PE-bear is a project that can be used for reversing malwares, the tool provides a very useful interface to compare two portable executable files and see the difference. Some of the features are:
- views multiple files in parallel
- recognizes known packers (by signatures)
- fast disassembler – starting from any chosen RVA/File offset
- visualization of sections layout
- integration with explorer menu
Users just need to load the PE file that require analyses and you will have several tabs where you can find the PE header section and file preview that allows to identify any abnormal or packed code.
The latest version is 0.2.0 (beta) and can be downloaded on the following link: http://hshrzd.wordpress.com/pe-bear/