dEEpEst Posted December 22, 2019 Share Posted December 22, 2019 Unlike programs of this type, it does not use DebugAPI and other features of the operating system. Everything is emulated. You can safely unpack malware for further investigation without the risk of damaging the system. All machine instructions are not executed on a real processor, so unpacking occurs regardless of the processor type and the operating system. It is possible to unpack 64 bit files on 32 operating systems. This build emulates the processors intel x86 and AMD64. It supports unpacking 32 and 64 bit Windows executable files. If there is community interest, it will be possible to unpack other executable files (ELF, MSDOS, Mach-O) and other processors. Due to its capabilities, with the correct manual setting, the program engine can be used to unpack almost any packer / protector. However, this version of the program works in a fully automatic mode and can only unpack simple non-commercial unpackers such as: UPX ASPack NsPack Mpress MEW (Win) Upack FSG and some others. The version of the program with the possibility of unpacking commercial protectors (such as VMProtect, ASProtect and others) will not appear in the public domain for obvious reasons. The program is absolutely free for non-commercial and commercial use. This version is for Windows. If you need a build for Linux, please let me know with the exact name of the operating system (for example Ubuntu 17.10 64 bit). The version for Linux is completely identical to the version of Windows. The program is still in alpha status, so I would be grateful for all the comments on the program, as well as for links to files with simple packers. First of all, packed samples of malicious programs are of interest. Address for communication horsicq [at] gmail.com. This is the hidden content, please Sign In or Sign Up Scan – scan a file for Packer/Protector information. Unpack – unpack a file. If the auto unpacking failed, try Advanced mode. Press Advanced. This is the hidden content, please Sign In or Sign Up Select Generic method. This is the hidden content, please Sign In or Sign Up Press Analyze This is the hidden content, please Sign In or Sign Up Change if necessary OEP and Import This is the hidden content, please Sign In or Sign Up Press Unpack This is the hidden content, please Sign In or Sign Up There is also console version of program (xvlkc.exe). It’s in the folder "base" xvlkc.exe –S <filename> scan a file xvlkc.exe <filename> unpack a file Download: This is the hidden content, please Sign In or Sign Up Password: level23hacktools.com Link to comment Share on other sites More sharing options...
Recommended Posts