PeStudio is a program for discovering malicious code, and locating and removing the infected files from your computer. It's a useful program for security professionals, novice users, and students alike. This freeware application is available for download to all Windows users, and contains no strings attached. It also offers a graphical user interface (GUI), command line version, and more than two dozen checks.
If you're curious about the endianness of your samples, PeStudio will tell you! This tool uses a powerful parser to analyze XML configuration files. It works on all Windows versions and won't modify the operating system's registries. Furthermore, this program is portable and doesn't require installation, making it ideal for private use. Besides, it is free of charge.
PeStudio is not just limited to finding suspicious executable files. It also has a comprehensive report on how executable files are constructed, as well as information about their signatures, sections, headers, and other information. It can also reveal the results of VirusTotal scans and hard-coded IP addresses. It can also reveal files' references and bind imports. In addition, it saves the entire report in XML format.
The interface of PeStudio makes it easy to use. It displays suspicious indicators such as UPX and MPRESS compressors, entropy, and size. All of these indicators can indicate malware. This tool has many features and is compatible with all versions of Windows. The best part is that it doesn't need any additional services, and it works on any Windows version. In addition, it doesn't require installation, so it's great for security professionals who don't want to be invasive.