Board logo

標題: [程式相關] Import REConstructor 1.7b FINAL (輸入表重建) [打印本頁]

作者: yoyo007     時間: 2008-3-8 07:01 PM    標題: [程式相關] Import REConstructor 1.7b FINAL (輸入表重建)

[軟體名稱] Import REConstructor 1.7b FINAL (輸入表重建)
[軟體語言] 繁體中文
[檔案大小] 411 KB (421,613 位元組)
[存放空間] HTTP
[軟體簡介] 免安裝

  Quote:


更新;ImpREC 用於修復可執行檔案 dump 後的輸入表 (如果有需要),配合 OllyDBG & PE Tools 或 LordPE 完成手動脫殼作業,使用方法請參考:http://www.centurys.net/viewthread.php?tid=236098 帖內說明。

註:中文化修飾了一些翻譯;Classic 版本我沒加入。

以下引自 TUTS4YOU:

  Quote:
This tool is designed to rebuild imports for protected/packed Win32 executables. It reconstructs a new Image Import Descriptor (IID), Import Array Table (IAT) and all ASCII module and function names. It can also inject into your output executable, a loader which is able to fill the IAT with real pointers to API or a ripped code from the protector/packer (very useful against emulated API in a thunk).

Sorry but this tool is not designed for newbies, you should be familiar a bit with manual unpacking first (some tutorials are easy to find on internet).

Features:

- Imports
- An original tree view
- 2 different methods to find original imports (by IAT and/or API calls)
- A *FULL* complete rebuilder (including a new fresh IAT)

- Loader
- An analyzer and ripper of redirected API code
- An injected loader code to support mix of imports + ripped code in a thunk
- A heuristic relocator

- Tracers
- 3 default tracers (disasm, hook & ring3) to find APIs in redirected code
- A plugin interface to develop your own tracers

- Misc
- Support ALL 32/64bits Windows (9x, ME, NT, 2k, XP and Vista32/64)
- An export renormalizer for Win9x/ME (ala Icedump)
- A built-in coloured disasm/hex-viewer to analyze the redirected code
- A built-in dumper
- Support almost all known antidump tricks

以下版本歷程引自 [History.txt]:

  Quote:
v1.7b FINAL (PUBLIC VERSION)
----------------------------

- Misc
- Fixed invalid API bug in user32.dll on Windows 98 (jstorme)
- Modified code to improve support for discardable/unreadable sections (jstorme)
- Fixed ImageBase problem with DLL's when "Use PE Header from Disk" is checked (jstorme)
- Added an "ImpREC Classic" looking version




檔案下載:


MD5:

CODE:  [Copy to clipboard]
0B5F6F7EE917C61F64C996B8DB10EDAF


請按 [Copy to clipboard] 複製解壓碼:

CODE:  [Copy to clipboard]

PS. 請注意:

如軟體需特殊文件,而您只下不回的話,那不好意思,即使您 PM 向我詢問,我也會學您當個潛水者,不予回應,請別怪我,這本是禮尚往來,大家互相,所以,敬請各位大大保持論壇的良好風氣,養成有下有回的網路禮儀,謝謝您的配合 !!

作者: xp20060726     時間: 2008-3-8 08:53 PM    標題: 感謝您提供的分享!

上一版版大說"做爽的",好快又更新1.7b了!!
中文化的好工具,下載收藏試試看更新了些....

感謝您的分享!!!
作者: osk     時間: 2008-3-9 12:16 AM
好工具..
下載更新..
感謝 版兄 分享...辛苦了  ^^
作者: khiav     時間: 2008-3-9 10:33 AM
雖然本身沒用到,但還是下載更新....
作者: 2Heaven     時間: 2008-3-9 11:37 AM
南無阿彌陀佛! 施主有心了.
真是功德圓滿.....
善哉!
作者: e722146     時間: 2008-3-11 12:02 AM
很實用的輸入表重建程式說!
一套超正點的軟件喔!
感激如此熱心公益喔!
作者: yoyo007     時間: 2008-3-11 07:22 PM


  Quote:
Originally posted by 2Heaven at 2008-3-9 11:37:
南無阿彌陀佛! 施主有心了.
真是功德圓滿.....
善哉!

能力越大,責任也越大;Heaven 兄還是還俗吧!
作者: 七彩琉璃雨     時間: 2008-3-13 12:32 PM
好用的工具
看來又開始動起來了
下載收藏新版~~




歡迎光臨 網際論壇 (http://centurys.net/) Powered by Discuz! 2.5