Softpedia
 

WINDOWS CATEGORIES:



GLOBAL PAGES >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>

WEEK'S BEST

  • DAEMON Tools Pro (...
  • FlashFXP [ DISCOUN...
  • PowerISO 4.9
  • WebcamMax [DISCOUN...
  • Zemana AntiLogger ...
  • System Mechanic Pr...
  • Glary Utilities Pr...
  • All My Movies [DIS...
  • Ad-Aware Internet ...
  • Atlantis Word Proc...
  • Home > Windows > System > File Management
     Report malware

    PE Detective 1.2.1.1

    download button

    Downloads: 2,551  Tell us about an update
    User Rating:
    Rated by:
    Good (3.4/5)
    16 user(s)
    Developer:

    License / Price:

    Size / OS:

    Last Updated:

    Category:

    Freeware / $0
    607 KB / Windows All

    C: \ System \ File Management

     Read user reviews (0)  Send to friend   Follow (0 users)

    PE Detective description

    A simple, easy to use PE identifier

    PE Detective can scan single PE files or entire directories (also recursevely) and generate complete reports.

    The PE Detective is deployed along with the Signature Explorer, which is an advanced signature manager to check collisions, handle, update and retrieve signatures.

    To scan a file is very easy with the PE Detective tool: just drag and drop a file on the interface and press scan. If PE Detective finds multiple results, all of them will be listed in descending priority.

    The data for each result shows the signature name, the number of matches (meaning how many bytes in the signature match, wildcards aren't counted) and possible comments regarding the signature.

    It's, also, possible to perform a directory scan through the PE Detective. This means that every file in that directory will be scanned and listed in the results. The scan can be performed recursevely. As you can see, through the pop-up menu you can generate a complete report of the scanning session.

    The PE Detective comes along with the Signature Explorer, an advanced signature manager. This manager can open a signature database (there's one for each supported platform and a platform independent dabatase) and add, modify and delete its signatures. Entire PE Signatures are only used when the Deep Scan option is enabled. Those kind of signatures are scanned through the entire PE.

    To retrieve new signatures to add to the database, there's a Signature Retriever utility. This utility retrieves common bytes (at a certain RVA and given a maximum signature lenght) of two or more applications. The default RVA is the application entrypoint.

    Update is an easy task. Through the update utility you can update the current loaded signature database online or from file. There's an option to show only not-already-existing signatures and you can still delete all the items you don't want to add to the database.

    The last utility provided by the Signature Explorer is a Collision Checker. Basically, it checks the current loaded database for collisions (meaning already existing signatures).

    The check can be done specifying various options. When the scan is completed, already existing signatures are showed in collision groups and each signature has a different colour depending on how it collides with the other signature in its collision group.

    You can also delete from the same interface all the signatures which you think of being redundant.

    Here are some key features of "PE Detective":

    · File Scanner
    · Directory Scanner
    · Deep Scan method
    · Recursive Scan method
    · Multiple results
    · Report generation
    · Signatures Manager
    · Signatures Updater
    · Signatures Collisions Checker
    · Signatures Retriever

     Softpedia guarantees that PE Detective 1.2.1.1 is 100% CLEAN, which means it does not contain any form of malware, including spyware, viruses, trojans and backdoors. [read more >]


    TAGS:

    PE finder | Portable executable locator | PE searcher | Portable executable | searcher | finder



    HTML code for linking to this page:


    Go to top

    WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

    SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM