From Collaborative RCE Tool Library

Jump to: navigation, search

PE Dumper

Tool name: PE Dumper
Rating: 0.0 (0 votes)
Author: FKMA                        
Website: N/A
Current version: 3.03
Last updated: January 14, 2008
Direct D/L link: Locally archived copy
License type: Free
Description: This is new PE Dumper plugin for best user mode debugger OllyDbg.
The PE Dumper is similar to OllyDump by Gigapede but fully rewritten and have
some features:

- You can dump any *.exe and *.dll from debugged process address space.
- You can add/remove sections to/from resulting dump. If you are add new section,
you specify VA and size of memory region to add as section, attributes, File Offset, RAW size and section name. So, now you can add to dump any memory regions created by protectors during debug session.
- Antidump antiprotection and most correct save dump technics: during dumping,
against other dumpers, PE Dumper save only present memory pages (basing on VA & Virtual size). So, if between memory regions present non-allocated space, most other dumpers (and OllyDump too) will not save dump correctly, but PE Dumper will save all correctly.
- Fix raw sizes correct only RAW size of image according to Virtual Sizes.
- Paste header from disk - use header from disk, it's clear.
Related URLs: No related URLs have been submitted for this tool yet


RSS feed Feed containing all updates for this tool.

You are welcome to add your own useful notes about this tool, for others to see!



If you find that any information for the tool above is missing, outdated or incorrect, please edit it!
(please also edit it if you think it fits well in some additional category, since this can also be controlled)


Views
Category Navigation Tree
   Code Coverage Tools  (13)
   Code Ripping Tools  (2)
   Helper Tools  (3)
   Hex Editors  (13)
   Memory Patchers  (7)
   Packers  (20)
   Profiler Tools  (11)
   String Finders  (10)
   Tool Hiding Tools  (7)
   Tracers  (23)
   Needs New Category  (3)