侦壳工具-pe-scanv3.31修正汉化绿色版
release history - 3.31 :: pfft. fixed always-on-top/minimise-to-tray registry entries. :: pfft. fixed bogus "virus infection" in pe-scan.exe. thanks to everyone@exetools. - 3.30 :: added unpackers for petite (all versions), wwpack (all versions), exe32pack (all versions), def 1.0, ep 0.1 & 0.2, exe-bundle 1.31, ezip 1.0, neolite 2.00, pcpec alpha preview, pc-shrink 0.29b/0.45b/0.70b/0.71b, pe-diminisher 0.1, pe-mangle 1.0, pencrypt 1.0, pe-nightmare 1.3, pe-pack 0.99 & 1.0, pklite 1.1 [11], shrinker 3.4, spec b2 & b3, stone's pe-encryptor 1.0 & 1.13, winkript 1.0, vg-shrink 0.14 :: added oep tracing for upx, wwpack, petite.. and some others i can't remember. ;p :: totally reworked the aspack unpacking routines; should be more compatible with any "mutated" loaders. thanks to everyone who tested their files for me. =) :: added TLS rebuilding for unpacked files. :: added an options dialog, also minimise-to-system-tray and always-on-top. :: added some signatures - armadillo, fsg, upx, pebundle.. etc.. :: finally got around to writing a .hlp file. :: changed the peHeader offset-value to a dword. =D :: fixed bug with drag'n'drop.. thanks qwerton. :: updated shrinker 3.4, ep 1.0, petite 1.3 and aspack 2.1 signatures for more compatibility. :: fixed bug with pep rva calculation to handle a pep located _before_ the first section. :: fixed minor bugs with ep, def and nfo website information. fucking string searches. heh. =| - 3.13 :: finally fixed the win2k shell bug. thanks Athlon for your help. =) as it turns out, WinNT had the same problem.. - :: known bug; the shellExtention still doesn't work on win2k. i'm out of ideas.. but i'll be able to diagnose the problem as soon as i have win2k installed. - 3.12 :: implemented generic pe-compact unpacker for all versions. :: fixed major bug with the pecompact unpacker; it erased bytes at the rva where the signature bytes _used_ to be. 8/ :: added support for .sys and .cpl pe's. :: added dragNDrop support (thanks snaker) :: remade the shellextention routines; should fix the win2k problem. - :: known bug; files packed with aspack 1.08.04 and above will lose non-packed resources (icon, version etc.); these resources are wiped during packing and there's no way of knowing where they were allocated with the resource table.. hence no way of copying a resource to/setting the original RVA. :: known bug; the shell extention might be a bit temperamental under win2k.. - 3.03 :: hehe.. swapped the shellExtention and idSecLabel checkboxes around.. *cough*. ;p - 3.02 :: added routine to rebuild the resource table in unpacked aspack files :: fixed small bug in the dumping routine when getting the imageSize. - 3.01 :: added unpacking routines for pe-compact 0.90, 0.92 :: added option to block or allow the loader's IAT construction. - 3.00 :: added unpacking routines for aspack. :: implemented the advanced scanner.. it's completely fucked =D :: added some obscure encryptor/packer signatures. :: added a second algo for asprotect 1.2 :: looked at the unorganised way the classes in my source interact.. and said "pfft." - < 3.00 :: i can't remember. ezip 1.0, neolite 2.00, pcpec alpha preview, pc-shrink 0.29b/0.45b/0.70b/0.71b, pe-diminisher 0.1, pe-mangle 1.0, pencrypt 1.0, pe-nightmare 1.3, pe-pack 0.99 & 1.0, pklite 1.1 [11], shrinker 3.4, spec b2 & b3, stone's pe-encryptor 1.0 & 1.13, winkript 1.0, vg-shrink 0.14 :: added oep tracing for upx, wwpack, petite.. and some others i can't remember. ;p :: totally reworked the aspack unpacking routines; should be more compatible with any "mutated" loaders. thanks to everyone who tested their files for me. =) :: added TLS rebuilding for unpacked files. :: added an options dialog, also minimise-to-system-tray and always-on-top. :: added some signatures - armadillo, fsg, upx, pebundle.. etc.. :: finally got around to writing a .hlp file. :: changed the peHeader offset-value to a dword. =D :: fixed bug with drag'n'drop.. thanks qwerton. :: updated shrinker 3.4, ep 1.0, petite 1.3 and aspack 2.1 signatures for more compatibility. :: fixed bug with pep rva calculation to handle a pep located _before_ the first section. :: fixed minor bugs with ep, def and nfo website information. fucking string searches. heh. =| - 3.13 :: finally fixed the win2k shell bug. thanks Athlon for your help. =) as it turns out, WinNT had the same problem.. - :: known bug; the shellExtention still doesn't work on win2k. i'm out of ideas.. but i'll be able to diagnose the problem as soon as i have win2k installed. - 3.12 :: implemented generic pe-compact unpacker for all versions. :: fixed major bug with the pecompact unpacker; it erased bytes at the rva where the signature bytes _used_ to be. 8/ :: added support for .sys and .cpl pe's. :: added dragNDrop support (thanks snaker) :: remade the shellextention routines; should fix the win2k problem. - :: known bug; files packed with aspack 1.08.04 and above will lose non-packed resources (icon, version etc.); these resources are wiped during packing and there's no way of knowing where they were allocated with the resource table.. hence no way of copying a resource to/setting the original RVA. :: known bug; the shell extention might be a bit temperamental under win2k.. - 3.03 :: hehe.. swapped the shellExtention and idSecLabel checkboxes around.. *cough*. ;p - 3.02 :: added routine to rebuild the resource table in unpacked aspack files :: fixed small bug in the dumping routine when getting the imageSize. - 3.01 :: added unpacking routines for pe-compact 0.90, 0.92 :: added option to block or allow the loader's IAT construction. - 3.00 :: added unpacking routines for aspack. :: implemented the advanced scanner.. it's completely fucked =D :: added some obscure encryptor/packer signatures. :: added a second algo for asprotect 1.2 :: looked at the unorganised way the classes in my source interact.. and said "pfft." - < 3.00 :: i can't remember.
用户评论
可以用,不错
这个工具还可以,但是很多识别不了,可能需要更新吧
能用,是个好工具
可以用,还不太会用,经验不多
很多都识别不了。
不错,可以使用,用过一次了
能用,有些知识待了解
可以使用,在多看看其他方面。
能用,不过有的解不了。