" />
PEID v0.94漢化綠色版下載,PEiD專(zhuān)業(yè)的查殼軟件哦! 幾乎可以偵測(cè)出所有的殼,其數(shù)量已超過(guò)470 種PE 文檔 的加殼類(lèi)型和簽名。
PEID v0.94漢化綠色版下載,PEiD專(zhuān)業(yè)的查殼軟件哦! 幾乎可以偵測(cè)出所有的殼,其數(shù)量已超過(guò)470 種PE 文檔 的加殼類(lèi)型和簽名。
PEiD專(zhuān)業(yè)的查殼軟件哦! 幾乎可以偵測(cè)出所有的殼,其數(shù)量已超過(guò)470 種PE 文檔 的加殼類(lèi)型和簽名。PEiD能檢測(cè)大多數(shù)編譯語(yǔ)言.、病毒和加密的殼,它主要利用查特征串搜索來(lái)完成識(shí)別工作的,各種開(kāi)發(fā)語(yǔ)言都有固定的啟動(dòng)代碼部分,利用這點(diǎn)可識(shí)別是何種語(yǔ)言編譯的,被加殼程序處理過(guò)的程序,在殼里會(huì)留下相關(guān)加殼軟件的信息,利用這點(diǎn)就可識(shí)別是保種殼所加密的,它提供了一個(gè)擴(kuò)展接口文件userdb.txt ,用啟可以自定義一些特征碼,這樣可以識(shí)別出新的文件類(lèi)型,簽名的制作可以用插件Add Signature來(lái)完成!
PEiD最常用的插件就是脫殼,PEiD的插件里有個(gè)通用脫殼器,能脫大部分的殼,如果脫殼后import表?yè)p害,還可以自動(dòng)調(diào)用ImportREC修復(fù)import表,點(diǎn)擊"=>"打開(kāi)插件列表,如圖:
根據(jù)插件列表,還可以專(zhuān)門(mén)針對(duì)一些殼脫殼,效果比通用脫殼器會(huì)好
點(diǎn)擊EP后的>可以展開(kāi)Section塊列表:
再在Section塊表上右擊鼠標(biāo),可以看到以下菜單選項(xiàng):
點(diǎn)擊搜索全0處,會(huì)把所有塊中全0的區(qū)塊搜出來(lái),這樣我們可以在這些代碼上加自己想加的code,非常方便:
直接用WinHex改就行了,
0.7 Beta -> First public release.
0.8 Public->Added support for 40 more packers. OEP finding module. Task viewing/control module.
GUI changes. General signature bug fixes. Multiple File and Directory Scanning module.
0.9 Recode->Completely recoded from scratch. New Plugin Interface which lets you use extra features.
Added more than 130 new signatures. Fixed many detections and general bugs.
0.91 Reborn-> Recoded everything again. New faster and better scanning engine. New internal signature system.
MFS v0.02 now supports Recursive Scanning. Commandline Parser now updated and more powerful.
Detections fine tuned and newer detections added. Very basic Heuristic scanning.
0.92 Classic->Added support for external database, independent of internal signatures. Added PE details lister.
Added Import, Export, TLS and Section viewers. Added Disassembler. Added Hex Viewer.
Added ability to use plugins from Multiscan window. Added exporting of Multiscan results.
Added ability to abort MultiScan without loosing results.
Added ability to show process icons in Task Viewer.
Added ability to show modules under a process in Task Viewer. Added some more detections.
0.93 Elixir->Added sorting of Plugin menu items. Submenus are created based on subfolders in the directory.
Added Brizo disassembler core. Added some more detections.
Fixed documented and undocumented vulnerability issues.
Fixed some general bugs.
Removed mismatch mode scanner which needs further improvements.
0.94 Flux->Too much is new to remember.
MFS, Task Viewer and Disassembler windows maximizable.
New smaller and lighter disassembler core CADT.
New KANAL 2.90 with much more detections and export features.
Added loads of new signatures. Thanks to all the external signature collections online.
String References integrated into disassembler.
Fixed documented and undocumented crashes.
Fixed some general bugs.
0.95 Phoenix -> Fixed some crashing bugs.
Minor Core update.
Crash Fix in Securom detection.