0020.jpg

 

This tool is designed to rebuild imports for protected/packed Win32 executables. It reconstructs a new Image Import Descriptor (IID), Import Array Table (IAT) and all ASCII module and function names. It can also inject into your output executable, a loader which is able to fill the IAT with real pointers to API or a ripped code from the protector/packer (very useful against emulated API in a thunk).

Sorry but this tool is not designed for newbies, you should be familiar a bit with manual unpacking first (some tutorials are easy to find on internet).

Features:

- Imports
- An original tree view
- 2 different methods to find original imports (by IAT and/or API calls)
- A *FULL* complete rebuilder (including a new fresh IAT)

- Loader
- An analyzer and ripper of redirected API code
- An injected loader code to support mix of imports + ripped code in a thunk
- A heuristic relocator

- Tracers
- 3 default tracers (disasm, hook & ring3) to find APIs in redirected code
- A plugin interface to develop your own tracers

- Misc
- Support ALL 32/64bits Windows (9x, ME, NT, 2k, XP and Vista32/64)
- An export renormalizer for Win9x/ME (ala Icedump)
- A built-in coloured disasm/hex-viewer to analyze the redirected code
- A built-in dumper
- Support almost all known antidump tricks

 

 

관련링크

http://www.tuts4you.com/download.php?view.415

 

 




List of Articles
번호 제목
42 [1장 리버스엔지니어링에 대하여] 개정된 국내 역분석 관련 법률
41 [5장 안티 디버깅] Anti Debugging Source file
» [3장 리버스엔지니어링 관련 툴] Import REConstructor 1.7c FINAL imagefile
39 [3장 리버스엔지니어링 관련 툴] UPX v3.04 imagefile
38 [3장 리버스엔지니어링 관련 툴] Cain & Abel v4.9.35 imagefile
37 [3장 리버스엔지니어링 관련 툴] DAMN Hash Calculator v1.5.1 imagefile
36 [3장 리버스엔지니어링 관련 툴] MarchHaRe's Crackme 16 imagefile
35 [3장 리버스엔지니어링 관련 툴] Dumpbin
34 [3장 리버스엔지니어링 관련 툴] Dependency Walker file
33 [3장 리버스엔지니어링 관련 툴] app1win crackme file
32 [3장 리버스엔지니어링 관련 툴] Sysinternals - Strings file
31 [3장 리버스엔지니어링 관련 툴] Resource Hacker file
30 [3장 리버스엔지니어링 관련 툴] PE View file
29 [3장 리버스엔지니어링 관련 툴] Cheat Engine
28 [3장 리버스엔지니어링 관련 툴] Delphi Decompiler - DeDe file
27 [3장 리버스엔지니어링 관련 툴] Java Decompiler - JAD file
26 [3장 리버스엔지니어링 관련 툴] T Search file
25 [3장 리버스엔지니어링 관련 툴] sothink SWF Decompiler
24 [3장 리버스엔지니어링 관련 툴] Sysinternals - Procexp file
23 [3장 리버스엔지니어링 관련 툴] Sysinternals - Tcp view file

XE Login

OpenID Login