风吹屁屁凉 发表于 2023-12-26 15:30

Manual Imports v3 by CodeCracker

ManualImports



This programs comes with two ways of getting imports:
1. Old mode:
by selecting "Process", you can optionally set OEP RVA, then press "Autodetect"
for getting Imports VA, Imports Size
and finally pressing "Get imports" for getting imports thunks.
2. New mode
by selecting "Process" and pressing Attach button.
Only valid imports will be showed in this mode.
"Sort thunks after:" "Sections" or "Dlls" refers to only this option
"Sections" option will set as name and as parent the section from which
an import thunk belongs,
"Dlls" option will set as name and as parent the dll name

"Don't scan first (code) section" also refers to this "New mode" only.

Import - Import ImpRec/Scylla saved Tree.
"Append to PE" is the final step - fixing the dump.

In Version 3:
- Added "Imports from file" to successfully resolve imports from file not from memory of module
- Added "Resolve forwarded" to resolve forwarded imports and Api Set;
- Fixed some bugs

wondering if there is any interest for such tool, please write bug reports/suggestions.

朱朱你堕落了 发表于 2023-12-26 15:41

本帖最后由 朱朱你堕落了 于 2023-12-26 15:49 编辑

百度翻译:
该计划有两种进口方式:
1.旧模式:
通过选择“进程”,您可以选择设置OEP RVA,然后按“自动检测”
用于获取进口VA,进口大小
最后按下“获取进口”按钮获取进口暴徒。
2.新模式
选择“处理”并按下附加按钮。
只有有效的导入才会在此模式中显示。
排序后的thunks:“Sections”或“Dlls”仅引用此选项
“Sections”选项将设置为节的名称和父节
导入thunk属于,
“Dlls”选项将设置为名称,并将dll名称设置为父级

“不要先扫描(代码)部分”也仅指此“新模式”。

导入-导入ImpRec/Scilla保存的树。
“附加到PE”是最后一步-修复转储。

在版本3中:
-添加了“从文件导入”以成功解决从文件而非模块内存导入的问题
-添加了“解析转发”以解析转发的导入和Api集;
-修复了一些错误

想知道是否有人对这样的工具感兴趣,请写下错误报告/建议。

whatdos 发表于 2023-12-27 11:04

Assembly_Resigner-CodeCracker

StrongName_Killer-CodeCracker

不知这两个程序与上面的软件是同一个作者

yy710 发表于 2023-12-26 16:05

感谢楼主分享。。。

lyliucn 发表于 2023-12-26 16:52

感谢楼主分享!!!

FruitBaby 发表于 2023-12-26 17:27

全是英语,没看懂,

CQGaxm 发表于 2023-12-26 20:46

感谢分享,很有用

冥界3大法王 发表于 2023-12-27 06:10

I like it.Thank you.

lyliucn 发表于 2023-12-27 11:55

楼上的,这两个也发一下,学习

jiqimaoer 发表于 2023-12-27 13:14

不知道干嘛的,先谢谢了
页: [1] 2
查看完整版本: Manual Imports v3 by CodeCracker