Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


How to detect a backdoor on a tool

 
Post new topic   Reply to topic    Cheat Engine Forum Index -> Random spam
View previous topic :: View next topic  
Author Message
Ze[X]ro
Master Cheater
Reputation: 1

Joined: 18 Feb 2009
Posts: 360
Location: ---

PostPosted: Tue Feb 02, 2010 11:30 am    Post subject: How to detect a backdoor on a tool Reply with quote

1) right click it, if you got winrar installed and you see
"open with winrar" then this means it was binded with winrar
so def backdoored

2) open it with a resource editor such as resource hacker/restorator/pe explorer and check the rcdata section,if theres 1 & 2 entries in it
then its binded

3) open it with a hex editor , at the start of a PE header theres always this line "This program cannot be run in DOS mode" , search for it,if it
exists more then once then it might be binded
it depends on the specific app,for example its not unusual for
binders/crypters to have the stub file attached in the resources
also search for .exe and inspect the results,a binded file
drops the files to a temp folder before executing em , so if
you find somethin like this: %.t.e.m.p.%.\.x.x...e.x.e or file1.exe/file2.exe
then its def binded

4) run it in sandboxie ,when a file is ran'd in sandboxie its isolated (cant access your files/registry, first click the sandboxie tray icon to
open up its Window , then right click the file and click "run with sandboxie"
if you see another process name in the sandboxie Window then its probably backdoored (this doesnt include sandboxie rpcss/dcom launch processes,those are legit and needed for some programs) , thats not all , the file may drop another when one of the buttons in the program GUI is clicked or after you close it , so click all the buttons and close it
just to make sure , if you do see other processes then immdiatly click file>terminate all processes from the sandboxie menu , if a file refuses to run in sandboxie or its suppose to be a program and it runs
without GUI then it would probably be best to delete it

_________________
i like potatoes
Back to top
View user's profile Send private message Send e-mail
Benji
Random spam moderator
Reputation: 3

Joined: 31 Dec 2007
Posts: 61
Location: The Netherlands

PostPosted: Tue Feb 02, 2010 11:32 am    Post subject: Reply with quote

Thx i dont want any viruses
how do i +rep u?

_________________
Back to top
View user's profile Send private message
Ze[X]ro
Master Cheater
Reputation: 1

Joined: 18 Feb 2009
Posts: 360
Location: ---

PostPosted: Tue Feb 02, 2010 11:39 am    Post subject: Reply with quote

Click The under my Avatar.
_________________
i like potatoes
Back to top
View user's profile Send private message Send e-mail
Benji
Random spam moderator
Reputation: 3

Joined: 31 Dec 2007
Posts: 61
Location: The Netherlands

PostPosted: Tue Feb 02, 2010 11:43 am    Post subject: Reply with quote

[KFF]ZeXro wrote:
Click The under my Avatar.

hmm i dont see it but i think u meen the one upside down xDDDD
ill click it now 4 you

_________________
Back to top
View user's profile Send private message
Ze[X]ro
Master Cheater
Reputation: 1

Joined: 18 Feb 2009
Posts: 360
Location: ---

PostPosted: Tue Feb 02, 2010 11:45 am    Post subject: Reply with quote

xDDDDDDDDDD U DERPED ME FAG!!! XDDDDDDD such n00b
_________________
i like potatoes
Back to top
View user's profile Send private message Send e-mail
Benji
Random spam moderator
Reputation: 3

Joined: 31 Dec 2007
Posts: 61
Location: The Netherlands

PostPosted: Tue Feb 02, 2010 11:47 am    Post subject: Reply with quote

[KFF]ZeXro wrote:
xDDDDDDDDDD U DERPED ME FAG!!! XDDDDDDD such n00b

dude wtf why do u call me n00b i only help you!!

_________________
Back to top
View user's profile Send private message
Ze[X]ro
Master Cheater
Reputation: 1

Joined: 18 Feb 2009
Posts: 360
Location: ---

PostPosted: Tue Feb 02, 2010 11:49 am    Post subject: Reply with quote

but you DEreped me so its no help its dis-help i had 0 reps now I have -1
_________________
i like potatoes
Back to top
View user's profile Send private message Send e-mail
Benji
Random spam moderator
Reputation: 3

Joined: 31 Dec 2007
Posts: 61
Location: The Netherlands

PostPosted: Tue Feb 02, 2010 11:51 am    Post subject: Reply with quote

[KFF]ZeXro wrote:
but you DEreped me so its no help its dis-help i had 0 reps now I have -1

but i dont see a up button i thought i was helping you sorry plz forgive me :'(

_________________
Back to top
View user's profile Send private message
Ze[X]ro
Master Cheater
Reputation: 1

Joined: 18 Feb 2009
Posts: 360
Location: ---

PostPosted: Tue Feb 02, 2010 11:54 am    Post subject: Reply with quote

thing that got ripped off by a dog when I was a childthing that got ripped off by a dog when I was a childthing that got ripped off by a dog when I was a childMark wrote:
[KFF]ZeXro wrote:
but you DEreped me so its no help its dis-help i had 0 reps now I have -1

but i dont see a up button i thought i was helping you sorry plz forgive me :'(

xDD acctually dereping and plusreping immaterial so ill forgive u lAwl

_________________
i like potatoes
Back to top
View user's profile Send private message Send e-mail
Benji
Random spam moderator
Reputation: 3

Joined: 31 Dec 2007
Posts: 61
Location: The Netherlands

PostPosted: Tue Feb 02, 2010 11:55 am    Post subject: Reply with quote

[KFF]ZeXro wrote:
thing that got ripped off by a dog when I was a childthing that got ripped off by a dog when I was a childthing that got ripped off by a dog when I was a childMark wrote:
[KFF]ZeXro wrote:
but you DEreped me so its no help its dis-help i had 0 reps now I have -1

but i dont see a up button i thought i was helping you sorry plz forgive me :'(

xDD acctually dereping and plusreping immaterial so ill forgive u lAwl

xPP

_________________
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> Random spam All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites