Tags: disassembly ollydbg PE
PE file structure (4)
Reference
Book: encryption and decryption
Video: Little Turtle decryption series video
Output table
Generally, the output table exists in the DLL. The output table provides the name of the function in the file and the address of these functions. The PE Loader modifies the IAT through the output table.
Datadi
Longko 1gu Disk
Enable the USB flash drive.
Install WINXP
1. USB flash disk formatting
Want to start the installation system with a USB flash drive
Usb zip format is recommended
Best compatibility
Usboot is used.
A large number of USB flash drives, but not 1 gb usb flash drives.
ZIP Format
I used Fla.
Shboot uses the built-in dossystem
File
2 motherboard startup settings
For USB boot options
Choose USB zip boot for the motherboard.
You can use the format
The converted USB flash drive enters do
Title: [original] A program simulating the behavior of the PE Loader
Author: linxer
Time: 2006-06-10, 00: 50: 49
Chain: http://bbs.pediy.com/showthread.php? T = 27134
[Title] A program simulating the behavior of the PE Loader[Statement] The level is limited. If not, please enlighten me!
The following procedure assumes that the PE file is legal, so fault toleranc
Clipeviewer is a WinForm applet written by Lao Liu, which can be used to view various structures in a managed PE file. Currently there are many programs that can view PE information, support. NET also has. However, the biggest difference between clipeviewer and them is that this small program is more concerned about the authenticity of the content of a PE file, e
When we use PE, there is a software in the PE system is not, but I just want to use, do I have to add myself to the PE system? There is a PE system under a software, I want to use, do I have to enter the PE system to use it?
Actually, teach you a random add the method of
I made a PE ISO want to test it? How to test? Then use the virtual machine software to test it.
Step 1th, install the virtual machine software VMware Workstation and create a new virtual machine, and then install the Windows XP Professional system in the virtual machine.
Step 2nd, return to the main window of the program and click the Edit virtual machine settings button on the Windows XP Professional tab.
Step 3rd, open the Virtual Machine Setting
In the blue screen of XP boot, I found a solution with the prompt "0xC0000218 unknown hard error" (using a CD with Windows PE). I also met this for the first time. My classmates called me and said that the blue screen was started on the computer, I didn't think much at the time, so I called him F8 -- the last time I correctly configured it, I told him that I couldn't do it. I thought he was wrong and annoyed. Later I found out --! I have never met eit
Boot Press F2 can enter the BIOS settings, if your system has been deleted, the boot will automatically enter the inspection program?After entering the BIOS, you can see that if you change to Legancy, the default first boot mode is internal HDD?If I reload the system, and the external mobile hard disk is the MBR boot mode, and to boot from this hard disk into the PE, to modify the boot mode of the BIOS is legency, after the change to the upper right c
PE-SHiELD V0.25 shelling -- Notepad of Win98: Http://protools.anticrack.de/files/packers/peshield.zipSoftware size: 32 KB
[Software Overview]: PE-SHiELD is a program, which encrypts 32-bit Windows EXE files, leaving them still executable. the previous version was over a year in the wild and there is still no unpacker for it.
[Author's statement]: Crack beginners are only interested and have no other purpose
Prerequisite: Prepare the U disk, do a good start disk (Chinese cabbage, u start, old peaches, etc.), win7ghost system files, computer.One: BIOS, SATA settings in Advanced settings: Ahci\ide: set to AHCI; 注:AHCI需要高级内核,如果进入PE,不能读取到SSD,则设置成IDE模式,并开启Legacy;Second: Enter Pe,diskgenius formatted disk; format after partition; 注:分区要至少分成两个区,一般情况,是分为一个主分区,一个扩展分区,扩展分区分成一个或多个盘符。Three: Modify the disk mode: Selec
I encountered some problems when installing window7, but after reading this article, I installed it successfully.
The installation methods of Windows 7 on the Internet are complicated, especially for cainiao. A simple installation method is provided:
1. decompress the ISO image of Windows 7 (or use the virtual optical drive software to extract it) to any folder on any non-system disk, for example, D: \ win7 \
2. Enter the PE and format the drive C a
Several Concepts in LVM:
PV (physical volume): physical volume is at the bottom of the logical volume management system and can be partitioned on the entire physical hard disk or the actual physical hard disk.
VG (volume group): A volume is created on a physical volume. A volume group must contain at least one physical volume. After a volume group is created, it can be dynamically added to the volume group, A logical volume Management System project can contain multiple volume groups.
LV (log
Question: HowUse winPE system installationISO file for win7/Win8?
Method: Use the ghost of PE to restore the gho file. But there are no gho files and only ISO files. What should I do?
Step 1. Copy the ISO file
In PE, use the ISO tool to copy the ISO file content of win7/Win8, for example, in D: \ win 8
Step 2. confirm that the system disk format is NTFS
Ensure that the system disk to be installed,
Customize your own personalized winpe tutorial (modify external PE
Program )
Currently, some external programs in many PES are based on the practicality of the disc. They are not what we need most, or the versions are relatively old, how can we add some of our favorite software, such as system maintenance, QQ Software Update, and testing? Or, how can we modify winpe's image file winpe. Is? Winpe. Is _ is actually a compressed package in th
First, we must have a Windows PE boot disc with anti-virus software. Here we recommend the old peach.You can download winpe from thunder and burn it into a winpe boot disc.Start the computer and set the first boot device of advanced BIOS features in BIOSCD-ROM boot (while checking whether there is a blocked optical drive in standard CMOS features ),Put the windows PE boot disc into the optical drive and ent
How to install GHOSTXP on a hard drive PEPreparations:
Go to the Internet to download a tool named "old peach WinPE" to the hard disk, or download a "old peach WinPE V5.3 pony enhanced version" below and decompress it with WINRAR, in the "WINPE installation" directory, the file is the "old peach WinPE" tool. the GHO image file is about 600 or 700 mb. copy and paste it to another non-C disk.
Click "Install. EXE" in "WINPE installation" to go to the following steps. Be careful when performing this
The production of successful launch U disk, PE system in the start-up will automatically detect U disk Gho directory under the GHO or ISO image file name, and prompts for automatic installation.
1. Into the PE desktop, automatically search the U disk is known as Gho folder, if the system will continue to detect the Gho folder Gho and ISO image files, and then the program pop-up prompts to select the
Required Software: 1. Windows 8 Pe;2.wimtool;3.reshacker;4.ultraiso.
Operations Tutorial (running the software as an administrator!)
1. Use Wimtool "mount image"--boot.wim file (under the PE Mirror boot directory)
2. Under "Mount Directory", make changes.
1 Modify "Property information": Use Reshacker to modify SYSTEMCPL.DLL.MUI (Mount directory WINDOWSSYSTEM32ZH-CN)
2 Modify th
copy the data back after the production is complete.
Ready to do, now start point: A key to make PE boot disk. The software will once again remind everyone to do the backup. Here we point: OK.
Production process will be a progress bar prompts, we quietly wait a few minutes, such as software production completed.
After the completion of the software will be prompted to let everyone whether the test, the launch of
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.