Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 06-19-2009, 09:48
Beyond2000! Beyond2000! is offline
Friend
 
Join Date: Jan 2002
Posts: 48
Rept. Given: 8
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 4
Thanks Rcvd at 1 Time in 1 Post
Beyond2000! Reputation: 3
Unknown Packer

Hi guys

i´m trying to find what packer/crypter was used with PentiumTools

http://www.pentiumtools.com
http://rapidshare.com/files/221467191/PentiumTools.1.06.rar

PEId can´t identiofy what packer/cryptr it was made. Anyone have any idea which one was used and also what unpacker use on it ?

Regards
Reply With Quote
  #2  
Old 06-19-2009, 18:04
quosego quosego is offline
Family
 
Join Date: Feb 2009
Posts: 104
Rept. Given: 8
Rept. Rcvd 39 Times in 13 Posts
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
quosego Reputation: 39
It's Armadillo;

[PROTECTiON SYSTEM]
Professional Edition
[PROTECTiON OPTiONS]
Debug-Blocker protection detected
CopyMem-II protection detected
Memory-Patching Protections enabled
Strategic Code Splicing enabled
Import Table Elimination enabled
Reply With Quote
  #3  
Old 06-20-2009, 02:43
Beyond2000! Beyond2000! is offline
Friend
 
Join Date: Jan 2002
Posts: 48
Rept. Given: 8
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 4
Thanks Rcvd at 1 Time in 1 Post
Beyond2000! Reputation: 3
Tks,

but it is not working.. I tested with many armadillo unpackers and the file refuses to be unpacked.

What is the neecssary (and working) tool to unpack this ?

Have any idea which file to use ?
Reply With Quote
  #4  
Old 06-20-2009, 05:01
quosego quosego is offline
Family
 
Join Date: Feb 2009
Posts: 104
Rept. Given: 8
Rept. Rcvd 39 Times in 13 Posts
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
quosego Reputation: 39
Well I don't like using unpackers, if you can't do it manually...
However armageddon 1.33, with name hack (changing the window name) unpacks it fine.

q.
Reply With Quote
  #5  
Old 06-20-2009, 06:42
Beyond2000! Beyond2000! is offline
Friend
 
Join Date: Jan 2002
Posts: 48
Rept. Given: 8
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 4
Thanks Rcvd at 1 Time in 1 Post
Beyond2000! Reputation: 3
Done

Many thanks
Reply With Quote
  #6  
Old 06-20-2009, 20:03
Git's Avatar
Git Git is offline
Old Git
 
Join Date: Mar 2002
Location: Torino
Posts: 1,116
Rept. Given: 220
Rept. Rcvd 265 Times in 157 Posts
Thanks Given: 110
Thanks Rcvd at 220 Times in 126 Posts
Git Reputation: 200-299 Git Reputation: 200-299 Git Reputation: 200-299
Quote:
Originally Posted by quosego View Post
Well I don't like using unpackers, if you can't do it manually...
Do you use a spoon to stir your tea or your finger?

Git
Reply With Quote
  #7  
Old 06-20-2009, 20:43
h--
 
Posts: n/a
hm

Well, knowing to use your finger to stir your tea, is good when you lack of a spoon, isnt it?
Reply With Quote
  #8  
Old 06-20-2009, 21:57
Git's Avatar
Git Git is offline
Old Git
 
Join Date: Mar 2002
Location: Torino
Posts: 1,116
Rept. Given: 220
Rept. Rcvd 265 Times in 157 Posts
Thanks Given: 110
Thanks Rcvd at 220 Times in 126 Posts
Git Reputation: 200-299 Git Reputation: 200-299 Git Reputation: 200-299
Indeed it is, but refusing to use a spoon that is in the saucer and using your finger instead is uncivilised

Git
Reply With Quote
  #9  
Old 06-21-2009, 01:19
quosego quosego is offline
Family
 
Join Date: Feb 2009
Posts: 104
Rept. Given: 8
Rept. Rcvd 39 Times in 13 Posts
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
quosego Reputation: 39
But it requires way more skill if your tea is hot enough.

No, what I meant is that unpackers don't teach you anything.. They're there to speed up the process once you've mastered a protection and it gets boring... ( Note I said 'can't' not can in my first statement. Most likely you interpreted it as 'can'.. ) Just using some unpacker defeats the imho the purpose of reversing.. It's the challenge of defeating a protection for the first time that's fun, not using a a program and click some buttons,

It's only a pitty that not everybody is here for the challenge. Only the result "whoaah I crackzorred it using unpacker x"..
(Though depending on your goal that isn't necessarily a bad thing, I mean there are pure keygenners around. That just hate unpacking.. ..)

