Xpeviewer 0.05
XPEViewer - PE file viewer/editor for Windows, Linux and MacOS.
Version 0.05
Detect it easy 3.09
Detect it easy 3.08
Detect it easy 3.07
Detect It Easy, or abbreviated “DIE” is a program for determining types of files.
Version 3.07
Nauz file detector 0.09
Nauz File Detector is a portable linker/compiler/packer identifier utility for OSX, Linux and Windows.
Version 0.09
Detect it easy 3.06
Detect It Easy, or abbreviated “DIE” is a program for determining types of files.
Version 3.06
Xopcodecalc 0.05
XOpcodeCalc x86/64 Opcode calculator. The program works on macOS, Linux and Windows.
Version 0.05
Xmachoviewer 0.04
XMachOViewer - MachO file viewer/editor for Windows, Linux and MacOS.
Version 0.04
Xpeviewer 0.04
XPEViewer - PE file viewer/editor for Windows, Linux and MacOS.
Version 0.04
Detect it easy 3.05
Detect It Easy, or abbreviated “DIE” is a program for determining types of files.
Version 3.05
Pdbripper 2.03
PDBRipper is an utility for extract an information from PDB-files.
Version 2.03
Xelfviewer 0.05
XELFViewer - ELF file viewer/editor for Windows, Linux and MacOS.
Version 0.05
Nauz file detector 0.08
Nauz File Detector is a portable linker/compiler/packer identifier utility for OSX, Linux and Windows.
Version 0.08
Xpeviewer 0.03
XPEViewer - PE file viewer/editor for Windows, Linux and MacOS.
Version 0.03
Xntsv 3.01
XNTSV program for detailed viewing of system structures in Windows.
Version 2.01
- Changelog: https://github.com/horsicq/xntsv/blob/master/changelog.txt
- More info: https://github.com/horsicq/xntsv
- Download: https://github.com/horsicq/xntsv/releases
Xapkdetector 0.03
XAPKDetector is Android/APK/DEX detector for Windows, Linux and MacOS.
Version 0.03
Pdbripper 2.02
PDBRipper is an utility for extract an information from PDB-files.
Version 2.02
Detect it easy 3.04
Detect It Easy, or abbreviated “DIE” is a program for determining types of files.
Version 3.04
Xelfviewer 0.04
XELFViewer - ELF file viewer/editor for Windows, Linux and MacOS.
Version 0.04
- Changelog: https://github.com/horsicq/XELFViewer/blob/master/changelog.txt
- More info: https://github.com/horsicq/XELFViewer
- Download: https://github.com/horsicq/XELFViewer/releases
Nauz file detector 0.07
Nauz File Detector is a portable linker/compiler/packer identifier utility for OSX, Linux and Windows.
Version 0.07
- Changelog: https://github.com/horsicq/Nauz-File-Detector/blob/master/changelog.txt
- More info: https://github.com/horsicq/Nauz-File-Detector
- Download: https://github.com/horsicq/Nauz-File-Detector/releases
Xopcodecalc 0.04
XOpcodeCalc x86/64 Opcode calculator. The program works on macOS, Linux and Windows.
Detect it easy 3.03
Detect It Easy, or abbreviated “DIE” is a program for determining types of files.
- Changelog: https://raw.githubusercontent.com/horsicq/Detect-It-Easy/master/changelog.txt
- More info: https://github.com/horsicq/Detect-It-Easy
- Download: https://github.com/horsicq/DIE-engine/releases
Bot for telegram
It scans files using the latest “Detect It Easy” (DiE) and “Nauz File Detector” (NFD) databases.
The address of the bot in Telegram @detectiteasy_bot or simply enter in the search for Telegram “Detect It Easy”
Xmachoviewer 0.02
XMachOViewer - MachO file viewer/editor for Windows, Linux and MacOS.
