pe-scan

-

it's a shitty little app that displays basic info about a pe (sections, pep, imports / resources
directories), and a possible encryptor/packer if there is one. just so you don't have to do the
work yourself =D
it's meant as an aid to reverse engineering. (pe packers. pff.)

currently, it recognises the following packers/encryptors;

armadillo 1.60a
armadillo 1.84
armadillo 1.90
armadillo 1.90b1
armadillo 1.90b2
armadillo 1.90b3
armadillo 1.90b4
armadillo 1.91a
armadillo 1.91c
armadillo 2.00
armadillo 2.00b3
armadillo 2.01
armadillo 2.10
armadillo 2.10b2
armadillo 2.20
armadillo 2.20b1
armadillo 2.50
armadillo 2.50b1a
armadillo 2.50b3
armadillo 2.51
armadillo 2.52
armadillo 2.52b2
* as-pack 1.00b
* as-pack 1.01b
* as-pack 1.02b
* as-pack 1.03b
* as-pack 1.05b
* as-pack 2.000
* as-pack 2.001
* as-pack 2.1
as-pack 2.11
as-pack 2.11c/2.11d
* as-pack 2.12
as-protect 1.0
as-protect 1.1
as-protect 1.1c
as-protect 1.2
* bit-arts crunch 1.2
* bit-arts crunch 2.0.0.2
bit-arts crunch 3.0.0.0
bit-arts crunch 4.0.0.0
bjfnt 1.2rc
bjfnt 1.3
code-crypt 0.14b
code-crypt 0.15b
code-crypt 0.16b
codesafe 3.1
dbpe/phantasm 0.07
dbpe/phantasm 0.8
dbpe/phantasm 1.0
dbpe/phantasm 1.5b3
* exe32pack 1.36/1.38
ezip 1.0
fsg 1.0
* neolite 1.0
* neolite 1.01
* neolite 2.00
noodle-crypt 2
pc-guard 3.00d-4.02d
pc-guard 4.05d
* pcpec alpha preview
pc-shrink 0.45b
pc-shrink 0.71b
pe-compact, any version
pe-crypt 1.02
* pe-diminisher 0.1
pencrypt 1.0
pencrypt 2.0
pencrypt 3.0
* pe-ninja 1.0
* pe-pack 0.99
pe-pack 1.0
pe-protect 0.9
pe-shield 0.1d
pe-shield 0.25
pe-shield 0.2b2
petite 1.2
petite 1.3
petite 1.4
petite 2.0
petite 2.1/2.2
pex 0.99
pklite 1.1 [11]
shrinker 3.4
* spec b2
* spec b3
* stone's encryptor 1.13
* telock 0.42
telock 0.51
telock 0.60
telock 0.70
telock 0.71
telock 0.80
telock 0.85f
telock 0.90
telock 0.92a
telock 0.95
telock 0.96
upx, any version
vbowatch 2.1
vg-crypt 0.75b
wwpack 1.00-1.20b2
yoda's encryptor 1.2

* oep resolved

-

future releases should include support for vbox, softsentry, upx scramblers.. and whatever else
i can find. bleh.
as a favour, if you have a packed/encrypted file that isn't identified by pe-scan, it'd be
cool if you sent me it with a description (program, version, where to get it maybe).
kyrim@lineone.net

=)

-

hope you find it useful.
[or at least, more useful than a session with a generic unpacker and hex-workshop. =p]

- snyper
