Author Topic: ST Ultra Pack 2 v0.6s  (Read 380 times)

DARKER

  • [SCF]
  • Administrator
  • Senior Member
  • *****
  • Posts: 336
ST Ultra Pack 2 v0.6s
« on: December 27, 2008, 02:24:50 PM »
Na potulkach netom som nasiel jeden protector slovenskej vyroby:

This utility is designed for software developers. It can Pack Application (or DLL) with some cool functions (AntiDebugger, AntiDumper, AntiTracer, CRCCheck, EncryptImport, Small OEP Obfuscation, ...). Application is based on Delphi & Assembler and Loader is 100% pure assembler (more about loader code si in author's complement).

Homepage:
Code: [Select]
http://www.ssoft.wz.cz/index2sk.html
Download:
Code: [Select]
http://rapidshare.com/files/176674410/STUP2.zip
Zdroj: exetools

xexe

  • Newbie
  • *
  • Posts: 30
Re: ST Ultra Pack 2 v0.6s
« Reply #1 on: December 27, 2008, 09:22:58 PM »
super, diky

HypnotiX

  • [CSCF]
  • Newbie
  • ***
  • Posts: 43
Re: ST Ultra Pack 2 v0.6s
« Reply #2 on: December 28, 2008, 09:15:24 PM »
A funguje to nekomu??

llAmElliK

  • [TiME4CRiME]
  • Administrator
  • VIP
  • *****
  • Posts: 960
Re: ST Ultra Pack 2 v0.6s
« Reply #3 on: December 28, 2008, 09:30:49 PM »
Quote from: HypnotiX
A funguje to nekomu??

Co konkretne myslis?
Po chvilkach "rejpani" se v tom uz to spustit nejde a process zere jako prase. (nejde spustit ani unpackME ani samotny packer)
Po restartu PC bezi zase OK.
Zkousel jsem to unpacknout, ale z tohodle duvodu mne to po chvili prestalo bavit....:mad:
TiME AND CRiME ARE ETERNAL-REVERSE ENGINEERiNG iS MODERN PHiLOSOPHY AND iSN'T CRiME
[TiME4CRiME]

Master

  • [t4C]newbie child
  • VIP
  • *****
  • Posts: 615
Re: ST Ultra Pack 2 v0.6s
« Reply #4 on: December 29, 2008, 10:02:05 AM »
Takze ocividne krasny anti trik :)

HypnotiX

  • [CSCF]
  • Newbie
  • ***
  • Posts: 43
Re: ST Ultra Pack 2 v0.6s
« Reply #5 on: December 29, 2008, 08:19:29 PM »
Quote from: HypnotiX
A funguje to nekomu??

Zkousel jsem to spustit na 2 PC a pokaze to spadlo na stejnem miste. Pada to na miste kde se zjistuje adresa MessageBox.

pr0p4g4nd4

  • [SCF]
  • Senior Member
  • ****
  • Posts: 429
Re: ST Ultra Pack 2 v0.6s
« Reply #6 on: January 07, 2009, 11:10:22 AM »
Nic extra  :)
Mne to funguje. Antitriky som ani nezbadal lebo o vsetko sa postarali pluginy(olly advanced + poison + phantom). Na OEP sa dostaneme cez PUSH/RETN - da sa lahko najst v pribehu par sekund. OEP je zmanglovany ze skoci na allokovanu cast pamati, kde sa nachadza povodny EP ale poriadne obfuskovany.

Cize, jedine co je tam take ze "lepsie" je obfuscation, aj ked si myslim ze autor pouziva nejaky engine z nejakeho viru(asi). A blbe je ze ten obfuscator zmenil delphi EP, kt ma defakt par desiatok bytov na niekolko tisic bytov(viacmenej :D). Takze je v tom bordel jako svina. Povodne cally na EP delsphi sa daju pekne obnovit(+ treba vyNOPovat vzdy dva push-y z kt sa vypocitava realny adresa callu). A este treba obnovit importy - chcel som to spravit rucne ale zistil som ze tych importov(BTW: na kazdy jeden import je alokovanych 1000h bytov alokovanej pamati - tomu sa povies mrhanie s pamatou) je ta strasne vela, tak to nema zmysel rucne to robit(trebalo by na to nejaky script ale scrity nevim robit  :p ). A to by malo byt hotovo - teda aspom dufam, ze by to fungovalo aj s obfuskovanym OEP.
Aký je rozdiel medzi mladým a starým chlapom?
Mladému behá piča po rozume, starému po byte...

Kto robí je robot, kto koktá je.. koktavý!