Anyone using PeStudio by Winitor?

Discussion in 'other anti-malware software' started by Tyrizian, May 27, 2013.

  1. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    Thanks Fabian! PeStudio does not write anything on the system it is running on, that is why I never released this handy Registry trick (that Fabian shared to me a while ago either).
     
  2. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    @EASTER: Thanks for the compliment! :)

     
  3. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    9,599
    Location:
    U.S.A. (South)
    I confess i was lazy and thought throwing out that suggestion would save me codeing yet another one in the many i been making lately and modifying from video thumbnails, toggle menus and a host of other customizations I'm always adding to improve both functionality and appearances.

    Thanks for the code though. It's mind bending sometimes when working directly with these scripts and spending hours in the registry maze. But it's an obsession with me. It's. a great place to defeat the apprehension most people have when working in this section of windows. Useful too.

    Easter
     
  4. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    @Fabian Wosar: Can I add this handy .reg file to the PeStudio package?
     
    Last edited: Jun 25, 2013
  5. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Thanks for agreeing with my rather selfish request, I believe most users prefer the easier choice of VirusTotal.

    You can easily add it to the "Send To" menu. Editing the registry is not for me, unless you use it frequently.

    I agree, great job by the developer.
     
  6. Fabian Wosar

    Fabian Wosar Developer

    Joined:
    Aug 26, 2010
    Posts:
    838
    Location:
    Germany
    Sure.
     
  7. StillAlive

    StillAlive Registered Member

    Joined:
    Dec 29, 2008
    Posts:
    42
    Is it possible to add some statistics calculation for a file and its sections: entropy, redundancy, density of FPU instructions, etc. And with some graphical representation, if possible. For example:

    http://onthar.in/wp-content/uploads/2012/01/tau2.png
    http://onthar.in/wp-content/uploads/2012/01/tau3.png
    http://www.the-interweb.com/bdump/hexer/notepad-entropy.png
    http://2.bp.blogspot.com/-PT7QIYrzXVs/T77HcBnrPvI/AAAAAAAAANg/jGM6gAKf2DU/s1600/25.05.2012+03-40-12++377.jpg


    Entropy analyzers:

    http://www.cert.at/downloads/software/bytehist_en.html

    Crypto Implementations Analysis Toolkit
    http://sourceforge.net/projects/ciat/

    Entyzer - Advanced Entropy Analyzer
    http://www.themutable.com/

    http://www.fourmilab.ch/random/

    http://onthar.in/files/tauscanner/


    Entropy analyzers with source code:

    Ent - Entropy Level and FPU Density Measurement Tool
    http://gynvael.coldwind.pl/?id=158
    http://gynvael.coldwind.pl/?id=162

    http://mydiary-musiclife.blogspot.com/2012/05/badguy.html
    http://mydiary-musiclife.blogspot.com/2012/05/blog-post_25.html

    http://www.manhunter.ru/assembler/556_raschet_entropii_na_assemblere.html
     
    Last edited: Jun 27, 2013
  8. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    @StillAlive: thank you very much for this input! Actually I am already working on MD5 for sections and Resources. Entropy is also in the pipe. I'll have a look at these suggested URLs very soon.
     
    Last edited: Jun 27, 2013
  9. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
  10. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
  11. StillAlive

    StillAlive Registered Member

    Joined:
    Dec 29, 2008
    Posts:
    42
    I don't know... I can access this site. Try a Russian proxy or startpage.com search engine -> View by Ixquick Proxy

    The file Entropy.Demo.zip from the site I uploaded to a file sharing service:
    http://rghost.ru/47060723
     
  12. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    PeStudio has been updated:

    . Added Detection of Fake UPX (sections named like UPX but the image is NOT UPXed)
    . Extended detection of Executable(s) embedded in the image
    . Extended "Severity" Indicator (see PeStudioIndicators.xml) to increase the granularity when scoring an image.
    . Added "PeStudioIntoExplorerContextMenu.reg" file to the package to *manually* integrate PeStudio in the context Menu of Explorer
     
  13. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    PeStudio has been updated:

    . Added detection of Overlay (extra-data appended to the end of the image)
     
  14. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,838
    Thank you mox for the update :thumb:
     
  15. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    a new version of PeStudio is available:

    . Added more validation check on Version info to handle hand-crafted version block (e.g. corkami\version_cust.exe)
    . Added Detection of Images based on the Visual Basic Virtual Machine
    . Corrected size of Overlay for signed images.
     
  16. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    PeStudio updated:

    . Enhanced detection of fake UPX
    . Extented Blacklist of Functions
    . Fixed a bug when handling exported functions
    . Show Section:Offset Addresses where exports, imports and strings are located in
     
  17. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    PeStudio update:

    . Added Detection of Device Drivers and handle Indicators accordingly
     
  18. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    9,599
    Location:
    U.S.A. (South)
    This update is the best one yet for my expectations.

    Thanks a bunch and keepem'.coming. Useful program indeed.
     
  19. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    @EASTER: thanks! Yeah, I keep working on it.
     
  20. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    PeStudio has been updated:

    - it now detects when an Image is statically linked to the C Run-Time Libraries
     
  21. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    PeStudio now detects the (direct) usage of the Native APIs.
     
  22. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    PeStudio updated:

    . Handle shrinked (hand-crafted) File Header
    . Added collection of Unicode Strings
     
  23. Marc Ochsenmeier

    Marc Ochsenmeier Developer

    Joined:
    Jun 6, 2013
    Posts:
    150
    Location:
    Germany
    PeStudio has been updated:

    . Added Sections MD5 computation
     
  24. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    mox,

    can you wait for few days and then release new update with several fixes?
    There is new version every day...
    Just my 2 cents....
     
  25. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,979
    @ mox

    Thanks for the updates ;)

    siketa makes a good point though ;)
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.