吾爱破解 - LCG - LSG |安卓破解|病毒分析|www.52pojie.cn

 找回密码
 注册[Register]

QQ登录

只需一步,快速开始

查看: 4941|回复: 4
收起左侧

[Other] Armadillo Informant 0.9.6 (Beta) Static Armadillo Scanner

[复制链接]
Hmily 发表于 2012-4-4 23:05
Hi to all,

After a long and fruitful investigation of The Armadillo Protection System internals I am able to show to you the some of the results of my research. I am presenting a public beta version of AI 0.9b (Armadillo Informant), which at present has been tested on files protected with Armadillo from version 4.00 up to current 9.00 only.

Note:

* All operations are performed on static files, this tool doesn't execute any processes.
* Versions lower than 3.75 are not supported currently, please note this.
* Unpacked or modified files are unsupported and i have no plans to ever support them.
* Feature requests and bug reports can be posted in this thread and i'll answer them as soon as i can.
* When completed, the tool will be accompanied by a full tutorial explaining how the tool works with Armadillo protected files.

File:                   Armadillo.exe
Path:                   C:\Program Files (x86)\SoftwarePassport

-> newer .text entrypoint signature found.
-> Locate compression options.
-> Locating pointer to application matrix.
-> Get dword from Armadillo code.
-> Get dword from Armadillo code.
-> Skip pdata pre-security.dll portion.
-> Skip tail portion(s).
-> Extract security.dll.
-> Packed size before: 0009951B
-> Packed size after: 0009951B
-> CRC32 Matches!
-> Locate Armadillo version.

* Scan Results *

Detected version:               9.00

* Compression Option *

Compression level:              Best/Slowest

* Protection Options *

CopyMem-II & Debug Blocker
Enable Import Table Elimination
Enable Nanomite Processing
Enable Random PE Names

Armadillo sections:             5

-> Name:                        .whilcb
-> Raw offset:          0x00001000
-> Raw size:            0x000B7000
-> Virtual address:             0x00703000
-> Virtual size:                0x000C0000
-> Characteristics:             0xE0000020

-> Name:                        .otpey
-> Raw offset:          0x000B8000
-> Raw size:            0x0000D000
-> Virtual address:             0x007C3000
-> Virtual size:                0x00010000
-> Characteristics:             0xE0000020

-> Name:                        .cwlot
-> Raw offset:          0x000C5000
-> Raw size:            0x00021000
-> Virtual address:             0x007D3000
-> Virtual size:                0x00030000
-> Characteristics:             0xC0000040

-> Name:                        .toip
-> Raw offset:          0x000E6000
-> Raw size:            0x0000A000
-> Virtual address:             0x00803000
-> Virtual size:                0x00010000
-> Characteristics:             0x42000040

-> Name:                        .avorgb
-> Raw offset:          0x000F0000
-> Raw size:            0x003BA000
-> Virtual address:             0x00813000
-> Virtual size:                0x003C0000
-> Characteristics:             0xC0000040

Text section encrypted: No
Dword shuffling used:   Yes
Number of dwords:               208
Real size of pdata:             0x003B930C
Compression type:               0x2

Raw options value:              0x3DC30A5E
Call exe OEP:           0x00B1F44F
Call dll OEP:           0x00B1DC31
Offset to Security.dll: 0x00000012
Security.dll size:              0x00157000
Security.dll base:              0x10000000
CopyMem-II decrypt:     0x10067CD0

-> Free file buffer.
-> Free .text buffer.
-> Free pdata buffer.
-> Free security.dll buffer.

AI 0.9.6b.rar

79.01 KB, 下载次数: 63, 下载积分: 吾爱币 -1 CB

发帖前要善用论坛搜索功能,那里可能会有你要找的答案或者已经有人发布过相同内容了,请勿重复发帖。

Alar30 发表于 2012-4-6 11:04
谢谢分享工具哈
网络小牛 发表于 2012-4-27 11:25
yuyuchun 发表于 2012-10-3 13:08
jimshicard 发表于 2012-11-15 16:03
支持一下好工具,去试试
您需要登录后才可以回帖 登录 | 注册[Register]

本版积分规则 警告:本版块禁止灌水或回复与主题无关内容,违者重罚!

快速回复 收藏帖子 返回列表 搜索

RSS订阅|小黑屋|处罚记录|联系我们|吾爱破解 - LCG - LSG ( 京ICP备16042023号 | 京公网安备 11010502030087号 )

GMT+8, 2024-5-14 05:52

Powered by Discuz!

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表