Quick Unpack v1.0 Readme
========================
Description
-----------
The program is intended for fast (in 2 seconds) unpacking simple packers (UPX, ASPack, PE Diminisher, PECompact, PE-PACK, PackMan, WinUPack and many others). Quick Unpack tries to bypass all possible scramblers/obfuscators. From the version 1.0 the opportunity of unpacking dll is added. This opportunity makes Quick Unpack unique software product which has no similar analogues in the world!
Technology of import recovery
-----------------------------
I recommend to look through the list of import rather attentively.. There can be fake functions in it!! So the unpacked program can be unable to work because of them..
The import recovery with syd's method works so: after loading the program, the dlls which it loads are hooked. The export is scanned from them. Then the program will be dumped and the addresses which coincide with the address from that dlls will be searched for. If coincides, this address will be called Record RVA and will be included in a cycle of creation the table of import further.
If addresses casually concides with the addresses from hooked dlls, they will be added in the list of import too but if you are rather experienced in unpacking to find them, they can be removed (for this purpose numbers of the sections and their names are showed). More often import lays in one section so be very attentive please.
There are some records in the file replace.ini according to which you should replace some functions in the import list. The matter is that e.g if you call GetProcAddress(GetModuleHandle("kernel32"), "HeapFree"), your system will return the address in ntdll.dll and it will be the address of api-function RtlFreeHeap. I have added in this list the api I met earlier. If you will notice some records from ntdll.dll in the list of import, try to find the replacement for them in your system. If it will be impossible, simply try to remove them.
In the Quick Unpack there is the opportunity of marking possible invalid records is added, for their removing please press the button "Delete invalid".
The license and rights
----------------------
The list of sources used in coding Quick Unpack 1.0.
GenOEP.dll by Snaker
ImpREC.dll by MackT
stripper asprotect unpacker by syd
History of the versions
-----------------------
v1.0 beta7 [+] Improved interface
[+] Fixed small bugs
v1.0 beta6 [!] Internal build
v1.0 beta5 [+] Support of unpacking UPX 2.0
[+] New signature list
[+] New ingine from stripper 2.13 b9
v1.0 beta4 internal [!] bugfixes
v1.0 [+] the opportunity of unpacking dlls
[+] the Opportunity of using plug-ins and own OEP finders is added.
v0.7 [!] Based on updated stripper 2.11 rc3 engine => new features
[+] Force mode added v0.6 [!] Final build
v0.5 [+] Quick Unpack now uses new engines and works through external tracer engine.sys. No debug API is used.
[+] Dump and PE header is very clean after unpacking
[+] Cool OEP finder for packers
v0.43. [+] The opportunites of ImpREC.dll were added. It will be useful, I think.
[+] Protection from IsDebuggerPresent was added (a tick " Hide unpacker ")
[!] This version is last, I think, as the opportunities of Debug API are fully used.
v0.41. [!] Fixed the bug with the unpacked programs compatiblity on the different OS (the bug with RestoreLastError)
v0.4 final. Final bild. All the mistakes were fixed.
v0.3. [+] The engine working with the dump is �ompletely re-coded.
Now the engine from PE Tools by NEOx [uinC] is used.
[+] The system of "clever" dump rebuilding and optimizing its size is supported.
The engine of the dump rebuilding from PE Tools by NEOx [uinC] was used.
[!] Picture of Quick Unpack was removed :)
[+] Packers with damaged headers (e.g. FSG) are supported.
[+] The bugs in the operations with PE files were fixed.
v0.2. The first version. All as is.
Greetz and thanks
-----------------
Thanks to: AHTeam, TSRh, KpTeam, REVENGE, CRACKLAB, ICU members, CoaxCable^CPH, Wild-Wolf and all CPH members on #cph, LaFarge [ICU] for nice music, syd, Aster!x, MozgC [TSRh], Sten, PolishOX, NEOx [uinC], WELL, GPcH, newborn, Funbit, sl0n, Ms-Rem, Bad_guy...
