PEiD是(shì)一(yī)款著(zhe)名的查(chá)壳工(gōng)具,其功能强大,几(jǐ)乎(hū)可(kě)以(yǐ)侦测出(chū)所有的(de)壳,其数量已超过470 种(zhǒng)PE 文档(dàng) 的加壳类型和签名。PEiD 强大侦壳工具0.95汉化(huà)绿色版(bǎn)本版本新(xīn)增加WinNT平台下的自动脱壳器插件,可以应对现(xiàn)在大部(bù)分的软件(jiàn)脱壳(包括PEiD自身的(de)UPXShit0.06壳)! 现在软件越来越(yuè)多(duō)的(de)加壳了(le),给破解(jiě)带(dài)来非常大的不便,但是这个软件可以检(jiǎn)测出 450种壳,非(fēi)常方(fāng)便!
PEiD是一款著名的查壳(ké)工具,PEiD功能强大,几乎可以侦测出所有的壳,PEiD数量已超(chāo)过(guò)470 种PE 文档 的加壳(ké)类型和签名。PEiD内(nèi)置有差错控制的技术,所以一般能确保(bǎo)扫描结(jié)果的准确性。PEiD 可以(yǐ)探测大多数的 PE 文档封(fēng)包器、加密(mì)器和编译器。当前可以(yǐ)探测 600 多个不同签(qiān)名,另外(wài)还可识别出EXE文件是用(yòng)什么语言编写(xiě)的,比如:VC++、Delphi、VB或Delphi等。PEiD汉化版能检测(cè)大多数编译语言、病毒(dú)和加(jiā)密的壳,它主(zhǔ)要利用查特征串搜索来完成识别工(gōng)作的。该PEiD汉化版为全插件版,是(shì)目前(qián)网络中(zhōng)最完(wán)美的版本,插件(jiàn)是特别全面的,又为广大的脱壳爱好者提供(gòng)了好工具啦!
·新增加WinNT平台(tái)下(xià)的自(zì)动脱壳器插件,可以应对现在大部分的软件脱壳(ké)(包括PEiD自身的UPXShit0.06壳)!
·现在软件越(yuè)来越多的加壳了,给破解(jiě)带来非常大的不便,但是这个(gè)软件可以(yǐ)检测出 450种壳,非常方便!
·增加病毒扫(sǎo)描功能,是目(mù)前(qián)各类查壳工(gōng)具中,性(xìng)能最强的。
·另外还(hái)可识别出EXE文件(jiàn)是用什么语言编(biān)写的,比如:VC++、Delphi、VB或Delphi等。
·支持(chí)文(wén)件(jiàn)夹(jiá)批量扫描;
· 插件增(zēng)加到(dào)5个:General OEP、Kanal 1.3,FSG v1.33 Unpacker,CRC32(新增加的),PEiD 通用脱壳器(qì) Forwinnt2kxp(新增(zēng)加的(de)),
PEiD最常用的插件就是脱壳,PEiD的(de)插件里有个通用脱壳器,能脱大部(bù)分(fèn)的(de)壳,如果脱(tuō)壳(ké)后(hòu)import表损害,还(hái)可以自动调用(yòng)ImportREC修复import表(biǎo),点击"=>"打开(kāi)插(chā)件列表,如图:
根据插件列(liè)表,还(hái)可(kě)以(yǐ)专门(mén)针对(duì)一些壳脱壳,效果比通(tōng)用脱壳器(qì)会好
点击(jī)EP后的>可以展开Section块列表:
再在Section块表上(shàng)右击鼠标,可以看到以下(xià)菜单选项:
点击搜索全0处,会把所有块中全0的(de)区块搜出来,这样(yàng)我们可以在这些代(dài)码上加自己想加的code,非常方便(biàn):
直接用winhex改就(jiù)行了,
正常(cháng)扫描模式:可在PE文档的入口点扫(sǎo)描所有记(jì)录的签名
深度扫描(miáo)模式:可深度(dù)扫(sǎo)描所有(yǒu)记录的签名,这种模式要比上一种的(de)扫描范围更广,更(gèng)深(shēn)入
核心扫描模式:可(kě)完整的扫描整个PE文(wén)档,但相对有点慢
0.7 Beta -> First public release.
0.8 Public->Added support for 40 more packers. OEP finding module. Task viewing/control module.
GUI changes. General signature bug fixes. Multiple File and Directory Scanning module.
0.9 Recode->Completely recoded from scratch. New Plugin Interface which lets you use extra features.
Added more than 130 new signatures. Fixed many detections and general bugs.
0.91 Reborn-> Recoded everything again. New faster and better scanning engine. New internal signature system.
MFS v0.02 now supports Recursive Scanning. Commandline Parser now updated and more powerful.
Detections fine tuned and newer detections added. Very basic Heuristic scanning.
0.92 Classic->Added support for external database, independent of internal signatures. Added PE details lister.
Added Import, Export, TLS and Section viewers. Added Disassembler. Added Hex Viewer.
Added ability to use plugins from Multiscan window. Added exporting of Multiscan results.
Added ability to abort MultiScan without loosing results.
Added ability to show process icons in Task Viewer.
Added ability to show modules under a process in Task Viewer. Added some more detections.
0.93 Elixir->Added sorting of Plugin menu items. Submenus are created based on subfolders in the directory.
Added Brizo disassembler core. Added some more detections.
Fixed documented and undocumented vulnerability issues.
Fixed some general bugs.
Removed mismatch mode scanner which needs further improvements.
0.94 Flux->Too much is new to remember.
MFS, Task Viewer and Disassembler windows maximizable.
New smaller and lighter disassembler core CADT.
New KANAL 2.90 with much more detections and export features.
Added loads of new signatures. Thanks to all the external signature collections online.
String References integrated into disassembler.
Fixed documented and undocumented crashes.
Fixed some general bugs.
0.95 Phoenix -> Fixed some crashing bugs.
Minor Core update.
Crash Fix in Securom detection.
