Enigma Virtual Box Unpacker / 解包工具
Project description
evbunpack
Enigma Virtual Box unpacker
Features
- Restores PEs
- PEs with overlays can be recovered as well (EVB sometimes break them).
- TLS, Exceptions, and Import Tables are recovered in a way that resembles the original PE most closely.
- Produces nearly byte-perfect packages. You should be able to run like they were intended to!
- Unpacks EVB's virtual file system w/wo compression (aplib)
- This applies to both built-in content and external packages
- Support for older/6.X and newest/9.X EVB packages
Installation
For Windows Users : Builds are available here
Or get the latest version from PyPi:
pip install evbunpack
Usage
usage: evbunpack [-h] [--ignore-fs] [--ignore-pe IGNORE_PE] [--legacy] [--list] file output
Enigma Virtual Box Unpacker
positional arguments:
file File to be unpacked
output Extract destination directory
options:
-h, --help show this help message and exit
--ignore-fs Don't extract virtual filesystem. Useful if you want the PE only
--ignore-pe IGNORE_PE
Treat PE files like external packages and thereby does not recover the original executable (for usage without pefile)
--legacy Enable compatibility mode to work with older (6.x) EVB packages
--list Don't extract the files and print the TOC only (surpresses other output)
Examples
evbunpack Lycoris_radiata.mys ../biman5_chs_moe
evbunpack biman2.exe ./extract --legacy
TODO
Restore original PEs- Registery configuration extraction
Credits
License
Apache 2.0 License
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
evbunpack-0.1.9.4.1.tar.gz
(14.6 kB
view hashes)
Built Distributions
evbunpack-0.1.9.4.1-py3.11.egg
(28.8 kB
view hashes)
Close
Hashes for evbunpack-0.1.9.4.1-py3-none-any.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | 900993fd0f4129eeb4c32aff20c1fe15e15d5c148b2a614c25c3bbbd596aec91 |
|
MD5 | 8a808a9899bd962b2789eab484915f50 |
|
BLAKE2b-256 | 78892d00d6091ec2126ca2ef5f5471e35c702697ef5d8fe633ac3466bf1b2ba2 |