没有合适的资源?快使用搜索试试~ 我知道了~
Quick Unpack 全集
共144个文件
dll:49个
txt:20个
ini:7个
1星 需积分: 12 13 下载量 179 浏览量
2012-04-11
11:35:10
上传
评论
收藏 1.54MB RAR 举报
温馨提示
Quick Unpack 全集木马加壳软件是一款木马加壳软件。现在的一般都能免杀。
资源推荐
资源详情
资源评论
收起资源包目录
Quick Unpack 全集 (144个子文件)
UPackOEP.bdsproj 8KB
UPackOEP.bdsproj 8KB
UPackOEP.bdsproj 8KB
UPackOEP.bdsproj 8KB
UPackOEP.cfg 504B
UPackOEP.cfg 504B
UPackOEP.cfg 504B
UPackOEP.cfg 504B
PluginEx.cpp 763B
PluginEx.cpp 763B
PluginEx.cpp 763B
PluginEx.cpp 763B
UsArdll.d11 15KB
pelib.dcu 6KB
pelib.dcu 6KB
pelib.dcu 6KB
pelib.dcu 6KB
PluginEx.def 184B
PluginEx.def 184B
PluginEx.def 184B
PluginEx.def 184B
PEiDLL.DLL 227KB
PEiDLL.DLL 227KB
PEiDLL.DLL 227KB
PEiDLL.DLL 227KB
ImpREC.dll 184KB
Force.dll 76KB
Force.dll 76KB
Force.dll 76KB
Force.dll 71KB
PESniffer.dll 64KB
PESniffer.dll 64KB
PESniffer.dll 64KB
PESniffer.dll 64KB
cadt.dll 32KB
Force.dll 23KB
selfscan.dll 18KB
selfscan.dll 18KB
selfscan.dll 18KB
selfscan.dll 17KB
UPackOEP.dll 16KB
UPackOEP.dll 16KB
UPackOEP.dll 16KB
Human.dll 14KB
WWPack32OEP.dll 10KB
PackManOEP.dll 10KB
PEPack10OEP.dll 10KB
EXE32PackOEP.dll 10KB
PackManOEP.dll 10KB
WWPack32OEP.dll 10KB
PackManOEP.dll 10KB
EXE32PackOEP.dll 10KB
EXE32PackOEP.dll 10KB
PEPack10OEP.dll 10KB
WWPack32OEP.dll 10KB
PEPack10OEP.dll 10KB
StealthPE21OEP.dll 9KB
StealthPE21OEP.dll 9KB
StealthPE21OEP.dll 9KB
deroko.dll 8KB
GenOEP.dll 6KB
GenOEP.dll 6KB
GenOEP.dll 6KB
GenOEP.dll 6KB
UsAr.dll 4KB
PECompactv2.x.dll 3KB
PluginEx.dll 2KB
PluginEx.dll 2KB
PluginEx.dll 2KB
PluginEx.dll 2KB
UPackOEP.dpr 8KB
UPackOEP.dpr 8KB
UPackOEP.dpr 8KB
UPackOEP.dpr 8KB
PluginEx.dsp 4KB
PluginEx.dsp 4KB
PluginEx.dsp 4KB
PluginEx.dsp 4KB
PluginEx.dsw 539B
PluginEx.dsw 539B
PluginEx.dsw 539B
PluginEx.dsw 539B
qunpack.exe 1.03MB
QUnpack.exe 644KB
qunpack.exe 588KB
QUnpack.exe 395KB
QUnpackchs.exe 275KB
PluginEx.h 535B
PluginEx.h 535B
PluginEx.h 535B
PluginEx.h 535B
LUA Manual.html 237KB
replace.ini 664B
replace.ini 664B
replace.ini 664B
replace.ini 664B
QU.ini 33B
QU.ini 33B
QU.ini 33B
UPackOEP.bdsproj.local 99B
共 144 条
- 1
- 2
资源评论
- 磁悬浮青蛙呱呱呱2020-07-14只有0.7, 1.0, 2.0这几个很旧的版本,没有4.3等新版,用处不大。
li050667
- 粉丝: 2
- 资源: 2
上传资源 快速赚钱
- 我的内容管理 展开
- 我的资源 快来上传第一个资源
- 我的收益 登录查看自己的收益
- 我的积分 登录查看自己的积分
- 我的C币 登录后查看C币余额
- 我的收藏
- 我的下载
- 下载帮助
安全验证
文档复制为VIP权益,开通VIP直接复制
信息提交成功