PEiD is a very useful shell checking tool, and it is easy to know whether the software has a shell. With this PEiD, almost all the shells of the software can be detected, with more than 470 types and signatures of PE files. In addition, PEiD can also identify what language exe files are written in, such as VC++, Delphi, VB or Delphi.
Introduction of peid function
1. Normal scanning mode: PEiD can scan the signatures of all records at the entry point of PE documents.
2. Deep scanning mode: All recorded signatures can be scanned in depth, which is wider and deeper than the previous scanning mode.
3. Core scanning mode: PEiD can scan the entire PE document completely, and this mode is recommended as the last choice.
Extended data
Main modules of PEID:
1. Task viewing module: all currently running tasks and modules can be scanned and viewed, and their operation can be terminated;
2. Multi-file scanning module: multiple files can be scanned at the same time. Select "Show PE files only" to filter non-PE documents; Select Recursive Scan to scan all documents, including subdirectories.
3. Hexadecimal viewing module: You can quickly view hexadecimal files.