Posts

Showing posts with the label Unpacking

We're back online!

Welcome to Leechermods 2026: The Signal is Amplified We’re officially heading into our 20th year! After a long period of strategic silence and low-frequency operations from our previous rural Eastern and Northern European outpost, we have fully transitioned to our new operational cycle. The Current Deployment: We are now alternating between the regulatory sanctuary of Iceland and the high-speed intelligence hubs of Singapore , before relocating to the Mekong Delta Hub for a longer-term signal persistence. Apologies for the recent downtime; I've been busy hardening our DNS configurations for enhanced security (Global HTTPS/TLS). A full site redesign (CSS, HTML, JS, and AI-integrated features) is underway to optimize our new CDN backbone and eliminate legacy graphical debt. Stay tuned. The audit never stops. Status: Moving Out. Moving Up. Operational.

VMunpacker 1.6 Latest Version

Image
This virtual machine-based tool is capable of unpacking a wide range of known and unknown shells. It is particularly well-suited for analyzing shelled Trojan horses in virus analysis , and its virtualized execution environment ensures that all code runs without posing any threat to your system. The commercial VM Unpack Engine SDK will be exclusively provided. By utilizing the VM Unpack Engine SDK, developers are relieved from concerns regarding the unpacking process and methodology. Developers simply need to transmit the data to the VMUE SDK, which will then automatically complete the analysis and unpacking. The VMUE supports simultaneous delivery of unpacking results to both file and memory, directly returning the Original Entry Point (OEP) post-unpacking. This functionality facilitates the integration of shell unpacking into your products and tools. Post-unpacking, the PE file is rebuilt, including repairs to the import table and overlay, which are essential for the successful...

PROTECTiON iD v6.3.5

Image
(c) http://pid.gamecopyworld.com CDKiLLER & TippeX [02/2003 - 12/2009] 'protectionid - we innovate, we dont replicate other peoples work' Homepage: http://pid.gamecopyworld.com/ Features - detection of every major PC ISO Game / Application protection - currently covers 475 detections, including win32/64 exe protectors & packers, .net protectors, dongles, licenses & installers - sector scanning CDs / DVDs for Copy Protections - files / folders can simply be drag & droped into pid - strong scanning routines allowing it to detect multiple protections - easy scanning via shell context menu - usefully misc tools included - coded 100% in Win32 assembly language - fully 32bit & 64bit compliant - working from Win9x to Windows 7 PROTECTiON iD v6.3.5 We are proud to present you the next and most up2date version of protection id. it was about time to bring this to the public, as the last version was released back in march. During development o...

Exeinfo PE ver.0.0.2.6 - 543 signatures by A.S.L.

Image
ver.0.0.2.6 - 543 signatures - not tested / no time Download exeinfope.zip 654.29 KB

Exeinfo Pe 0.0.2.6 work ( 535 sign ) for test by A.S.L.

Image
Program to check files how they are done (exe packer, archives, compiler,... and many more) Helpful info to unpack. Exeinfo Pe v.0.0.2.6 ( 535 signatures ) - work version ! for test - AVI info added movie size/fps - new skins added - non exe RTF text added - removed anipacker - added Visual Basic fake signer for upx packer - screenshot saver added ( bmp/jpg ) - new sign added .... A.S.L Homepage: http://www.exeinfo.xwp.pl/ Mirror: exeinfope.zip 624.35 KB

Exeinfo PE 0.0.2.5 - 12.10.2009 530 signatures

Image
exeinfo - work version 12.10.2009 (530 signatures) GUI changed: - section view, - about, - config two skin changed to color skin save screenshot added bug fixed A.S.L Homepage: www.exeinfo.xwp.pl exeinfope.zip

Exeinfo PE v0.0.25 526 sign 30items by A.S.L.

Image
Please redownload exeinfo Mirror: Exeinfo_v0025_526sign30items.zip 579.17 KB some tools for unpacking: http://www.woodmann.com/collaborative/tools/index.php/Category:Unpacking_Tools http://www.accessroot.com/arteam/site/download.php?list.9

Exeinfo PE ver.0.0.2.5 - 525 signatures

Image
Exeinfo for Win32 by A.S.L. Packer, compressor detector / unpack info / internal exe tools Exeinfo PE ist ein Datei Identifizierungs Programm welches erkennt mit welchen Packer oder Protector eine Datei erstellt wurde. Zudem zeigt es hilfreiche Informationen um gepackte Dateien zurück in den Ursprung zu entpacken. Eine Vielzahl von integrierten Optionen ermöglichen weitaus mehr. Zur Zeit werden 525 unterschiedliche Packer/Protektoren wie auch Compiler erkannt. Das Programm ist sehr ausgereift und versteht den Unterschied zwischen falschen Signaturen und echten. Die Bedienung ist einfach per Drag'n Drop der Datei(en) in die Programm Oberfläche. Changelog: Exeinfo PE ver.0.0.2.5 - 525 signatures fixed : The Enigma Protector [1.70] NOT EXE - eof check added for JPG format - Hidden exe data - HideMyArchive program. NOT EXE - .RM Video/Audio format NOT EXE - audio .MID format (MIDI) NOT EXE - audio .XM tracker format ver: xx.xx NOT EXE - audio .MOD Soundtracker/Protracker format (M.K....

