首页
社区
课程
招聘
[转帖]OllyExt 1.1 by Ferrit
发表于: 2013-3-27 23:31 13216

[转帖]OllyExt 1.1 by Ferrit

2013-3-27 23:31
13216
OllyExt 1.1 by Ferrit
The main intention of this plugin is to provide the biggest anti-anti debugging features and bugfixes for Olly 2.xx. Updates will come...

VMProtect support!

The currently supported protections are the following:
- IsDebuggerPresent
- NtGlobalFlag
- HeapFlag
- ForceFlag
- CheckRemoteDebuggerPresent
- OutputDebugString
- CloseHandle
- SeDebugPrivilege
- BlockInput
- ProcessDebugFlags
- ProcessDebugObjectHandle
- TerminateProcess
- NtSetInformationThread
- NtQueryObject
- FindWindow
- NtOpenProcess
- Process32First
- Process32Next
- ParentProcess
- GetTickCount
- timeGetTime
- QueryPerformanceCounter
- ZwGetContextThread
- NtSetContextThread
- KdDebuggerNotPresent
- KdDebuggerEnabled
- NtSetDebugFilterState
- ProtectDRX
- HideDRX
- DbgPrompt

The currently supported bugfixes are the following:
- Caption change
- Kill Anti-Attach ( dll integrity check )

Requirements:
- Microsoft Visual C++ 2010 Redistributable Package (x86)
- On x64 platfoms the testsigning has to be turned on because of the protection driver
1. bcdedit -set testsigning on
2. Reboot windows

OS support:
- WinXP x32
- WinXP WoW64
- Win7 x32
- Win7 WoW64


[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)

上传的附件:
收藏
免费 1
支持
分享
最新回复 (12)
雪    币: 153
活跃值: (260)
能力值: ( LV5,RANK:60 )
在线值:
发帖
回帖
粉丝
2
沙发啊 支持
2013-3-28 07:45
0
雪    币: 341
活跃值: (143)
能力值: ( LV7,RANK:110 )
在线值:
发帖
回帖
粉丝
3
下载试试。。。
2013-3-28 08:11
0
雪    币: 27
活跃值: (127)
能力值: ( LV8,RANK:120 )
在线值:
发帖
回帖
粉丝
4
"for Olly 2.xx

OS support:
- WinXP x32
- WinXP WoW64
- Win7 x32
- Win7 WoW64"

very nice..
2013-3-28 09:51
0
雪    币: 3305
活跃值: (2027)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
5
Win 7 x64 运行出错,提示:

Unable to start service,

File: OllyExtDriver.cpp Line: 111
2013-3-28 10:04
0
雪    币: 8996
活跃值: (3213)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
6
下载试用……
2013-3-28 10:42
0
雪    币: 216
活跃值: (370)
能力值: ( LV7,RANK:100 )
在线值:
发帖
回帖
粉丝
7
要启用testsign并重启,说明里有。
不过,只要你还没有遇到那么BT的壳,可以不管这个提示。
没事就加个驱动也不好。
2013-3-28 10:52
0
雪    币: 3305
活跃值: (2027)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
8
什么是 testsign?是软件,还是 dos 命令?

怎么开启?用软件开启,还是 dos 命令开启?

谢谢。
2013-3-28 22:53
0
雪    币: 98745
活跃值: (201039)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
9
OllyExt 1.2
上传的附件:
2013-4-13 14:13
0
雪    币: 371
活跃值: (72)
能力值: ( LV5,RANK:60 )
在线值:
发帖
回帖
粉丝
10
[ATTACH]OllyExt 1.22[/ATTACH]

The main intention of this plugin is to provide the biggest anti-anti debugging features and bugfixes for Olly 2.xx. Updates will come...

VMProtect support!

The currently supported protections are the following:
- IsDebuggerPresent
- NtGlobalFlag
- HeapFlag
- ForceFlag
- CheckRemoteDebuggerPresent
- OutputDebugString
- CloseHandle
- SeDebugPrivilege
- BlockInput
- ProcessDebugFlags
- ProcessDebugObjectHandle
- TerminateProcess
- NtSetInformationThread
- NtQueryObject
- FindWindow
- NtOpenProcess
- Process32First
- Process32Next
- ParentProcess
- GetTickCount
- timeGetTime
- QueryPerformanceCounter
- ZwGetContextThread
- NtSetContextThread
- KdDebuggerNotPresent
- KdDebuggerEnabled
- NtSetDebugFilterState
- ProtectDRX
- HideDRX
- DbgPrompt

The currently supported driver based protections are the following:
- RDTSC

The currently supported bugfixes are the following:
- Caption change
- Kill Anti-Attach ( dll integrity check )

Requirements:
- Microsoft Visual C++ 2010 Redistributable Package (x86)

OS support:
- WinXP x32
- WinXP WoW64 (LIMITED FEATURES)
- Win7 x32
- Win7 WoW64 (LIMITED FEATURES)

Limitations:
- Driver based protection works ONLY on x86 platform

If you have any problem just notify me.
Image        no image available
Filesize        149.31 kB
Date        Sunday 12 May 2013 - 11:23:15
上传的附件:
2013-7-24 21:22
0
雪    币: 196
活跃值: (46)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
11
谢谢谢谢,太辛苦楼主了。
2013-10-13 21:28
0
雪    币: 98745
活跃值: (201039)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
12
OllyExt 1.7
上传的附件:
2014-2-5 02:14
0
雪    币: 3305
活跃值: (2027)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
13
已经 1.8 了。
2014-2-5 23:12
0
游客
登录 | 注册 方可回帖
返回
//