- Changelog: https://github.com/horsicq/XMachOViewer/blob/master/changelog.txt
- More info: https://github.com/horsicq/XMachOViewer
- Download: https://github.com/horsicq/XMachOViewer/releases
Xntsv 3.00
XNTSV program for detailed viewing of system structures in Windows.
- Changelog: https://github.com/horsicq/xntsv/blob/master/changelog.txt
- More info: https://github.com/horsicq/xntsv
- Download: https://github.com/horsicq/xntsv/releases
Xpeviewer 0.02
XPEViewer - PE file viewer/editor for Windows, Linux and MacOS.
- Changelog: https://github.com/horsicq/XPEViewer/blob/master/changelog.txt
- More info: https://github.com/horsicq/XPEViewer
- Download: https://github.com/horsicq/XPEViewer/releases
Xelfviewer 0.03
XELFViewer - ELF file viewer/editor for Windows, Linux and MacOS.
- Changelog: https://github.com/horsicq/XELFViewer/blob/master/changelog.txt
- More info: https://github.com/horsicq/XELFViewer
- Download: https://github.com/horsicq/XELFViewer/releases
Nauz file detector 0.06
Nauz File Detector is a portable linker/compiler/packer identifier utility for OSX, Linux and Windows.
Version 0.06
- Changelog: https://github.com/horsicq/Nauz-File-Detector/blob/master/changelog.txt
- More info: https://github.com/horsicq/Nauz-File-Detector
- Download: https://github.com/horsicq/Nauz-File-Detector/releases
Pdbripper 2.01
PDBRipper is an utility for extract an information from PDB-files.
Version 2.01
- Changelog: https://github.com/horsicq/PDBRipper/blob/master/changelog.txt
- More info: https://github.com/horsicq/PDBRipper
- Download: https://github.com/horsicq/PDBRipper/releases
Xapkdetector 0.02
XAPKDetector is Android/APK/DEX detector for Windows, Linux and MacOS.
Version 0.02
- Changelog: https://github.com/horsicq/XAPKDetector/blob/master/changelog.txt
- More info: https://github.com/horsicq/XAPKDetector
- Download: https://github.com/horsicq/XAPKDetector/releases
Xopcodecalc 0.03
XOpcodeCalc - X86/X64 Opcode calculator. The program works on OSX, Linux and Windows.
Version 0.03
- Changelog: https://github.com/horsicq/XOpcodeCalc/blob/master/changelog.txt
- More info: https://github.com/horsicq/XOpcodeCalc
- Download: https://github.com/horsicq/XOpcodeCalc/releases
X64dbg Plugin Manager 0.05
x64dbg Plugin Manager
Version 0.05
R6002 floating point support not loaded
Sometimes we can unpack protected executables in Windows but there is a runtime error
Microsoft Visual C++ Runtime Library
Runtime Error!
Program: ***.unp.exe
- floating point support not loaded
There is some info in UPX sources: https://github.com/upx/upx/blob/8d42b12117130b944023335cc2b76072c145db4d/src/p_w32pe.cpp#L200
// This works around a "protection" introduced in MSVCRT80, which
// works like this:
// When the compiler detects that it would link in some code from its
// C runtime library which references some data in a read only
// section then it compiles in a runtime check whether that data is
// still in a read only section by looking at the pe header of the
// file. If this check fails the runtime does "interesting" things
// like not running the floating point initialization code - the result
// is a R6002 runtime error.
// These supposed to be read only addresses are covered by the sections
// UPX0 & UPX1 in the compressed files, so we have to patch the PE header
// in the memory. And the page on which the PE header is stored is read
// only so we must make it rw, fix the flags (i.e. clear
// PEFL_WRITE of osection[x].flags), and make it ro again.
This code raises the exception:
.xvlk:0045A560 __IsNonwritableInCurrentImage proc near ; CODE XREF: __except_handler4+FF p
.xvlk:0045A560 ; __cinit+E p
.xvlk:0045A560 ; __cinit+79 p
.xvlk:0045A560 ; __endthreadex+E p
.xvlk:0045A560 ; _threadstartex(x)+6A p
.xvlk:0045A560 ms_exc = CPPEH_RECORD ptr -18h
.xvlk:0045A560 arg_0 = dword ptr 8
.xvlk:0045A560 push ebp
.xvlk:0045A561 mov ebp, esp
.xvlk:0045A563 push 0FFFFFFFEh
.xvlk:0045A565 push offset stru_4D2228
.xvlk:0045A56A push offset __except_handler4
.xvlk:0045A56F mov eax, large fs:0
.xvlk:0045A575 push eax
.xvlk:0045A576 sub esp, 8
.xvlk:0045A579 push ebx
.xvlk:0045A57A push esi
.xvlk:0045A57B push edi
.xvlk:0045A57C mov eax, dword_4D7A00
.xvlk:0045A581 xor [ebp+ms_exc.registration.ScopeTable], eax
.xvlk:0045A584 xor eax, ebp
.xvlk:0045A586 push eax
.xvlk:0045A587 lea eax, [ebp+ms_exc.registration]
.xvlk:0045A58A mov large fs:0, eax
.xvlk:0045A590 mov [ebp+ms_exc.old_esp], esp
.xvlk:0045A593 mov [ebp+ms_exc.registration.TryLevel], 0
.xvlk:0045A59A push offset __ImageBase
.xvlk:0045A59F call __ValidateImageBase
.xvlk:0045A5A4 add esp, 4
.xvlk:0045A5A7 test eax, eax
.xvlk:0045A5A9 jz short loc_45A600
.xvlk:0045A5AB mov eax, [ebp+arg_0]
.xvlk:0045A5AE sub eax, offset __ImageBase
.xvlk:0045A5B3 push eax
.xvlk:0045A5B4 push offset __ImageBase
.xvlk:0045A5B9 call __FindPESection
.xvlk:0045A5BE add esp, 8
.xvlk:0045A5C1 test eax, eax
.xvlk:0045A5C3 jz short loc_45A600
.xvlk:0045A5C5 mov eax, [eax+24h]
.xvlk:0045A5C8 shr eax, 1Fh
.xvlk:0045A5CB not eax
.xvlk:0045A5CD and eax, 1
I am using the trick in my projects to fix it
// 004947D5 |. 8B40 24 MOV EAX,DWORD PTR DS:[EAX+24]
// 004947D8 |. C1E8 1F SHR EAX,1F
// 004947DB |. F7D0 NOT EAX
// 004947DD |. 83E0 01 AND EAX,00000001
qint64 nNWAddress=findSignature(nImageBase,nImageSize,"8B4024C1E81FF7D083E001");
_messageString(MESSAGE_TYPE_WARNING,tr("NW Address found: 0x%1").arg(nNWAddress,0,16));
// 83 c8
// AND ->OR
Discussions about the exception: https://forum.exetools.com/showthread.php?t=15330
Detect it easy 3.02
Detect It Easy, or abbreviated “DIE” is a program for determining types of files.
- Changelog: https://raw.githubusercontent.com/horsicq/Detect-It-Easy/master/changelog.txt
- More info: https://github.com/horsicq/Detect-It-Easy
- Download: https://github.com/horsicq/DIE-engine/releases
Xmachoviewer 0.01
XMachOViewer - MachO file viewer/editor for Windows, Linux and MacOS.
- Changelog: https://github.com/horsicq/XMachOViewer/blob/master/changelog.txt
- More info: https://github.com/horsicq/XMachOViewer
- Download: https://github.com/horsicq/XMachOViewer/releases
Xelfviewer 0.02
XELFViewer - ELF file viewer/editor for Windows, Linux and MacOS.
- Changelog: https://github.com/horsicq/XELFViewer/blob/master/changelog.txt
- More info: https://github.com/horsicq/XELFViewer
- Download: https://github.com/horsicq/XELFViewer/releases