티스토리 뷰

Reversing tools/검사도구

Stud PE V2.4.0.1 released

Reverser - J.M.C - 2008. 4. 9. 08:28
반응형
사용자 삽입 이미지



What's new in latest release:

2.4.0.1 - 02 apr 2008
-fixed a bug with imported functions name lenght;
-added external signature verifier; writed a note about signatures;
-fixed RVA2RAW for UPACK which has EP inside PE HEADER; now imports are shown fine;
-added basic disassembler from hexeditor right click menu;
-fixed showing which export is in fact a forwarder to other dll; like HeapAlloc in kernel.dll;
-added process memory dumper/viewer; right click on the process you want to inspect; you can
use dissasambler (from right click menu inside the hexeditor) to see how the code looks at
certain VA; the difference from other (dumpers LordPE, ProcDump, PETools) is that it can dump/view code blocks protected with PAGE_GUARD or NOACCESS flags.

2.2.0.5 - 19 mar 2006
-Open Folder option in Procs list;
-fixed dos header word array - 10x TQN;
-fixed showing wrong signature searching time on PEs with EP 0 - 10x marciano;
-removed a validity check..some packed with asprot files didn't show any res dir;
-it now shows the forwarder exports;
-TLS table editor/viewer;
-new option in hexeditor :select up to 4 bytes the from menu -> GoToRAW GoToRVA GoToVA;
-option to view what is the virtual address of slected byte in hexeditor;
-"Mark Sel"ection inside hexeditor;
-"History" of recent Blocks of data viewed inside hexeditor;
-it will see imports like upack imports (names inside header);


'Reversing tools > 검사도구' 카테고리의 다른 글

dllexp 32-bit + 64-bit  (0) 2008.05.02
AT4RE FastScanner Version 1.0  (0) 2008.04.10
PE Detective V.1.2.1.1  (0) 2008.04.09
ProtectionID  (0) 2008.04.01
exeinfo pe  (0) 2008.04.01
DiE  (0) 2008.04.01
Stud_PE  (0) 2008.04.01
댓글