飘云阁

 找回密码
 加入我们

QQ登录

只需一步,快速开始

查看: 4053|回复: 5

[PEtools] Import REConstructor 1.7 FINAL

[复制链接]
  • TA的每日心情
    开心
    2019-3-13 23:42
  • 签到天数: 7 天

    [LV.3]偶尔看看II

    发表于 2008-2-22 22:43:17 | 显示全部楼层 |阅读模式
    Import REConstructor 1.7 FINAL
    This tool is designed to rebuild imports for protected/packed Win32 executables. It reconstructs a new Image Import Descriptor (IID), Import Array Table (IAT) and all ASCII module and function names. It can also inject into your output executable, a loader which is able to fill the IAT with real pointers to API or a ripped code from the protector/packer (very useful against emulated API in a thunk).

    Sorry but this tool is not designed for newbies, you should be familiar a bit with manual unpacking first (some tutorials are easy to find on internet).


    [EXT]


    Features:

    QUOTE
    - Imports
    - An original tree view
    - 2 different methods to find original imports (by IAT and/or API calls)
    - A *FULL* complete rebuilder (including a new fresh IAT)

    - Loader
    - An analyzer and ripper of redirected API code
    - An injected loader code to support mix of imports + ripped code in a thunk
    - A heuristic relocator

    - Tracers
    - 3 default tracers (disasm, hook & ring3) to find APIs in redirected code
    - A plugin inte**ce to develop your own tracers

    - Misc
    - Support ALL 32/64bits Windows (9x, ME, NT, 2k, XP and Vista32/64)
    - An export renormalizer for Win9x/ME (ala Icedump)
    - A built-in coloured disasm/hex-viewer to analyze the redirected code
    - A built-in dumper
    - Support almost all known antidump tricks


    Changes in Version 1.7:

    QUOTE
    - Fixed RestoreLastError API set to SetLastError for WinXP/Vista compatibility (MaRKuS_TH-DJM)
    - user32.dll is always read from the system, prevents a crash from corrupted PE of user32.dll (MaRKuS_TH-DJM)
    - Latest version of psapi.dll (6.0.6000.16386) included
    - Fixed Vista64 crash bug (jstorme)
    - GUI modified and improved (based upon Fly's modification)
    - Updated/corrected plugins and deleted dups

    本帖子中包含更多资源

    您需要 登录 才可以下载或查看,没有账号?加入我们

    x
    PYG19周年生日快乐!
  • TA的每日心情
    开心
    2019-3-15 21:05
  • 签到天数: 5 天

    [LV.2]偶尔看看I

    发表于 2008-2-22 22:46:53 | 显示全部楼层
    感谢转帖优秀工具/:good
    PYG19周年生日快乐!
  • TA的每日心情
    开心
    14 小时前
  • 签到天数: 2079 天

    [LV.Master]伴坛终老

    发表于 2008-2-22 22:50:20 | 显示全部楼层
    不错的工具,收下了
    PYG19周年生日快乐!

    该用户从未签到

    发表于 2008-5-22 23:37:44 | 显示全部楼层
    谢谢分享/:good
    PYG19周年生日快乐!

    该用户从未签到

    发表于 2008-5-27 13:23:20 | 显示全部楼层
    英文版??????
    PYG19周年生日快乐!

    该用户从未签到

    发表于 2010-5-8 21:22:41 | 显示全部楼层
    支持下  呵呵
    PYG19周年生日快乐!
    您需要登录后才可以回帖 登录 | 加入我们

    本版积分规则

    快速回复 返回顶部 返回列表