首页
社区
课程
招聘
[下载]ArmaG3ddon v1.8 [穿山甲脱壳工具]
发表于: 2010-1-20 08:47 108115

[下载]ArmaG3ddon v1.8 [穿山甲脱壳工具]

2010-1-20 08:47
108115
http://www.accessroot.com/arteam/site/download.php?view.262

===========================================================
Version History

Current Release: December 2009 v1.8
+ new internal Nanomites Fixer ArmNF.dll v1.0 for analyzing / patching nanomites from NeVaDa
+ new PEiDLL.dll v1.06 from Bob, "Powered by" PEiD v0.94 by snaker, Jibz & Qwerton
+ updates to support ArmNF.dll and PEiDLL.dll
+ new group box to support the loading and saving of preconfigured option (initialization) files
+ fixed small problem with repairing nanos for minsize dump
+ fixed some problems associated with UPX
+ new bypass 2nd .text option
+ refinements to the OEP process for 2nd text section
+ use of copymemII option to detach bypasses dump messagebox
+ Updated Arteam Import Reconstructor (Nacho_dj) version 1.6.4 December 2009
Includes:
+ An important bug fixed about IAT Size when rebuilding imports by relocations
+ Fixed a bug when rebuilding resources
+ Improved detection of overlay offset
+ Fixed rebuilding resources from other section than .rsrc
+ Fixed a bug when rebuilding imports by relocations
+ Added a new type of compiled to rebuild properly all sections
+ Added more possibilities to rebuild overlay
+ Improved detection of pdata section
+ Added some checks about PE header of dump
+ Fixed a bug when getting forwarded functions related to Wsock32.dll/ws2_32.dll
+ Fixed a bug that was destroying export table
+ Fixed a bug related to pointers for PE header names
+ Improved the rebuilding of sections and relocations for Delphi and Borland C++ targets
+ Recoded the Rebuild imports procedure to cover different compiled executables
+ Fixed a bug when rebuilding original IT for VC++ targets
+ Added support for UPX targets using overlay
+ Armadillo Nanomites Fixer v1.2 (public release) has been included into this
distribution by NeVaDa
UnReal-RCE
Persian Crackers
==========================================================

Known Issues

You are encouraged to use tools like ArmaDetach or ArmadilloFindProtected to determine version / features / protection options of a target application. Should the Import Reconstructor fail, i.e. return code > 0, a workaround is (Rerun the program, when the program asks you to dump / save, press "Cancel") to perform the dump and IAT rebuild yourself using a 3rd party tool (LordPE or similar), CHImpRec, ImpREC (or Magic_h2001's Universal Import fixer - UIF, etc.) to dump and/or rebuild the imports.
Should the application appear to hang (do nothing) it could be that the process is taking some time to unpack, a resource conflict, a compatibility issue with your OS, your AV program running in the background or, the version of Armadillo is not supported! In some cases, if you try again, it may work due to available resources (memory).
Note: Make sure there are no other instances of the target program running in Windows Task manager before proceeding. Make sure there are no instances of applications running with the Window Captions similar to "Armageddon" or "@rm@Geddon" or similar.

Armadillo V6.0+ (Custom Builds)

You may need to patch for the condition "Armadillo not protected" MessageBox before executing a newly dumped file. This messagebox is generated when the variable ALTUSERNAME is not found when executing the GetEnvironmentVariableA API. This is quite normal after dumping an application.

As with any custom build, it is always a good idea to use the SetEnvironmentVariableA API for all relevant Armadillo variables in your dumped file prior to executing from the OEP (i.e. build / run from an existing code cave and return to OEP).

[注意]传递专业知识、拓宽行业人脉——看雪讲师团队等你加入!

上传的附件:
收藏
免费 0
支持
分享
最新回复 (61)
雪    币: 51
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
2
膜拜下,好东西
2010-1-20 09:05
0
雪    币: 113
活跃值: (16)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
3
好东西呀   对付穿山甲的又一利器
2010-1-21 17:31
0
雪    币: 407
活跃值: (11)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
4
很好的工具,感谢楼主!
2010-1-22 11:33
0
雪    币: 179
活跃值: (50)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
5
1.8的好些有汉化的
2010-1-22 12:49
0
雪    币: 202
活跃值: (46)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
6
膜拜下利器,一物降一物啊
2010-1-22 14:34
0
雪    币: 108
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
7
英文看不懂。。
2010-1-22 22:59
0
雪    币: 212
活跃值: (13)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
8
很好的工具,感谢楼主!
2010-1-22 23:25
0
雪    币: 212
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
9
".....一物降一物....."呵呵....
2010-1-22 23:34
0
雪    币: 338
活跃值: (10)
能力值: ( LV4,RANK:50 )
在线值:
发帖
回帖
粉丝
10
这个脱壳机,很强悍
2010-1-22 23:54
0
雪    币: 125
活跃值: (15)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
11
怎么报毒呢???
2010-1-23 20:44
0
雪    币: 97697
活跃值: (200734)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
12
正常,使用时关闭就可以.
2010-1-23 21:06
0
雪    币: 210
活跃值: (20)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
13
在那有汉化的
2010-1-24 01:47
0
雪    币: 200
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
14
谢谢,下来试试
2010-1-24 10:34
0
雪    币: 201
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
15
是看不太懂,先下来试试,
2010-1-24 12:26
0
雪    币: 72
活跃值: (30)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
16
很好的工具,感谢楼主!
2010-1-24 12:26
0
雪    币: 7832
活跃值: (2567)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
17
好东西
2010-1-30 23:30
0
雪    币: 201
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
18
支持下.........
2010-2-12 17:11
0
雪    币: 203
活跃值: (42)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
19
嗯,先支持,再去下吧!
2010-2-13 11:20
0
雪    币: 180
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
20
很好的脱壳软件。用过1.6版的。
感谢楼主分享!
2010-2-15 11:25
0
雪    币: 202
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
21
也来见识下,不知2010年大礼包里有没有
2010-2-15 11:58
0
雪    币: 170
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
22
如何使用, 有没有成功的教程。
带key的怎么弄
2011-2-9 11:10
0
雪    币: 207
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
23
谢谢分享,收藏
2011-3-10 02:26
0
雪    币: 162
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
24
好东西,强贴,现在是1.9了
2011-3-30 10:29
0
雪    币: 157
活跃值: (20)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
25
1.9我用了,为什么拖不掉呢
Armadillo v1.xx - v2.xx or 2.51 - 3.xx DLL Stub -> Silicon Realms Toolworks
就是不行,高手能指点一下么
2011-6-26 17:20
0
游客
登录 | 注册 方可回帖
返回
//