								UnPeShield - The  PEShield 0.25 Unpacker
This unpacker is written in win32asm, for use with PEShield version 0.25 only. 
Some notes about this unpacker are in order:
	* It's not a generic unpacker: it works only with files encrypted with PEShield 0.25.
	* It doesn't unpack the reloc section: it only decrypts the section. This behavior is intentional.
	  The reloc section is not used by .exe and this version of PEShield doesn't accept .dll. So I
	  don't see any value in restoring it to original state. 
	* It doesn't delete the decrypter section from the final output file. This is because PEShield moved
	  the icons from the target file into the decrypter section. The original icons are destroyed so there is
	  no way to restore the icons back to the original places.
	* It handles recursive encryption automatically. It means if the target is encrypted by PEShield several
	  times in succession, unpeshield will attempt to decrypt the target again and again until it can detect no
	  more encryption layer.
	
How to use this unpacker
Very simple. Just run unpeshield.exe. You'll be presented with an openfile dialog. Just choose the file you want
to decrypt and press OK. If the file is encrypted by PEShield 0.25, it will start decryption immediately and will
ask you to supply the name of the output file.

I haven't tested this unpacker with older versions of PEShield. Those were already taken care of by G-RoM.
Contact me at Iczelion@galaxycorp.com

Greets: hutch--, __Ice, Stone, the_owl, novatrix, X-Calibre, Accz, thesmurf, Kanobi, Einride,defiler, _Secret
               Neural_Noise (nu), llama, _masta_, notty, _iceman__, Weazel, NRoC, Cali, JosephCo, rudeboy
               WarezPup, CrackZ, MrNop,ultra_schall everyone in #win32asm and #cracking4newbies