搜索资源列表
PEFile.rar
- 使用C语言分析Windows的PE文件格式源码, 函数封装在pe/pe.h中,PE File.c是一个简单的测试代码 ! ,The use of C language analysis of the PE file format Windows source code, function is packaged in a pe/pe.h in, PE File.c is a simple test code!
PE-Export
- 解析pe文件,分析PE文件加载的dll模块,显示导出表和导入表-Pe file analysis to analyze export tables and import tables PE
PE_EXEVIEW_PEFILE
- The Portable Executable File Format from Top to Bottom原文、译文及源代码 1、The Portable Executable File Format from Top to Bottom 是最早讲解PE格式的文章之一,是了解PE格式入门很好的文章,原文可以在MSDN1998光盘找到中。 2、这篇文章被国内网友多次翻译,有代表性的译文有两个: 看雪软件安全论坛(bbs.pediy.com)中的ah007译为:可移植的
PEViewer
- PE文件查看器,对于研究PE文件,获取软件信息的好工具-PE viewer,use this tool to get PE file informatio。
PE-digital-signature-
- 提取PE文件的数字签名,还可以写入数字签名-PE files extracted digital signature, digital signature can also be written
TLS_CallBack
- 漫谈TLS_CallBack:原理、编程、手工感染及检测.利用TLS_CallBack(线程局部存储回调函数)玩弄调试器以及感染PE文件.-Talk TLS_CallBack: principles, programming, manual infection and detection. Use TLS_CallBack (thread local storage callback function), as well as playing with the debugger PE file
minifilterLimited
- 文件系统 Minifilter驱动,通过限制PE文件的载入和修改达到限制可执行文件启动运行。-Minifilter file system driver, by limiting the PE file limit is reached, load and modify the executable file to start running.
pedump
- Windows PE文件格式分析与PEDUMP的实现-Windows PE File Format Analysis and realization of PEDUMP
pe
- 获取pe文件的函数. 我的QQ:2891-Pe a function of access to documents. My QQ: 2891
pe
- PE文件分析例子-Examples of PE File Analysis
dos_stub
- Windows PE 文件在 DOS 下运行一般会显示:This program cannot be run in DOS mode. 这是PE文件头部的一个"dos stub"程序,这个就是"dos stub"的源码,我们可以修改它,用fasm.exe编译,在vc连接时,加上 /stub:stub.exe-Windows PE files will normally be run under DOS shows: This program cannot be run in DOS mode
ZEROADD
- 为PE文件增加任意名称,任意大小的空白区段。是DELPHI的原代码,自己准备编写壳时的一个练习。-PE file for the increase in arbitrary name, of any size blank section. Is DELPHI original code, its own shell at the time of the preparation of a practice.
SECTIO~1.RAR
- 一个小巧的 PE 文件区段添加工具,用来给可执行程序添加区段。-A small section of the PE file Add tool to add a section to the executable program.
VBMAKEKE
- VB制作的加壳工具只是修改了PE文件头.很轻松的就可以脱掉了.声明本人所上传代码如果没有特别声明都是来自VBGOOD论坛-VB Tools加壳produced only modify the PE file header. Very easily can be off. Statement From my code if there is no special statement from VBGOOD Forum
PEView1.0
- 分析PE文件的基本信息、导入表、导出表、资源和节等信息-Analyser for PE file,basic information, import table, export table, resources and section
VaToOffset
- 将PE文件映射到内存的虚拟地址转成文件偏移-PE file will be mapped to virtual memory addresses into file offset
ImpREC_lite_v11
- winodws PE文件脱壳后用来修复输入表的工具,经过一部分改进,修复了部分bug-winodws PE files after the shell used to repair the instrument input table, after some improvements, some bug fixes
FileCheckSum
- pe文件校验和计算 在写驱动壳或者驱动感染的时候使用-pe file checksum calculation at Writing-driven shell, or when the use of infection-driven
PETool
- PE文件信息查看编辑工具,VC源码。 作者MackT-PE file information editing tools to view, VC source. Author MackT ..
PE
- 学习PE文件格式的一个小测试程序.上传凑分.-PE file format to learn a small test program. From points together.