Inno Setup Unpacker 0.22

Image
Supports Inno Setup versions 2.0.18 through 5.3.4 Aug 20 2009 innounp 0.22 Inno Setup is a popular program for making software installations. Unfortunately, there is no official unpacker - the only method of getting the files out of the self-extracting executable is to run it. One piece of software that addresses this issue is Sergei Wanin's InstallExplorer, a plug-in for the FAR Manager that unpacks several types of installations, including Inno Setup (IS). But since it is not updated in a timely fashion, and so does not support the latest IS most of the time, this program was born. The advantages over InstallExplorer are: * Innounp is open source and based on IS source. Therefore, it is more likely to support future IS versions. * It recovers portions of the installation script (.iss file), including the registry changes and the compiled Innerfuse/RemObjects Pascal Script, if available. 0.22 (20.08.2009) Added support for Unicode versions Added support for IS versions 5.3...

eMule 0.49c SBI Leecher 2.01

Image
eMule 0.49c BSI Leecher v2.01 emule.exe Image is 32bit executable done with VMProtect 1.70.4 - 1.8 ( 2009.02/04 ) emule run in a virtual machine process nfo: PolyTech - www.vmprotect.ru , info says: find swf tutorial by Nooby www.google.com v2.01 -fixed upload bug v2.0 -add spooky mode [serverwindow/sbi controll] -show users ip [transferwindow] -add reconnect on low id [switchable]* -add fake rank start value [switchable]* -add fake rank update time [switchable]* -add auto drop ranking QR>x [switchable]* -add auto drop ranking time [switchable]* -add ranking value for button & auto drop [switchable]* -add file reask time [switchable]* -add auto load/save sources[switchable]* -add sources to save/load value [switchable]* -add reload sources before save [switchable]* -add show downloads in bold [switchable]* -changed download in color code [switchable]* -some fixes of previous version -some other code changes Name: eMule 0.49c SBI Leecher 2.01 Coder: But...

uTorrent extreme LE 4.02 - Not crypted - Logo in Pogo eDiTioN

Image
μTorrent Extreme Leecher Edition v4.02 "Back to the Future" Changelog v4.0: Neu! Basiert auf μTorrent 1.83 Final Installsetup / Deinstall // buggy if D drive is not present Eintrag ins Startmenü // installer set shortcut Changelog / Liesmich // save as picture use ocr Linkliste hinzugefügt // installer add a bunch of urls Geänderte Oberfläche + Icon´s // extras optional general uT addon feature Neu! Language Pack hinzugefügt // extras optional general uT addon feature Neu! Länderflaggen vom 18.6.09 // extras optional general uT addon feature Neu! integrierte Ipfilter von blocklistpro.com 13.06.09 // external use wget + batch to exe or replace download help/langpack url with download ipfilter.dat inside the ut.exe Neu! Ozzy Ip-Filter Updater hinzugefügt // external prog use wget + batch to exe Neu! Pawcio Ip-Filter Updater hinzugefügt // external use wget + batch 2 exe Verzeichnissstruktur für Tempverzeichniss und Downloadverzeichniss // portable default sett...

diablo2oo2 Universal Patcher dUP 2.20 Beta 5 [24-Jun-2009]

diablo2oo2's Universal Patcher [dUP] ************************************ Version: 2.20 Features: -multiple file patcher -create Offset and Search&Replace patch/loader -compare files (RawOffset and VirtualAddress) with different filesize -text patcher -registry patcher, also for loaders -attach files to patcher -get filepaths from registry -usage of CRC32 and filesize checks -patching packed files -compress patcher with your favorite packer -saving projects -use custom skin in your patcher -add music (Tracker Modules: xm,mod,it,s3m,mtm,umx,v2m,ahx,sid) to patcher -multilanguage support -and many more... Version History --------------- [2.20] -added wildcard support for textpatch module -windowresize bugs fixed -minimize patcherwindow with rightmouseclick -added new "event" module for patcher -bugfixes in textpatch module -bugfix: executing attached files -bugfix: problem with nested environment variables Homepage: http://diablo2oo2.di....

