Author Topic: Own TrIDDefs.TRD ?  (Read 15245 times)

Scrapie

  • Guest
Own TrIDDefs.TRD ?
« on: November 28, 2008, 06:40:31 PM »
Hi

I'm just wondering if it's possible to generate a personal TrIDDefs.TRD for the CMD-Version of TrID or make it use personal *.xml-definitions only ?

Found out that the detection of UPX and Yoda in the general TrIDDefs.TRD isn't very good and I would like to build my own TrIDDefs.TRD wich detect every single on of the 22 different UPX-Versions more accurate (like PEiD). Depending on the UPX-Version TrID shows up to 33% yoda and 38% UPX - wich isn't very good.


Thx for you answer,
Scrapie

PS:
You recieved my submission via email ?

Mark0

  • Administrator
  • Hero Member
  • *****
  • Posts: 2743
    • Mark0's Home Page
Re: Own TrIDDefs.TRD ?
« Reply #1 on: November 29, 2008, 01:13:15 PM »
Hi!

I'm just wondering if it's possible to generate a personal TrIDDefs.TRD for the CMD-Version of TrID or make it use personal *.xml-definitions only ?

Yes! Just use the TrIDDefsPack tool you can find on the TrIDScan page. It will take all the *.trid.xml files in the current dir and create a new TRD file.
Then you could use TrID with that (or various other) definitions pack specififing it with the "-d:<filepath+filename>" parameter.

Quote
Found out that the detection of UPX and Yoda in the general TrIDDefs.TRD isn't very good and I would like to build my own TrIDDefs.TRD wich detect every single on of the 22 different UPX-Versions more accurate (like PEiD). Depending on the UPX-Version TrID shows up to 33% yoda and 38% UPX - wich isn't very good.

Yes. Clearly while it can identify many EXE types, TrID isn't clearly the best tool for a so specific job.

Bye!


Scrapie

  • Newbie
  • *
  • Posts: 2
Re: Own TrIDDefs.TRD ?
« Reply #2 on: November 30, 2008, 05:17:39 PM »
Hi

Thx for our reply.
Must have been blind, sorry. Found what you suggested and I'm able to creat my own TRD now :)

Thank you also for this nice little DLL you created. It works great with VB and is very easy to implement.


Cheers,
Scrapie

Mark0

  • Administrator
  • Hero Member
  • *****
  • Posts: 2743
    • Mark0's Home Page
Re: Own TrIDDefs.TRD ?
« Reply #3 on: December 01, 2008, 05:51:31 PM »
Perfect.
If you'll develop something using TrIDLib, let me know and I will be happy to cite / link it!

Thanks,
Bye!