Exetools

Exetools (https://forum.exetools.com/index.php)
-   Community Tools (https://forum.exetools.com/forumdisplay.php?f=47)
-   -   protection id 6.2.3 released (https://forum.exetools.com/showthread.php?t=12177)

hypn0 01-22-2015 22:33

Quote:

Originally Posted by Loki (Post 96886)
Just a hunch, but I think he might have guessed that bit :P

I'm understand, he groaned for my post. I'm guilty, really sorry. :D

niculaita 01-24-2015 22:33

Quote:

Originally Posted by evlncrn8 (Post 96349)
what antivirus? and its documented in the nfo file about some antiviruses and false positvies.. simply add an exclusion until they get round to whitelisting..

"same as last year" .. there was more than one release in the past year m8

uploading a non crypted version isnt going to happen, its not my fault the av is a false positive on some av's and im not going to do multiple releases with stuff turned on / off, that makes maintainance a total pain

also, (this is highly ironic), if i remove the encryption (i've tested this, and indeed, this was one of the reasons crypto was added), some anti viruses see some signatures for detection and raise those as false positive.. so its a no win situation

then upload a crypted version made by other cryptor

evlncrn8 01-26-2015 20:25

which cryptor would you suggest?

evlncrn8 01-26-2015 20:27

Quote:

Originally Posted by mcp (Post 96878)
Does anyone know what "WhiteLabel (SecuROM) protection Detected" means? What is this "Whitelabel" tag?

whitelabel means it was renamed and could be 'rebranded' (dss was one of the common names), whitelabel like on records etc

http://en.wikipedia.org/wiki/White-label_product

niculaita 01-27-2015 01:00

repack
 
Quote:

Originally Posted by evlncrn8 (Post 96978)
which cryptor would you suggest?

enigma or vmprotect are ok but private cause public licenceses are antivirus blacklisted

Corsten 10-31-2015 22:42

ProtectionID v6.7.0
31-10-2015

Quote:

Some bugs fixed, some tweaks, some protection detections added, next changelog will be more detailed, as it will give me time to catch up on what i changed, and to add other things and involve the beta testers again but i wanted to get the release done for the traditional halloween release
Download:
Code:

http://pid.gamecopyworld.com/dl.php?f=ProtectionId.670.halloween.2015.rar

niculaita 10-31-2015 23:38

repack with else packer cause it is blocked as virused

evlncrn8 11-01-2015 00:34

no, i havent changed the crypt used on it in years, and im not planning to
and i mentioned the av is a false positive
so simple solution - add the folder to exclusions, or simply dont use it
simple as that, raising the same thing over and over is really boring

and if you see the virus total link i supplied on the home page, you'll see its 1 hit, from microsoft, which always falsely detect that, it will be whitelisted soon hopefully, but for now, the only way to get around it is add the exe to the exclusion list

also, its is NOT fucking virused... if it is, please show me the viral code oh wise one

evlncrn8 11-02-2015 18:16

new virustotal report -> https://www.virustotal.com/en/file/544cdc44c9cb8b9eb0043ccbd89309e88a380a1aacbcd3fb342297bd27626226/analysis/

so only a few hours after release it went to 19/55 'hits' (which i documented on the pid home page), 5 bad votes and 35 good ones, and then some attempt of a hack on the home page too, by someone looking for the source code (or anything related), looking for /jenkins folders etc... which is comical as the source isnt on the home site :)

now, as you can see, i hide nothing... the only av currently flagging pid as 'bad' is microsoft (windows defender etc), which is a false positive, and has happened for a long time, so adding the protectionid exe to the exclusion list is the only way to solve that

i've had no feedback of crashing or anything currently, so i hope that implies the release was a success

daqstar 12-16-2015 22:09

Excellent Release but can't get Context Menu to function!
 

What a host of wonderful features you have injected into Protection ID,
but for some reason I can't get the
'Context Menu'
configuration to work.
(Configuration > Main Configuration > Context Menu)
Sure enough I can apply a tick to the relevant box,
but after 'Applying', Closing and Restarting,
the tick has gone,
and the 'Context Menu' item does not appear.
I have it set to 'run as admin',
so what am I doing wrong?


evlncrn8 12-19-2015 00:46

turn off the fucking colors for a start.. it looks dumb
i guess you did it for attention, it almost worked in the opposite way...

if the context menu doesnt work, then try running protectionid as administrator and doing it then.. it should work and stick.. im guessing you're on windows 10 or similar.. which doesnt let the context menu stuff happen unless admin access is given.. also the code hasnt changed for that part in many many years, so its not a 'new' bug..

1. run as admin
2. turn on context menu
3. exit
4. dont run as admin.. should all be fine then, and pid doesnt really benefit from having admin privs anyway

Corsten 12-24-2015 23:42

Protection ID v6.7.5
 
Protection ID v6.7.5
24-12-2015

Quote:

I fixed some bugs and tweaked more code making things a bit more stable, I plan to add in taggant v2 support soon,
but im having trouble obtaining sample files to work from (i dont use the taggant lib), so if anyone wants to help with
that please do so.

I plan to wind down this version and start on v7 as soon as possible, most will port over relatively easily and
the goal is to make an x64, x86, gui and console versions, with most of the code being in c/c++ for portability
(asm doesnt port too easily).. and will focus on it having a scanning core initially, and some pe
(perhaps elf etc too) tools built in

If you'd like to contribute to v7 please get in touch at the email above, same goes if anyone wants to donate anything
Download:
Code:

http://pid.gamecopyworld.com/dl.php?f=ProtectionId.675.December.2015.rar

TechLord 11-01-2016 19:48

Protection ID v6.8.0 ( Halloween 2016) Released.
31-10-2016

Quote:

"Change Log :

I fixed some bugs and tweaked more code making things a bit more stable, and added some new detections.
Some bugs (like the pestuff ones) still exist, as they didnt make it to the 'fixed' list but should hopefully be addressed for the christmas / holiday season release

I also didnt find any taggant v2 samples, so that didnt make it into the release either, other things did though so i hope this release brings some pleasure to previous users."
Download Here :

Code:

http://pid.serveexchange.com/dl.php?f=ProtectionId.680.halloween.2016.rar

evlncrn8 11-01-2016 21:18

wow, someone noticed :)

TechLord 11-02-2016 07:40

Quote:

Originally Posted by evlncrn8 (Post 107577)
wow, someone noticed :)

I am sure that just like me, the entire reversing community would have been waiting for this release :)

Great job , I must say ! :)


All times are GMT +8. The time now is 02:05.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX