View Single Post
  #8  
Old 02-13-2005, 19:37
Michel Michel is offline
Friend
 
Join Date: Sep 2004
Location: France
Posts: 66
Rept. Given: 2
Rept. Rcvd 6 Times in 1 Post
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
Michel Reputation: 6
You are right, I think it's a recent version : Peid, even with a 200 kb userdb.txt, cann't detect it, but PID 0.5 can. Nevertheless, this version is really easy to unpack.
What is funny is I found these bits of string in the perplex section : "PROGRAM MANAGER.] BY YODA.T.COM/ - .LUGIN - .IALS/FILE_INFO/DOWNLOAD1.PHP?FILE=ACPROTECT_NAGREM" :Lol, it seems the author has read the Shub-Nigurrath's nagremover tut...
The tools he don't like are : EXESPY.WXR95.REGMON.FILE MONITOR.REGMONEX.WINDOW DETECTIVE.DEBUGVIEW.RESSPY.ADVANCED REGISTRY TRACER.REGSNAP.MEMSPY.MEMORY DOCTOR.PROCDUMP32.MEMORY EDITOR.FROGSICE.SMU WINSPECTOR.MEMORY DUMPER.MEMORYMONITOR.NUMEGA SOFTICE LOADER.URSOFT W32DASM.-=CHINA CRACKING GROUP=-.OllyDbg.TRW2000...
Ciao.
Reply With Quote