File Format Identifier v1.4

Image
Sucop virus analysis tool (File Format Identifier) v1.4 unnoo-dswlab products It is an auxiliary tool for virus analysis, which includes various file format recognition engine code, sniffing packers, unpacking by virtual machine, editing PE file, rebuilding PE file, obtaining the import table(using virtual machine to decode the encode import table), dumping memory, processing the overlay, PE address conversion, supporting PEid plugins, computing MD5 and efficient use of third-party tools, and so on. It is also used for disposing the Trojan virus samples during virus analysis. This software is free; you can download, install, copy and distribute it non commercially; For commercial sale, copy and distribute, you should get the warranty and permission of DSWLAB before (for example, if the anti-virus company want to use it to analysis the Trojan horse in batches, he must get mandate and permission of DSWLAB before). v1.4 new features: - add obtaining the import table function,...

ASProtect unpacker script by VolX 1.15E (support new version)

ASProtect unpacker script by VolX 1.15E (support new version) for ollydbg history ---------- 1.00 First release. 1.10 1. Occasionally crash when fixing initialization table of Delphi apps. 2. IAT rebuild for an early version of Asprotect. 3. Add one more crc check pattern. 4. Add one more Asprotect API emulation. 1.11 IAT rebuild is incomplete when the address of the API caller is beyond first section of the app. 1.12 With some version of ODBGscript it occasionally fails to locate the OEP. 1.13 1. With ODBGscript v1.63 or above it fails to fix initialization table of Delphi apps. 2. Support a newer Asprotect whose stolen code type definition is different. 1.14 1. Script runs on ODBGscript v1.64 or above only. 2. Modification of fixing CRC check point. 3. Failed to locate OEP of proggie packed with verison 1.4x 4. Unhide the Asprotect API used in proggie packed with version 1.4x. 5. If std function can't find a match, they will be copied to .aspr section...

Game Archive UnPacker 0.6.0.2 PRO - can unpack Clickteam Install Creator

0.6.0.2 PRO (13/02/2009) Legend: (+) - Feature added (!) - Feature changed/corrected (*) - Bug fixed Added unpack support for the following games: + "Beach Head 2002" (*.R24 and *.T24 files); + "Moorhuhn-Im-Anflug" (*.NPK files); + "ExMachina: Meridian 113" (*.GDP files); + "Fable: The Lost Chapters" (*.LUT files); + "Space Rangers" (*.DAT and *.PKG files); + "GTA2" (*.RAW/*.STD files); + "Need for Speed ProStreet" (*.BIN and *.BUN files); + "Test Drive Unlimited" (*.BNK and *.2DB files). * "F.E.A.R." (*.ARCH00 files) bugfix: doesn't replace files in subfolders of archive. ! "Crimsonland" (*.JAZ files) new feature: added mask image in TGA format. 0.6.0.1 PRO (22/01/2009) Legend: (+) - Feature added (!) - Feature changed/corrected (*) - Bug fixed Added unpack support for the following games: + "Tom Clancy's Ghost Recon" (*.RSB files); + ...

ExeInfo PE ver. 0.0.2.0 by A.S.L

___________________________________________________________________________ ExeInfo PE ver. 0.0.2.0 by A.S.L (c) 2006.03 - 2008.xx freeware version for Windows XP Windows 32 PE executable file checker, compilators, exe packers .... with solve hint for unpack/internal exe tools/rippers ___________________________________________________________________________ Internal Tools Menu: --------------------- - overlay remover - generate new file without overlay data - save overlay as external file - EP Corrector (for Delphi) - generate many exe file with Entry Point - EP Corrector (for Delphi) Runtime - correct EP - XoR permutator (xor, or, shl..) - create one file with xor data (255x2000 bytes) - Section splitter - save exe sections as files & exe header - 8/16 bit string finder - enter 8 bit string = searching 16 bit strings & 8 bit (F7 key) - REGistry call finder + CLSID - find registry call & regedit.exe strings - overlay xor uncrypter - uncrypt one byt...

Unpacking StuFF

The Chinese have updated OD plugin: OllyDBG v1.10 plugin - StrongOD v0.18 Temptress Moon Shadow by sea [CUG] ==================================================================== [2008.09.18 v0.18] 1, to repair the Ctrl + G calculation rva, offset when a small BUG 2, when the program is not running the state, Detach before running program 3, restoration of the original data OD zone copy BUG 4, repair od after the CPU running very high occupancy rate BUG 5, you can set it to skip some of the exception handling [2008.09.02 v0.17] 1, to skip some of the improper handling of the abnormal OD 2, correctly handle the instructions int 2d [2008.08.31 v0.16] 1, joined the drive to protect the process, the hidden window, over most of the anti-debugging 2, driver support for the custom equipment 000 (ollydbg.ini of DeviceName, equipment were not more than 8 characters) ollydbg.ini of [StrongOD], you can set up their own HideWindow = 1 to hide the window HideProcess = 1 to hide...