Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 05-24-2013, 02:32
TempoMat TempoMat is offline
Friend
 
Join Date: Jan 2006
Posts: 87
Rept. Given: 10
Rept. Rcvd 6 Times in 6 Posts
Thanks Given: 4
Thanks Rcvd at 28 Times in 21 Posts
TempoMat Reputation: 6
Samsung Kies with Themida?

Today I was trying to transfer some eBooks in PDF to a friend's Samsung Phone with Kies (version 2.5.3.13043_14) while Ollydbg was loaded and was greeted with the nasty message
"A debugger has been found running in your system. Please, unload if from memory and restart your program" with "Themida" in the Title of the message. At first I thought it was a mistake. But after a second pop up Kies was closed. I then restarted it and the same message poped up with Olly loaded. Interestingly I had used KIES some days earlier on the same computer without Olly and there was no such message.

So the question is whether Samsung is protecting KIES with Themida or a third party program inside KIES is using Themida.
Reply With Quote
  #2  
Old 05-24-2013, 04:19
deepzero's Avatar
deepzero deepzero is offline
VIP
 
Join Date: Mar 2010
Location: Germany
Posts: 300
Rept. Given: 111
Rept. Rcvd 64 Times in 42 Posts
Thanks Given: 178
Thanks Rcvd at 215 Times in 92 Posts
deepzero Reputation: 64
Seeing that kies is freeware that would not make a lot of sense.
Check which process fires the message and check it with pid...or scan the entire kies installation folder.
Reply With Quote
  #3  
Old 05-24-2013, 04:29
Dreamer's Avatar
Dreamer Dreamer is offline
Family
 
Join Date: May 2012
Posts: 604
Rept. Given: 613
Rept. Rcvd 659 Times in 257 Posts
Thanks Given: 117
Thanks Rcvd at 170 Times in 128 Posts
Dreamer Reputation: 38
no themida i am found this two only in common folder

Common
basscd.dll===Petite [unknown version] compressed !
bassenc.dll===Petite [unknown version] compressed !
Reply With Quote
  #4  
Old 05-24-2013, 12:52
Av0id Av0id is offline
VIP
 
Join Date: Jan 2006
Posts: 399
Rept. Given: 112
Rept. Rcvd 111 Times in 69 Posts
Thanks Given: 0
Thanks Rcvd at 15 Times in 15 Posts
Av0id Reputation: 100-199 Av0id Reputation: 100-199
bass*.dll they are from un4seen, which is author of petite
Reply With Quote
The Following User Gave Reputation+1 to Av0id For This Useful Post:
  #5  
Old 05-24-2013, 15:10
giv's Avatar
giv giv is offline
VIP
 
Join Date: Jan 2011
Location: Romania
Posts: 1,657
Rept. Given: 801
Rept. Rcvd 1,283 Times in 561 Posts
Thanks Given: 226
Thanks Rcvd at 562 Times in 240 Posts
giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299
Quote:
Originally Posted by TempoMat View Post
So the question is whether Samsung is protecting KIES with Themida or a third party program inside KIES is using Themida.
What does matter?
Is a freeware and IMHO is much weaker than Nokia PC Suite.
Reply With Quote
  #6  
Old 05-24-2013, 19:29
JeRRy's Avatar
JeRRy JeRRy is offline
VIP
 
Join Date: Oct 2010
Posts: 121
Rept. Given: 89
Rept. Rcvd 205 Times in 72 Posts
Thanks Given: 14
Thanks Rcvd at 26 Times in 12 Posts
JeRRy Reputation: 200-299 JeRRy Reputation: 200-299 JeRRy Reputation: 200-299
Scanning -> C:\Program Files\Samsung\Kies\External\FirmwareUpdate\CommonModule.dll
File Type : 32-Bit Dll (Subsystem : Win GUI / 2), Size : 1012176 (0F71D0h) Byte(s)
-> File Appears to be Digitally Signed @ Offset 0F5A00h, size : 017D0h / 06096 byte(s)
[File Heuristics] -> Flag : 00000000000001001101000000110111 (0x0004D037)
[!] Themida v2.0.1.0 - v2.1.8.0 (or newer) detected !
[i] Hide PE Scanner Option used
- Scan Took : 0.47 Second(s) [00000002Fh tick(s)] [229 scan(s) done]

Scanning -> C:\Program Files\Samsung\Kies\External\FirmwareUpdate\AgentModule.dll
File Type : 32-Bit Dll (Subsystem : Win GUI / 2), Size : 1626576 (018D1D0h) Byte(s)
-> File Appears to be Digitally Signed @ Offset 018BA00h, size : 017D0h / 06096 byte(s)
[File Heuristics] -> Flag : 00000000000001001101000000110111 (0x0004D037)
[!] Themida v2.0.1.0 - v2.1.8.0 (or newer) detected !
[i] Hide PE Scanner Option used
- Scan Took : 0.62 Second(s) [00000003Eh tick(s)] [229 scan(s) done]
__________________
SnD
Reply With Quote
The Following 2 Users Gave Reputation+1 to JeRRy For This Useful Post:
TempoMat (05-25-2013)
  #7  
Old 05-24-2013, 21:42
Dreamer's Avatar
Dreamer Dreamer is offline
Family
 
Join Date: May 2012
Posts: 604
Rept. Given: 613
Rept. Rcvd 659 Times in 257 Posts
Thanks Given: 117
Thanks Rcvd at 170 Times in 128 Posts
Dreamer Reputation: 38
great JeRRy you found that i was scan but there is to many files to scan
Reply With Quote
  #8  
Old 05-25-2013, 19:39
TempoMat TempoMat is offline
Friend
 
Join Date: Jan 2006
Posts: 87
Rept. Given: 10
Rept. Rcvd 6 Times in 6 Posts
Thanks Given: 4
Thanks Rcvd at 28 Times in 21 Posts
TempoMat Reputation: 6
Quote:
Originally Posted by giv View Post
What does matter?
Is a freeware and IMHO is much weaker than Nokia PC Suite.
"giv" I was not comparing KIES to Nokia PC Suite.
So what is the point of you mentioning Nokia PC Suite here, knowing well that they are both meant for different products, unless perhaps you have a special version of Nokia PC Suite which also works for Samsung phones?

Nevertheless I was just surprise to see signs of Themida in a FREEWARE (as already noted by you) from Samsung.
Reply With Quote
  #9  
Old 05-26-2013, 02:44
giv's Avatar
giv giv is offline
VIP
 
Join Date: Jan 2011
Location: Romania
Posts: 1,657
Rept. Given: 801
Rept. Rcvd 1,283 Times in 561 Posts
Thanks Given: 226
Thanks Rcvd at 562 Times in 240 Posts
giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299
Quote:
Originally Posted by TempoMat View Post
So what is the point of you mentioning Nokia PC Suite here, knowing well that they are both meant for different products
They both do the same thing

Quote:
Originally Posted by TempoMat View Post
unless perhaps you have a special version of Nokia PC Suite which also works for Samsung phones?
I got-it. You think you are some smart guy.

Quote:
Originally Posted by TempoMat View Post
Nevertheless I was just surprise to see signs of Themida in a FREEWARE (as already noted by you) from Samsung.
Is not a rule that only comercial apps to be protected.
Reply With Quote
  #10  
Old 05-27-2013, 20:31
mr.exodia mr.exodia is offline
Retired Moderator
 
Join Date: Nov 2011
Posts: 784
Rept. Given: 492
Rept. Rcvd 1,122 Times in 305 Posts
Thanks Given: 90
Thanks Rcvd at 711 Times in 333 Posts
mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299
maybe Samsung wants to protect their products from eyes that want to steal their source...
Reply With Quote
  #11  
Old 06-21-2013, 03:07
leosmi05 leosmi05 is offline
Friend
 
Join Date: Feb 2005
Posts: 26
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
leosmi05 Reputation: 0
Or they are (beta)testing the "technology" behind Themida.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
# Z3X Samsung Pro v24.3 Not Box Required. Patch# RDGMax General Discussion 1 04-09-2017 19:01


All times are GMT +8. The time now is 20:50.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )