Skip to content

Repository files navigation

PKZIP/PKUNZIP/PKSFX/PKLITE utilities


Classic DOS PKZIP

PKZIP 2.04g

The latest DOS PKZIP 2.04g releases are archived here, both in their original forms including documentation and utilities where available, as well as binaries that have been properly unpacked, decrypted, and PSP patched when necessary. The unpacked versions are useful for further reverse engineering and analysis and also load faster on slow machines (like 8086/8088 systems).

Directory Description Date
pkzip/2.04g/docs PKZIP 2.04g Documentation 02‑01‑1993
pkzip/2.04g/shareware PKZIP 2.04g Shareware 02‑01‑1993
pkzip/2.04g/registered PKZIP 2.04g Registered 02‑01‑1993

The files in these directories are meant to be additive (or cumulative):

  • The files in the Documentation directory apply to all PKZIP 2.04g/2.06 versions.
  • The files in the Shareware directory represent the complete PKZIP 2.04g Shareware release.
  • The files in the Registered directory replace the 2.04g Shareware files.
  • The files in the IBM Licensed directory (see below) replace the 2.04g Registered files.

Tip

To make a complete DOS PKZIP distribution, first create a directory containing all the Shareware files, then copy the Registered files into this same directory. Make sure that you overwrite any files with the same name. If you desire, you can do the same to "upgrade" to the IBM Licensed 2.06 release, but you should read the following section for more details first.

PKZIP 2.06 (IBM)

Directory Description Date
pkzip/2.06/docs PKZIP 2.06 Documentation 01‑24‑1994
pkzip/2.06/ibm PKZIP 2.06 (IBM Licensed) 01‑24‑1994

Note

The IBM Licensed PKZIP 2.06 release is equivalent to the Registered PKZIP 2.04g, except it does not contain the encryption features of 2.04g (so it could be exported and distributed to international IBM employees). There are no other differences known (at this time), so you might want to stick with the 2.04g release (certainly if you might ever want to create encrypted ZIP archives).

PKZIP 2.50

The last DOS PKZIP 2.50 release available in original binary form, as well as properly unpacked, decrypted, and PSP patched unpacked executables.

Directory Description Date
pkzip/2.50/docs PKZIP 2.50 Documentation 03‑01‑1999
pkzip/2.50/shareware PKZIP 2.50 Shareware 03‑01‑1999
pkzip/2.50/registered PKZIP 2.50 Registered 03‑01‑1999

Warning

This is the newest (and last) DOS PKZIP release, 2.50, but unfortunately it is NOT recommended for most users. It has known bugs (and subtle issues) when used on vintage machines that have caused much user frustration. You really should be using the classic 2.04g (or 2.06) releases unless you have a very specific reason not to.

PKZIP 1.1x

The last DOS PKZIP 1.x (1.10/1.10a/1.11) release is also available.

Directory Description Date
pkzip/1.10/docs PKZIP 1.10 Documentation 03‑15‑1990
pkzip/1.10/bin PKZIP 1.10 Executables 03‑15‑1990
pkzip/1.10a/bin PKZIP 1.10a Patched Executable 03‑15‑1990
pkzip/1.11/ibm PKZIP 1.11 (IBM Licensed) 11‑23‑1990
pkzip/1.10/findav PHALCON/SKISM FindAV 1.5 07‑27‑1992

Warning

PKZIP 1.10 is even more thoroughly obsolete than DOS PKZIP 2.x. It has known bugs and is included only for the purposes of historical preservation and researching the PKAV 1.x format.

Note

The IBM Licensed PKZIP 1.11 release is equivalent to a Registered PKZIP 1.10, except it does not contain the encryption features of 2.04g (so it could be exported and distributed to international IBM employees), and it contains a fix for the well-known implode compression bug affecting PKZIP 1.10. There are no other differences known (at this time), so you might want to use the patched 1.10a release, which simply backports that fix from 1.11, and retains the 1.10 encryption capability.

PKZIP utilities

The for first time, updated versions of my classic PKZIP utilities are being made available and distributed under the open source MIT license.

Authenticity Verification

After the Authenticity Verification (PKAV) feature of the old PKZIP 1.x was trivially compromised (see 40Hex, Number 8, Volume 2, Issue 4, File 3, a completely new PKAV system was introduced for PKZIP 2.x.

The new PKAV system was also quickly compromised, with PKAV 2 keygens appearing in mid‑1993. PKAV 2 began to be phased out of PKZIP in version 4.0 (which introduced modern cryptography), and support was removed in PKZIP 7.0.

PKAV today is cryptographically useless, but supporting it is important for historical preservation and authenticity, and it unlocks the encrypted AVEXTRA data present in many original PKZIP archives that would otherwise be completely inaccessible (or only accessible using official PKWARE software).

PKAV is still a fun feature of the classic DOS PKZIP, but no source code or open implementation was ever released showing how it works, until now.

MAKEAV
  • The MAKEAV "PKZIP 2.04g/2.06/2.50 Authenticity Verification Generator" utility is an open source keygen tool that generates the two serial numbers needed to enable PKAV for any given company name.
PUTAV
  • The PUTAV "PKZIP 2.04g/2.06/2.50 Put Authenticity Verification" utility is an open source clone of the PKWARE PUTAV utility distributed with registered PKZIP releases. It embeds the PKAV code directly into (registered) PKZIP.EXE 2.04g/2.06/2.50 executables, enabling the use of the ‑! option.
pkav_verify.py
  • The pkav_verify.py utility is an open source implementation the PKAV 1.x and PKAV 2.x verification algorithms. It can verify PKAV information (and decrypt and dump AVEXTRA data) in both ZIP files and PKSFX self‑extracting executables.
PKAV for Info-ZIP

PKSFX (self-extractor) tools

These utilities help advanced users extract, analyze, and customize the PKSFX decompression stub.

These tools have a long history, starting out as Pascal programs before conversion to Python 3 and gaining some features from pkstrings.py.

zip2exe_unpack.py
  • The zip2exe_unpack.py utility extracts the decompression stubs from (de‑PKLITE'd) Registered or Shareware versions of ZIP2EXE.EXE.
pksfx_text_tool.py
  • The pksfx_text_tool.py utility can de‑obfuscate message blocks in the full (de‑PKLITE'd) PKSFX stub. You can dump these blocks out to disk files for analysis, or de‑obfuscate them in‑place (in the PKSFX binary itself). It also disables the de‑obfuscation engine, so the patched executable can be easily modified with the de‑obfuscated text in place. This tool supports working with stubs that have been reconstructed using pksfx_resource_tool.py.
pksfx_resource_tool.py
  • The pksfx_resource_tool.py utility allows analyzing, dumping, and patching of the obfuscated text resources (herald, usage, license terms, and registration information) in the full (de‑PKLITE'd) PKSFX stub.

Classic DOS PKLITE

PKLITE 1.x/2.x

The following PKLITE versions are archived here, both in their original form including documentation and utilities where available, as well as binaries that have been properly unpacked, decrypted, and PSP patched when necessary. The unpacked versions are useful for further reverse engineering and analysis and also load faster on slow machines (like 8086/8088 systems).

Directory Description Version Date
pklite/1.11p PKLITE Professional 1.11 05‑15‑1991
pklite/1.12p PKLITE Professional 1.12 06‑15‑1991
pklite/1.13p PKLITE Professional 1.13 08‑01‑1991
pklite/1.14 PKLITE Standard 1.14 06‑01‑1992
pklite/1.15p PKLITE Professional 1.15 07‑30‑1992
pklite/1.50 PKLITE Standard 1.50 04‑10‑1995
pklite/1.50f PKLITE (UCF Fake) 1.50 04‑10‑1995
pklite/2.01 PKLITE Standard 2.01 03‑15‑1996

PKLITE notes

Fake PKLite 1.50 (-e enabled)

  • The UCF Fake 1.50 version is a hacked release, very similar to the very widely distributed (but equally fake) so‑called "1.20 Professional" described below.

  • The UCF release does enable the ‑e option, which does change the output just enough to confuse the official PKLITE ‑x decompressor, but it does not actually create a "scrambled" decompression stub or do any of the other things that the real Professional version would do.

  • The fake UCF 1.50 release was not packed with PKLITE as usual, but was instead encrypted and compressed with what seems to be a "warez scene" (TEDSUO II [TED/UCF] PaCKeD) polymorphic executable packer, which was reverse engineered to produce unpacked binaries.

TEDSUO II [TED/UCF] unpacker
  • The included Python‑based unpacker is able to decrypt and unpack this TEDSUO II [TED/UCF] file, without executing any of its code directly. It is currently specific to this file, but if other files are found that use the same packer, it would possible to create a generic version of the unpacking tool.

Fake PKLITE Professional 1.20

  • After examining hundreds of PKLITE "1.20 Professional" versions, every single one was the same (fake) hack of PKLITE 1.12 Professional. You can use Jason Summers' pkla.py utility to easily identify fake PKLITE 1.20 Professional versions by their ‑e output.

  • I will not be distributing the fake "1.20 Professional" releases here (because it is not just misleading but useless, as it is essentially identical to the legitimate PKLITE 1.12 Professional release). It is most likely the real PKLITE "1.20 Professional" was an internal PKWARE tool and was never made available as a public release.

Other PKLITE versions

  • I am currently not interested in collecting, analyzing, or unpacking and patching PKLITE releases older than 1.11 (unless it's something very special). I am actively seeking legitimate releases of PKLITE 1.50 Professional and PKLITE 2.01 Professional. If you have a copy, please open a GitHub Issue.

PKLITE utilities

For the first time, updated versions of my classic PKLITE utilities are being released under the open source MIT license.

Tip

I highly recommend Jason Summers' deark unpacker for PKLITE decompression, since it reports if a PSP signature is present when decompressing PKLITE packed executables.

PKPSPFIX

  • The PKPSPFIX "PKLITE Executable Postprocessor (add PSP protection code)" is an open source utility used to patch decompressed executables (previously compressed with PKLITE) that look for a PSP signature to detect unpacking or other tampering. Because programs can check for the PSP signature in multiple places using obfuscated code, manual patching can be tedious. PKPSPFIX automatically inserts code into the unpacked executable to set the PSP signature, so no other modifications to the program are needed for it to run correctly.

PKLAXFIX

  • The PKLAXFIX "PKLITE Executable Postprocessor (AX restoration fix)" utility fixes a bug present in the generated compressed executables of all versions of PKLITE before 1.50, where the AX register was not properly restored after decompression. Some DOS programs depend on the correct AX register status to work correctly. The current PKLAXFIX tool has been updated to support fixing "scrambled" and ‑e (extra compression) executables.

Latest known PKLITE versions

License

  • All original programs and source code in this repository are distributed under the terms of the MIT License.
  • All programs by other authors are included strictly for the convenience of historical researchers. We make no copyright claims on them and they remain the property of their respective owners.

Availability

DOS binaries

Repository mirrors

External links

About

PKZIP/PKUNZIP/PKSFX/PKLITE utilities

Topics

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Used by

Contributors

Languages