PEiD updated description PEiD detects most common packers, cryptors and compilers for PE files and currently it can detect more than 470 different signatures in PE files. PEiD is special in some aspects when compared to other identifiers already out there! Here are some key features of “PEiD updated”: · It has a superb GUI and the interface is really intuitive and simple. En la primera etapa del análisis
trataremos de conocer la estruc-
tura del i chero sospechoso. Para
ello nos servirá el analizador de
i cheros ejecutables PEiD. Esta
herramienta posee una base de
datos incorporada que permite de-
terminar el lenguaje utilizado para
crear una aplicación e identii car
los tipos más populares de compre-
sores y protectores de i cheros eje-
cutables. También podemos utilizar
FileInfo, un analizador de i cheros
un poco más antiguo. Sin embargo,
este último no es desarrollado tan
dinámicamente como PEiD, y el re-
sultado obtenido puede ser menos
preciso.
PEiD detects most common packers, cryptors and compilers for PE files
· Detection rates are amongst the best given by any other identifier.
· Special scanning modes for *advanced* detections of modified and unknown files.
· Shell integration, Command line support, Always on top and Drag’n'Drop capabilities.
· Multiple file and directory scanning with recursion.
· Task viewer and controller.
· Plugin Interface with plugins like Generic OEP Finder and Krypto ANALyzer.
· Extra scanning techniques used for even better detections.
· Heuristic Scanning options.
· New PE details, Imports, Exports and TLS viewers
· New built in quick disassembler.
· New built in hex viewer.
· External signature interface which can be updated by the user.
What’s New in This Release:
· Added sorting of Plugin menu items. Submenus are created based on subfolders in the directory.
· Added Brizo disassembler core. Added some more detections.
· Fixed documented and undocumented vulnerability issues.
· Fixed some general bugs.
· Removed mismatch mode scanner which needs further improvements.