<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0">
<channel>
  <title>CGSoftLabs Forum</title>
  <link>http://makephpbb.com/phpbb/index.php?mforum=cgsoftlabs</link>
  <description>A place to talk about CGSoftLabs releases</description>
  <language>english</language>
  <copyright>(c) Copyright 2010 by CGSoftLabs Forum</copyright>
  <managingEditor>christig2k2@yahoo.com</managingEditor>
  <webMaster>christig2k2@yahoo.com</webMaster>
  <pubDate>Fri Jul 30, 2010 9:09 pm</pubDate>
  <lastBuildDate>Fri Jul 30, 2010 9:09 pm</lastBuildDate>
  <docs>http://backend.userland.com/rss</docs>
  <generator>phpBB2 RSS Syndication Mod by Lucas</generator>
  <ttl>1</ttl>

  <image>
    <title>CGSoftLabs Forum</title>
    <url></url>
    <link>http://makephpbb.com/phpbb/</link>
    <description>A place to talk about CGSoftLabs releases</description>
  </image>

                                      <item>
                                        <title>Problem while compressing a x64 DLL from the command line</title>
                                        <link>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=195#195</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://makephpbb.com/phpbb/profile.php?mforum=cgsoftlabs&amp;mode=viewprofile&amp;u=2'&gt;CGSoftLabs&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Thu May 06, 2010 5:19 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      Only if you are a registered user.</description>
                                        <comments>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=195#195</comments>
                                        <author>CGSoftLabs</author>
                                        <pubDate>Thu May 06, 2010 5:19 am</pubDate>
                                        <guid isPermaLink="true">http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=195#195</guid>
                                      </item>
                                      <item>
                                        <title>Working status on v 1.8.x</title>
                                        <link>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=190#190</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://makephpbb.com/phpbb/profile.php?mforum=cgsoftlabs&amp;mode=viewprofile&amp;u=2'&gt;CGSoftLabs&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Thu Jan 28, 2010 2:38 pm&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      I'm working at an 32bit Advanced Protection Engine which will use between other a VM implementation;&lt;br /&gt;
&lt;br /&gt;
for a given function, the engine should perform:&lt;br /&gt;
1. disassembling and building of a linked list of instructions;&lt;br /&gt;
Then perform per instruction (a kind of plug-ins for the engine):&lt;br /&gt;
 -2. per instruction expander (metamorphism; replace 1 instr with other: one ore more similar) ;&lt;br /&gt;
 -3. random virtualization of a set of handled instructions (this requires a VM);&lt;br /&gt;
 -4. obfuscation; insertion of junk (ie ebo1xx) instructions which will make harder analyzing of disassembled code;&lt;br /&gt;
 -5. anti-cracking; small blocks inserted on the fly between instructions; anti-tracing, seh etc;&lt;br /&gt;
7. rebuild the code; link instructions in other order; use jmps between; link virtualized instructions with VM;&lt;br /&gt;
&lt;br /&gt;
the engine should accept customization of  how much obfuscation,virtualization,metamorphism to apply; &lt;br /&gt;
&lt;br /&gt;
this engine will help protecting:&lt;br /&gt;
- almost every functions in the protection stub;&lt;br /&gt;
- EP;&lt;br /&gt;
- code inside target;&lt;br /&gt;
...making disassembling a pain, mostly to myself  &lt;img src=&quot;images/smiles/icon_lol.gif&quot; alt=&quot;Laughing&quot; border=&quot;0&quot; /&gt;</description>
                                        <comments>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=190#190</comments>
                                        <author>CGSoftLabs</author>
                                        <pubDate>Thu Jan 28, 2010 2:38 pm</pubDate>
                                        <guid isPermaLink="true">http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=190#190</guid>
                                      </item>
                                      <item>
                                        <title>To AV developers</title>
                                        <link>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=187#187</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://makephpbb.com/phpbb/profile.php?mforum=cgsoftlabs&amp;mode=viewprofile&amp;u=2'&gt;CGSoftLabs&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Wed Jan 20, 2010 9:48 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      Please contact me for older vesions of eXPressor, or any other questions.</description>
                                        <comments>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=187#187</comments>
                                        <author>CGSoftLabs</author>
                                        <pubDate>Wed Jan 20, 2010 9:48 am</pubDate>
                                        <guid isPermaLink="true">http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=187#187</guid>
                                      </item>
                                      <item>
                                        <title>About fake virus detection of your packed/protected software</title>
                                        <link>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=186#186</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://makephpbb.com/phpbb/profile.php?mforum=cgsoftlabs&amp;mode=viewprofile&amp;u=2'&gt;CGSoftLabs&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Wed Jan 20, 2010 9:40 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      Yesterday I have contacted some AV companies:  McAfee, Sophos, F-prot regarding this problem; they are lazy companies which doesn't handle all packer/protectors; it's true that eXPressor isn't such popular but this is not a reason not to learn your software to scan inside protected files; that's why, first virus found packed with eXPressor becomes a signature in their database and after that, all apps protected will be seen as that virus; in other words virustotal.com shows you which av software is good and which is bad;&lt;br /&gt;
 &lt;br /&gt;
If your software is fake detected as a virus I advise you (if you wish to help) to contact av companie and complain that their av. block your protected software; they will fix the problem at some moment.</description>
                                        <comments>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=186#186</comments>
                                        <author>CGSoftLabs</author>
                                        <pubDate>Wed Jan 20, 2010 9:40 am</pubDate>
                                        <guid isPermaLink="true">http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=186#186</guid>
                                      </item>
                                      <item>
                                        <title>Working status on v 1.7.x</title>
                                        <link>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=180#180</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://makephpbb.com/phpbb/profile.php?mforum=cgsoftlabs&amp;mode=viewprofile&amp;u=2'&gt;CGSoftLabs&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Wed May 27, 2009 5:32 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      I was occupied with something else during last weeks so I had to cancel the  programming session; last days I did some progress and I hope I'll finish the features I've planned for this version.</description>
                                        <comments>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=180#180</comments>
                                        <author>CGSoftLabs</author>
                                        <pubDate>Wed May 27, 2009 5:32 am</pubDate>
                                        <guid isPermaLink="true">http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=180#180</guid>
                                      </item>
                                      <item>
                                        <title>Virtual Size = Raw Size (Why?)</title>
                                        <link>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=179#179</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://makephpbb.com/phpbb/profile.php?mforum=cgsoftlabs&amp;mode=viewprofile&amp;u=2'&gt;CGSoftLabs&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Thu May 21, 2009 7:45 pm&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      you can edit later virtual size...since it's just a dword inside section's header</description>
                                        <comments>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=179#179</comments>
                                        <author>CGSoftLabs</author>
                                        <pubDate>Thu May 21, 2009 7:45 pm</pubDate>
                                        <guid isPermaLink="true">http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=179#179</guid>
                                      </item>
                                      <item>
                                        <title>Help!!</title>
                                        <link>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=161#161</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://makephpbb.com/phpbb/profile.php?mforum=cgsoftlabs&amp;mode=viewprofile&amp;u=2'&gt;CGSoftLabs&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Wed Dec 17, 2008 2:07 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      sorry but you must first learn some english; I can't understand really what are you trying to say.  &lt;img src=&quot;images/smiles/icon_confused.gif&quot; alt=&quot;Confused&quot; border=&quot;0&quot; /&gt;</description>
                                        <comments>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=161#161</comments>
                                        <author>CGSoftLabs</author>
                                        <pubDate>Wed Dec 17, 2008 2:07 am</pubDate>
                                        <guid isPermaLink="true">http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=161#161</guid>
                                      </item>
                                      <item>
                                        <title>Crash on &amp;quot;about&amp;quot; and &amp;quot;protection&amp;quot; dialog</title>
                                        <link>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=159#159</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://makephpbb.com/phpbb/profile.php?mforum=cgsoftlabs&amp;mode=viewprofile&amp;u=2'&gt;CGSoftLabs&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Tue Oct 21, 2008 9:36 pm&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      problem fixed.</description>
                                        <comments>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=159#159</comments>
                                        <author>CGSoftLabs</author>
                                        <pubDate>Tue Oct 21, 2008 9:36 pm</pubDate>
                                        <guid isPermaLink="true">http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=159#159</guid>
                                      </item>
                                      <item>
                                        <title>About he future of IETools (msie7 and later)</title>
                                        <link>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=157#157</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://makephpbb.com/phpbb/profile.php?mforum=cgsoftlabs&amp;mode=viewprofile&amp;u=2'&gt;CGSoftLabs&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Fri Apr 18, 2008 7:04 pm&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      Well since m$ brooked the msie continuity with latest ie7 adding tabbed browsing the IETools won't work anymore; with the intrinsic PopUp blocker this feature doesn't have sense (90%) inside IETools (don't forget that IETools started as a popup blocker)&lt;br /&gt;
&lt;br /&gt;
Since I have limited time, although some time ago I started the basic skeleton of the BHO for msie7, I don't see in the actual circumstances, when I'll continue this project again. It was a failure regarding benefits (one or 2 licenses sold). I would love having more time, recoding IETools again, just for my pleasure, but for the moment all my energy goes enhancing eXPressor.&lt;br /&gt;
&lt;br /&gt;
Meanwhile you can use &lt;a href=&quot;http://www.ie7pro.com,&quot; target=&quot;_blank&quot;&gt;http://www.ie7pro.com,&lt;/a&gt; it seems a nice plugin, and the interface looks quite similar to IETools  &lt;img src=&quot;images/smiles/icon_lol.gif&quot; alt=&quot;Laughing&quot; border=&quot;0&quot; /&gt; &lt;br /&gt;
&lt;br /&gt;
And btw, Firefox beats msie (I'm writing this from fox &lt;img src=&quot;images/smiles/icon_smile.gif&quot; alt=&quot;Smile&quot; border=&quot;0&quot; /&gt; )</description>
                                        <comments>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=157#157</comments>
                                        <author>CGSoftLabs</author>
                                        <pubDate>Fri Apr 18, 2008 7:04 pm</pubDate>
                                        <guid isPermaLink="true">http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=157#157</guid>
                                      </item>
                                      <item>
                                        <title>Solutions &amp;amp; remedies</title>
                                        <link>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=155#155</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://makephpbb.com/phpbb/profile.php?mforum=cgsoftlabs&amp;mode=viewprofile&amp;u=2'&gt;CGSoftLabs&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Fri Apr 18, 2008 6:37 pm&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      Hope this will help some other people &lt;img src=&quot;images/smiles/icon_smile.gif&quot; alt=&quot;Smile&quot; border=&quot;0&quot; /&gt;&lt;br /&gt;
&lt;br /&gt;
While switching eXPressor's sourcecode from vc6 to vc8 I came across a number of problems; one of them was that vc8 linker won't let us merge anymore all sections in one as we want, he sticks IAT at the very beginning of first section; and since my  source code relies on that I was forced to find a hack in order to skip recoding which in the particularly case of building stubs is very hard due limited debugging options.&lt;br /&gt;
&lt;br /&gt;
In my stubs I do modifications for some global vars after building; since now I don't have my vars at the beginning of the firsts section I have 2 alternatives:&lt;br /&gt;
&lt;br /&gt;
1.Enable /MAP file and build a simple parser to retrieve variables and functions VA. once I have VA I know where to apply the patch.&lt;br /&gt;
&lt;br /&gt;
2.Find a hack and  use the old method: structures stored inside specific PE directories like below:&lt;br /&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Code:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;code&quot;&gt;#pragma data_seg &amp;#40; &amp;quot;.A$A&amp;quot; &amp;#41;&lt;br /&gt;
DWORD dwVal1 = 1;&lt;br /&gt;
DWORD dwVAl2 = 2;&lt;br /&gt;
//...etc&lt;br /&gt;
#pragma data_seg&amp;#40;&amp;#41;&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;br /&gt;
&lt;br /&gt;
Now I know for sure that those vars are placed at the beginning of section .A and you can access them later via section[.A].VirtualAddress.&lt;br /&gt;
&lt;br /&gt;
The linker will always put teh IAT table (which lies in .idata$5) at the very beginning of teh first section which normally starts at 0x1000, and since I merge all my stub sections in .A I have problems modifying my globals.  I found a hack to force having global variables at the very beginning of first section for easy access (we don't even need the /MAP file); in the code above, replace &amp;quot;.A$A&amp;quot; with &amp;quot;.idata$5&amp;quot;</description>
                                        <comments>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=155#155</comments>
                                        <author>CGSoftLabs</author>
                                        <pubDate>Fri Apr 18, 2008 6:37 pm</pubDate>
                                        <guid isPermaLink="true">http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=155#155</guid>
                                      </item>
                                      <item>
                                        <title>where i can down the tools?</title>
                                        <link>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=154#154</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://makephpbb.com/phpbb/profile.php?mforum=cgsoftlabs&amp;mode=viewprofile&amp;u=2'&gt;CGSoftLabs&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Tue Apr 15, 2008 3:53 pm&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      what tools?</description>
                                        <comments>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=154#154</comments>
                                        <author>CGSoftLabs</author>
                                        <pubDate>Tue Apr 15, 2008 3:53 pm</pubDate>
                                        <guid isPermaLink="true">http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=154#154</guid>
                                      </item>
                                      <item>
                                        <title>Feel free to post in here</title>
                                        <link>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=152#152</link>
                                        <description>&lt;br /&gt;
                                      &lt;b&gt;Author:&lt;/b&gt; &lt;a href='http://makephpbb.com/phpbb/profile.php?mforum=cgsoftlabs&amp;mode=viewprofile&amp;u=204'&gt;haileyuxin&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      &lt;b&gt;Posted:&lt;/b&gt; Sat Apr 12, 2008 7:21 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &amp;#35874;&amp;#35874; &amp;#20320;&amp;#20204; &amp;#25105;&amp;#20250;&amp;#25903;&amp;#25345;&amp;#20320;&amp;#20204;&amp;#30340;&amp;#65281;</description>
                                        <comments>http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=152#152</comments>
                                        <author>haileyuxin</author>
                                        <pubDate>Sat Apr 12, 2008 7:21 am</pubDate>
                                        <guid isPermaLink="true">http://makephpbb.com/phpbb/viewtopic.php?mforum=cgsoftlabs&amp;p=152#152</guid>
                                      </item></channel></rss>