Last edited by quosego; 06-21-2009 at 01:25.
Reply With Quote
  #10  
Old 06-21-2009, 02:11
Nacho_dj's Avatar
Nacho_dj Nacho_dj is offline
Lo*eXeTools*rd
 
Join Date: Mar 2005
Posts: 211
Rept. Given: 16
Rept. Rcvd 179 Times in 34 Posts
Thanks Given: 44
Thanks Rcvd at 137 Times in 41 Posts
Nacho_dj Reputation: 100-199 Nacho_dj Reputation: 100-199
As quosego wisely pointed, it is an Armadillo target, and last released version of Armageddon (v1.6) can unpack it without problems; no need to change the window name since this 'bug' has been solved...

Best regards

Nacho_dj
__________________
http://arteam.accessroot.com
Reply With Quote
  #11  
Old 06-21-2009, 03:19
ahmadmansoor's Avatar
ahmadmansoor ahmadmansoor is offline
Coder
 
Join Date: Feb 2006
Location: Syria
Posts: 1,047
Rept. Given: 517
Rept. Rcvd 374 Times in 142 Posts
Thanks Given: 380
Thanks Rcvd at 416 Times in 119 Posts
ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399
yes Armageddon (v1.6) is very Good Tools but it fail in some target especially ...with target like :
target <<VB6.0>> with this options
Debug-Blocker protection detected
CopyMem-II protection detected
Memory-Patching Protections enabled
Strategic Code Splicing enabled
Import Table Elimination enabled

it can't unpack it ....and I can give u some example ..
so I agree with quosego in this point ...man must not depended on unpacker unless he know how to unpack it ,and he need to save some times ,not else .
I like to work on Armadillo ( as all know ) .
but I like very much to use Armageddon (v1.6) ,which is very amazing ...
big Thanks go to Condzero and Arteam.
__________________
Ur Best Friend Ahmadmansoor
Always My Best Friend: Aaron & JMI & ZeNiX
Reply With Quote
  #12  
Old 06-21-2009, 03:23
Nacho_dj's Avatar
Nacho_dj Nacho_dj is offline
Lo*eXeTools*rd
 
Join Date: Mar 2005
Posts: 211
Rept. Given: 16
Rept. Rcvd 179 Times in 34 Posts
Thanks Given: 44
Thanks Rcvd at 137 Times in 41 Posts
Nacho_dj Reputation: 100-199 Nacho_dj Reputation: 100-199
We are working to get ALL Armadillo targets unpacked by Armageddon, so please, when you find any target failing, as you mentioned in your post, report a target link to us, any of ARTeam members...

Thanks for your feedback.

Cheers

Nacho_dj
__________________
http://arteam.accessroot.com
Reply With Quote
  #13  
Old 06-21-2009, 18:18
ahmadmansoor's Avatar
ahmadmansoor ahmadmansoor is offline
Coder
 
Join Date: Feb 2006
Location: Syria
Posts: 1,047
Rept. Given: 517
Rept. Rcvd 374 Times in 142 Posts
Thanks Given: 380
Thanks Rcvd at 416 Times in 119 Posts
ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399
http://download.cnet.com/FlashCards-2003/3000-2051_4-10022954.html

I don't know I have try to unpack it under VMware i don't if this affect .
many thanks
__________________
Ur Best Friend Ahmadmansoor
Always My Best Friend: Aaron & JMI & ZeNiX
Reply With Quote
  #14  
Old 06-26-2009, 12:47
trickyboy trickyboy is offline
Friend
 
Join Date: Dec 2005
Posts: 43
Rept. Given: 11
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 15
Thanks Rcvd at 3 Times in 3 Posts
trickyboy Reputation: 0
Armadillo was a old story. I think if Armadillo's author change all structure of protection,it will be better.
Reply With Quote
  #15  
Old 06-26-2009, 19:42
ahmadmansoor's Avatar
ahmadmansoor ahmadmansoor is offline
Coder
 
Join Date: Feb 2006
Location: Syria
Posts: 1,047
Rept. Given: 517
Rept. Rcvd 374 Times in 142 Posts
Thanks Given: 380
Thanks Rcvd at 416 Times in 119 Posts
ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399
@trickboy: Hi my friend
Long time we didn't hear ur voice ....
nice to see u around .
__________________
Ur Best Friend Ahmadmansoor
Always My Best Friend: Aaron & JMI & ZeNiX
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
An Unknown Packer ! Newbie_Cracker General Discussion 10 10-11-2005 14:35


All times are GMT +8. The time now is 07:12.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )