the hidden window, over most of the anti-debugging
2, driver support for the custom equipment 000 (ollydbg.ini of DeviceName, equipment were not more than 8 characters)
ollydbg.ini of [StrongOD], you can set up their own
HideWindow = 1 to hide the window
HideProcess = 1 to hide the process
ProtectProcess = 1 protection process
DriverKey =- 82693034 and the key driver of communication
DriverName = fengyue0 who drives (not more than 8 characters)

3, OD will be the creation of the parent process into the process explorer.exe (copied from shoooo code)

/////////////////////////////////////////////////////////////

The increase in the version of the driver, if a blue screen, set up minidump spread to the Forum, thank you
OllyDbg original use as much as possible, and other generally do not need the anti-anti plugin in conjunction with plug-in (including phant0m)

[Note of the final film Temptress Moon by the sea in the editing 2008-9-19 20:52]

House accounts, anti shell had the option to use the skills

The following are no special note are the original OD add a plug-in plug-in StrongOD operate

Ollydbg.ini in the first [Plugin StrongOD] the following HideWindow, ProtectProcess into the value of 1, the value of KernelMode turned into a preserve

1, Themida / WinLicense
Plug-in option to set a minimum
Original run OD, included in the main program Themida v1.9.9.0, stopped at the entrance after the removal of all breakpoints, Shift + F9 up-and-run
2, ExeCryptor v2.4.1
Plug-in option to set a minimum
Original run OD, set up break point on break point in the system to stop
ExeCryptor v2.4.1 included in the main program, stopped at the breakpoint system, according to Alt + B, remove the breakpoint EP
And then Shift + F9, you can
3, TTProtect v1.05 DEMO
Plug-in option to set a minimum. Original run OD, loading TTProtect v1.05 DEMO main program, Shift + F9
4, VMProtect v1.65.2
vmp v1.65 added to the xp system under the OD of the new anti
Plug-in option to set a minimum. Original run OD, loading VMProtect v1.65.2 main program, Shift + F9

Homepage: http://bbs.cracktool.com/viewthread.php?tid=28854&extra=page%3D1
http://www.unpack.cn/viewthread.php?tid=26870
http://cracklab.ru/f/index.php?action=vthread&forum=3&topic=12832

Download:
StrongOD v0.18.rar 101.89 KB

03 October 2008

Shareaza 2.4.0.0

1 comments
Release Date: October 1st, 2008

Shareaza can connect to up to 4 separate Peer-to-Peer networks, providing access to hundreds of thousands of diverse users, all from one single program. You can download/upload from these networks: EDonkey2000, Gnutella, BitTorrent and Gnutella2 (G2).

Shareaza 2.4 celebrates 4 years of open source p2p community,
and presents almost 900 changes from 9 months of solid dedication under difficult circumstances.

Shareaza 2.4 Changelog
Revisions 6540-7410 (Jan.01-Oct.01 2008)
Almost 900 Cumulative Updates.
Windows 9X Support Dropped, new VC9 Development Platform.
to much to put here.
Full Changelog visit: http://pantheraproject.net/wiki/index.php?title=ChangeLog2.4

Shareaza Features:
• Use the power of 4 P2P Networks simultaneously!
Four networks mean access to a wide variety of users. Look no further: Shareaza has got you covered!
• Download from multiple sources
Experience downloads the way they were meant to be: fast! Shareaza swarms across four networks!
• Sophisticated file-hashing
Say adios to corrupted files and mp3s that skip. Shareaza detects and fixes corruption before the download completes.
• Find that file with Global Searching on Gnutella2!
Search the entire network, not just a part of it. Shareaza will find you that file!
• Multiple results tabs
Each search is displayed in a new window. Your search results will never be overwritten. Shareaza runs the searches you want, when you want!
• Previews, users comments, and ratings
Get picture and movie previews right from the search panel. Even view comments and ratings written by users like you. Shareaza ensures you avoid those fakes and download the real deal!

Homepage: http://shareaza.sourceforge.net/
Changelog: http://pantheraproject.net/wiki/index.php?title=ChangeLog2.4

Download: http://heanet.dl.sourceforge.net/sourceforge/shareaza/Shareaza_2.4.0.0.exe
all files: http://sourceforge.net/project/showfiles.php?group_id=110672

02 October 2008

ISP P2P (BitTorrent, eMule) traffic shaping - P2P Bandwidth limiting

12 comments
Article based on:
http://filesharingz.com/guides/bittorrent_encryption_myths.php
http://www.azureuswiki.com/index.php/Bad_ISPs

Traffic shaping is used in some countries by several ISP's to save bandwidth from customer internet accounts. In Europe, United Kingdom, some ex colonies, Malaysia use this Technology in Asia and a few South American Countries. Other European Countries as well Africa and Russia do not limit customer bandwidth for P2P filesharing.
If your ISP shaping traffic, please consider finding a new, better one.

Protocol Encryption can help to increase download speed if your ISP limits P2P traffic.
Some ISPs limits encrypted traffic.

Test it with a good seeded torrent or eMule downloads with many sources such as on Linux distributions, Open Office... if the speed is significant slower as http downloads. For example a http (ftp) download with download manager runs at 4 Mb/s full line speed and P2P (torrent, edonkey) is rate limit to 400 - 550 kb/s (40 ~ 50).

Furhter more there is an online BitTorrent traffic tester available from Max Planck Institute for Software Systems:
http://broadband.mpi-sws.mpg.de/transparency/bttest.php
While running this test, you can next to your ip in the url address bar change the ports to others during a short interrupt and re-run the test on ports of your choice (others than the standard BitTorrent ports).

How to activate Protocol Encryption in eMule:

eMule Official and eMule Mods (MorphXT, Xtreme...)
Go to Options -> Settings -> Security, Select the Checkbox: [X] Enable Protocol Obfuscation
If your download speeds do not increase when you choose Enabled, choose: [X] Allow obfuscated connections only.



click on the pictures for fullscreen


In extension for eMule mods based on Applejuice (HyperTraxx, Fireball, RC-Atlantis, EPB-Mod, GPS2Crew Mod, Titandonkey, Razorback Mod, SunPower-Mod, Wikinger Mod, ROCKFORCE Mod,...) using "AES 256 bit" Encryption.

Try the following setting combination as shown in this screenshots:


Settings as in the Official eMule and Mods, see above, plus try under 'Sharing' Tab Encryption AES 256 bit to select: [X] Support Encryption
If it do not increase the download speed try: [X] Use Encryption for all files


Caution AES 256 encryption is not compatible with other clients which do not support this features. You may get no upload if you are connected with incompatible clients. You can possible not download from standard eMule if this is activated!

If your ISP do not limit P2P traffic, activated forced protocol encryption needs more cpu load and system resources!

You can try to change the standard Ports in eMule:

Make shure Portforwarding via UPnP (can use settings Random ports) or manually (fixed ports) is setup for your router.

Remark:
eMule protocol obfuscation, Applejuice Mods enhanced Encryption (AES 256 bit) and BitTorrent encryption will not hide your identity or improve your security!!!
Encryption will not hides the data you are sharing!
"Encryption was developed with only one purpose in mind: circumventing traffic shapers and sniffers. Certain ISPs employ traffic shaping tactics to lower eMule and BitTorrent speeds and thus reduce eMule and BitTorrent traffic."
eMule Applejuice 'extra' security as a eMule mod do not exist. Applejuice based eMule Mods aren't more or less secure as every other eMule client.

encryption AES 256 bit part implementation port taken from???: http://www.i2p2.de/how_intro_de - http://www.i2p2.de/download
•Source install:
http://mirror.i2p2.de/i2psource_0.6.3.tar.bz2 ???


AES code, under the Cryptix (MIT) license, written by the Cryptix team

How to encrypt BitTorrent Traffic Weblink: http://filesharingz.com/guides/how_to_encrypt_bittorrent_traffic.php

eMule 0.49b ZZ-RS V1.5 HotFix | ZZ-R V1.5 HotFix

1 comments
eMule 0.49b ZZ-R V1.5 + ZZ-RS V1.5
ZZ-R & RS V1.5 Hotfix (eMule 0.49b)
---------------------------------

+ Fixed: Bug in LogFriends & AutoFriendslot
+ Readded: Minimule
+ MiniMule Auto Close
+ MiniMule Transparency

Download

ed2k links:

eMule.0.49b.ZZ-R.V1.5.HotFix.rar

eMule.0.49b.ZZ-RS.V1.5.HotFix.rar

http links:

emule.0.49b.zz_rs.v1.5.hotfix.rar

emule.0.49b.zz_r.v1.5.hotfix.rar

01 October 2008

XoftSpySE 4.33 (DB-312) English / Deutsch

0 comments

XoftSpySE - Fast & Effective PC Protection! XoftSpy is the latest and most advanced Spyware detection & removal application on the Internet. XoftSpySE was designed to scan the user's complete computer system to detect spyware parasites and quarantine the infected files for immediate protection, XoftSpySE is your fast, dependable anti-spyware defense.

XoftSpy scans your PC's registry, memory, files & folders for Spyware, Adware, Malware, Spybots, Keyloggers, Spy Pop-ups and Unwanted Toolbars! We provide free spyware definition updates and enhancements so that your privacy is protected from the latest threats to hit the Internet. XoftSpy's user-friendly interface makes it easy to identify and destroy threats. The backup and restore feature allows you to quickly revert back to a previous state in case a recovery is necessary.

In just a few minutes you can detect andeliminate all these harmful PC threats: Spyware, Spybot, Hijackers, Adware, Malware, Keyloggers, Worms, Hacker Tools, PCParasites, Trojan Horses, Spy Programs, Trackware and much more!

Key features of this software:
• Video Presentation Complete PC scanning, including running processes, registry entries, files and folders
• Detects and removes: adware, spyware, pop-Up generators, keyloggers, trojans, hijackers, and malware
• One of the largest spyware definition databases in the industry
• Automatic definition and feature updates
• Fast, powerful, and easy to use
• Comprehensive customer technical support
• Protects against identity and credit card theft

Patch here with dUP v2.18: XoftSpySE 4.33 (DB-312).rar 5.87 MB
DB-312 after update

German/Deutsch Language:

German/Deutsch Language File/Sprach Datei: resources.dll 120.00 KB

eMule 0.49b ZZ-R V1.5 + ZZ-RS V1.5

1 comments
eMule 0.49b ZZ-R V1.5 + ZZ-RS V1.5
eMule v0.49b [ZZ-RS V1.5]


Changelog:
==========


30.09.2008

ZZ-RS V1.5 (eMule 0.49b)
------------------------------------------------------------------------------------

+ Fixed Argos settings (now saved again ;-) [morph4u]
+ Fixed Downloading file in bold (now need no restart) [merged from MorphXT]
+ Reduce some cpu under wine [merged from MorphXT]
+ Open a default website when nodesURL is invalid [merged from Xtreme]
+ Date & Time format [Official]
+ Date & Time format for log [Official]
+ Readded: More info in upload Status (now switchable) [morph4u]

Please update to this Version, eMule 0.49b ZZ-R V1.4 doesn't save Argos settings!!!



Downloads:

ed2k links
eMule.0.49b.ZZ-R.V1.5.rar

eMule.0.49b.ZZ-RS.V1.5.rar

http links
eMule.0.49b.ZZ-RS.V1.5.rar

eMule.0.49b.ZZ-R.V1.5.rar

Archive