用Import REConstructor v1.2 beta2修复输入表 --- 之HiClock Pro v2.2 及S-Spline 2.04

从看雪论坛转载此文
【标题:用Import REConstructor v1.2 beta2修复输入表        --- 之HiClock Pro v2.2 及S-Spline 2.04】

作者:BestFont  

--------------------------------------------------------------------------------
【下载处】
1)Import REConstructor v1.2 beta2
 http://www.digitalrice.com/kaparo/files/utilities/imprec.zip (取自protoools)

以下两个程序皆用Asprotect1.2以后的版本加壳
2)HiClock Pro version 2.2 build 126 - released on April 9, 2001
 http://www.downme.com/download/6815hiclockpro.zip
 http://www.kgsoft.com/  (官方网址)

3)S-Spline 2.04
 http://202.108.252.24/stcsr/rj/txtx/S-Spline%202.04.zip   (康乐园)
 http://www.shortcut.nl/S-Spline/Shortcut_S-SplineDemo.zip (官方下载)

--------------------------------------------------------------------------------
【前言】
     本文只简述输入表的修复,没涉及软件的破解。
     主角是ImpREC1.2 beta2, 目标软件是 HiClockPro v2.2 及 S-Spline2.04 。
     其中, HiClockPro 2.2 可一次性修复完成,S-Spline 2.04 还需要手工修复/填补。
     本文在win98se下完成,当然也适合在windows2k下做参考

【工具】 1) ImpREC1.2beta2(必须是beta2 或其最新版本)
       2) SoftIce4.05build334 , icedump6.022     (《=必备!)
       3) PE-Editor1.7
       4) BW2000 v0.2 (for win9x only)

     工具简述:ImpREC的说明文件指出,使用ImpREC时系统中最好已加载icedump。
           这样建立的输入表比较少跨平台的问题。而运行icedump前,当然得先加
      &nbs
Author MackT<br><br>Author website http://www.tuts4you.com/forum/index.php?showtopic=6410<br>Description This tool is designed to rebuild imports for protected/packed Win32 executables. It reconstructs a new Image Import Descriptor (IID), Import Array Table (IAT) and all ASCII module and function names. It can also inject into your output executable, a loader which is able to fill the IAT with real pointers to API or a ripped code from the protector/packer (very useful against emulated API in a thunk).<br><br>Sorry but this tool is not designed for newbies, you should be familiar a bit with manual unpacking first (some tutorials are easy to find on internet).<br><br>Features:<br><br>- Imports<br>- An original tree view<br>- 2 different methods to find original imports (by IAT and/or API calls)<br>- A *FULL* complete rebuilder (including a new fresh IAT)<br><br>- Loader<br>- An analyzer and ripper of redirected API code<br>- An injected loader code to support mix of imports + ripped code in a thunk<br>- A heuristic relocator<br><br>- Tracers<br>- 3 default tracers (disasm, hook & ring3) to find APIs in redirected code<br>- A plugin interface to develop your own tracers<br><br>- Misc<br>- Support ALL 32/64bits Windows (9x, ME, NT, 2k, XP and Vista32/64)<br>- An export renormalizer for Win9x/ME (ala Icedump)<br>- A built-in coloured disasm/hex-viewer to analyze the redirected code<br>- A built-in dumper<br>- Support almost all known antidump tricks<br><br>Filesize 395.89 kb<br>Date Friday 22 February 2008 - 03:37:58
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值