Anyone using PeStudio by Winitor?

Discussion in 'other anti-malware software' started by Tyrizian, May 27, 2013.

  1. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    PeStudio updated:
    . Added more Indicators specific to the location of the Entry Point
    . Added more details (offset and size) for each file Cave detected
     
  2. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Thanks for another heads up.
     
  3. nosirrah

    nosirrah Malware Fighter

    Joined:
    Aug 25, 2006
    Posts:
    561
    Location:
    Cummington MA USA
    @ Marc Ochsenmeier

    Where do you want me to send malware that crashes your project?
     
  4. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    @nosirrah: always glad to improve the stability of PeStudio! You can send me samples to the following email address: info@winitor.com

    Please zip the file with "infected" as psw. Thanks.
     
  5. nosirrah

    nosirrah Malware Fighter

    Joined:
    Aug 25, 2006
    Posts:
    561
    Location:
    Cummington MA USA
    Sent with subject "samples that crash PeStudio".
     
  6. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    Thank your very much for the samples. PeStudio has been fixed (enhanced) to support these malformations and will be released soon. Please continue to send me samples that crashes PeStudio!
     
  7. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    @0strodamus: Thank you very much for accepting to correct my text into real English! :thumb:
     
  8. FOXP2

    FOXP2 Guest

    Your English is better than 98% of those born into it. Tschüß!
     
  9. 0strodamus

    0strodamus Registered Member

    Joined:
    Aug 23, 2009
    Posts:
    1,058
    Location:
    United Surveillance States
    You're very welcome and FOXP2 is right - you didn't need much help at all. I just hope I didn't make any mistakes! :)
     
  10. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    I am looking for samples already packed with nspack. Can anyone give me a hint where I can find such samples? Thanks.
     
  11. ELWIS1

    ELWIS1 Registered Member

    Joined:
    Sep 29, 2010
    Posts:
    60
    Marc no problem for me with samples packed nspack.

    I will be you send little samples with nspack in a few hours.
     
  12. 0strodamus

    0strodamus Registered Member

    Joined:
    Aug 23, 2009
    Posts:
    1,058
    Location:
    United Surveillance States
    Is there a way to launch PeStudio and have it open to a specific tab? For example, "PeStudio.exe /VTtab" or "PeStudio.exe /Librariestab".
     
  13. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    @0strodamus: good Idea! What about setting this starting Tab option in the XML file e.g. <starting_tab>2</starting_tab>?
     
  14. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    @ELWIS1: Thanks for the files!
     
  15. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    @nosirrah: thanks again for the samples that crashed PeStudio! The new version of PeStudio now handles this malformed samples correctly.


    . Added an Indicator when the Offset of a Directory is outside any Section
    . Added an Indicator for duplicate Sections Offset
    . Corrected mapping of Sections
    . Handle non-printable characters in XML report
     
  16. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    PeStudio updated:

    . Handle Resources distributed among several Sections (à la Themida)
    . Added <default_tab> TAG in the PeStudioSettings.xml file to determine in which TAB the GUI must start
     
    Last edited: Jul 24, 2013
  17. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    I would stilll welcome images that crash PeStudio or that are malformed....Thanks!
     
  18. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    My poor SSD is being overwritten like crazy! :eek:

    I remember it crashing when I accidentally checked a large media or text file, doubt that counts.
     
  19. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    PeStudio update:

    - . Fixed an issue with 64bit Images
     
  20. 0strodamus

    0strodamus Registered Member

    Joined:
    Aug 23, 2009
    Posts:
    1,058
    Location:
    United Surveillance States
    Thanks Marc!
     
  21. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    @0strodamus: You're welcome! Hope this feature saves the click. :)
     
  22. genieautravail

    genieautravail Registered Member

    Joined:
    May 6, 2012
    Posts:
    109
  23. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    @genieautravail: thanks for using PeStudio! Really sorry about this failure. Actually, I don't know why that happens. I'll reinstall my XP SP3 VM and test it.
     
  24. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    PeStudio has been updated:

    . Support usage of PeStudio from the Command Prompt
    . Started a "PeStudio Handbook.pdf"
     
  25. ellison64

    ellison64 Registered Member

    Joined:
    Oct 5, 2003
    Posts:
    2,587
    Hi ...
    would it be hard to intergrate right click explorer scan on a file.?I like the virustotal intergration but it would be great to perform this action from right click explorer.Same goes for analyse a file..I know this doesn't install anywhere but it would be nice for that option.
    thanks
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.