| View previous topic :: View next topic |
| Author |
Message |
Ze[X]ro Master Cheater
Reputation: 1
Joined: 18 Feb 2009 Posts: 360 Location: ---
|
Posted: Tue Feb 02, 2010 11:30 am Post subject: How to detect a backdoor on a tool |
|
|
1) right click it, if you got winrar installed and you see
"open with winrar" then this means it was binded with winrar
so def backdoored
2) open it with a resource editor such as resource hacker/restorator/pe explorer and check the rcdata section,if theres 1 & 2 entries in it
then its binded
3) open it with a hex editor , at the start of a PE header theres always this line "This program cannot be run in DOS mode" , search for it,if it
exists more then once then it might be binded
it depends on the specific app,for example its not unusual for
binders/crypters to have the stub file attached in the resources
also search for .exe and inspect the results,a binded file
drops the files to a temp folder before executing em , so if
you find somethin like this: %.t.e.m.p.%.\.x.x...e.x.e or file1.exe/file2.exe
then its def binded
4) run it in sandboxie ,when a file is ran'd in sandboxie its isolated (cant access your files/registry, first click the sandboxie tray icon to
open up its Window , then right click the file and click "run with sandboxie"
if you see another process name in the sandboxie Window then its probably backdoored (this doesnt include sandboxie rpcss/dcom launch processes,those are legit and needed for some programs) , thats not all , the file may drop another when one of the buttons in the program GUI is clicked or after you close it , so click all the buttons and close it
just to make sure , if you do see other processes then immdiatly click file>terminate all processes from the sandboxie menu , if a file refuses to run in sandboxie or its suppose to be a program and it runs
without GUI then it would probably be best to delete it _________________
i like potatoes |
|
| Back to top |
|
 |
Benji Random spam moderator
Reputation: 3
Joined: 31 Dec 2007 Posts: 61 Location: The Netherlands
|
Posted: Tue Feb 02, 2010 11:32 am Post subject: |
|
|
Thx i dont want any viruses
how do i +rep u? _________________
|
|
| Back to top |
|
 |
Ze[X]ro Master Cheater
Reputation: 1
Joined: 18 Feb 2009 Posts: 360 Location: ---
|
|
| Back to top |
|
 |
Benji Random spam moderator
Reputation: 3
Joined: 31 Dec 2007 Posts: 61 Location: The Netherlands
|
Posted: Tue Feb 02, 2010 11:43 am Post subject: |
|
|
| [KFF]ZeXro wrote: | Click The under my Avatar. |
hmm i dont see it but i think u meen the one upside down xDDDD
ill click it now 4 you _________________
|
|
| Back to top |
|
 |
Ze[X]ro Master Cheater
Reputation: 1
Joined: 18 Feb 2009 Posts: 360 Location: ---
|
Posted: Tue Feb 02, 2010 11:45 am Post subject: |
|
|
xDDDDDDDDDD U DERPED ME FAG!!! XDDDDDDD such n00b _________________
i like potatoes |
|
| Back to top |
|
 |
Benji Random spam moderator
Reputation: 3
Joined: 31 Dec 2007 Posts: 61 Location: The Netherlands
|
Posted: Tue Feb 02, 2010 11:47 am Post subject: |
|
|
| [KFF]ZeXro wrote: | | xDDDDDDDDDD U DERPED ME FAG!!! XDDDDDDD such n00b |
dude wtf why do u call me n00b i only help you!! _________________
|
|
| Back to top |
|
 |
Ze[X]ro Master Cheater
Reputation: 1
Joined: 18 Feb 2009 Posts: 360 Location: ---
|
Posted: Tue Feb 02, 2010 11:49 am Post subject: |
|
|
but you DEreped me so its no help its dis-help i had 0 reps now I have -1 _________________
i like potatoes |
|
| Back to top |
|
 |
Benji Random spam moderator
Reputation: 3
Joined: 31 Dec 2007 Posts: 61 Location: The Netherlands
|
Posted: Tue Feb 02, 2010 11:51 am Post subject: |
|
|
| [KFF]ZeXro wrote: | | but you DEreped me so its no help its dis-help i had 0 reps now I have -1 |
but i dont see a up button i thought i was helping you sorry plz forgive me :'( _________________
|
|
| Back to top |
|
 |
Ze[X]ro Master Cheater
Reputation: 1
Joined: 18 Feb 2009 Posts: 360 Location: ---
|
Posted: Tue Feb 02, 2010 11:54 am Post subject: |
|
|
| thing that got ripped off by a dog when I was a childthing that got ripped off by a dog when I was a childthing that got ripped off by a dog when I was a childMark wrote: | | [KFF]ZeXro wrote: | | but you DEreped me so its no help its dis-help i had 0 reps now I have -1 |
but i dont see a up button i thought i was helping you sorry plz forgive me :'( |
xDD acctually dereping and plusreping immaterial so ill forgive u lAwl _________________
i like potatoes |
|
| Back to top |
|
 |
Benji Random spam moderator
Reputation: 3
Joined: 31 Dec 2007 Posts: 61 Location: The Netherlands
|
Posted: Tue Feb 02, 2010 11:55 am Post subject: |
|
|
| [KFF]ZeXro wrote: | | thing that got ripped off by a dog when I was a childthing that got ripped off by a dog when I was a childthing that got ripped off by a dog when I was a childMark wrote: | | [KFF]ZeXro wrote: | | but you DEreped me so its no help its dis-help i had 0 reps now I have -1 |
but i dont see a up button i thought i was helping you sorry plz forgive me :'( |
xDD acctually dereping and plusreping immaterial so ill forgive u lAwl |
xPP _________________
|
|
| Back to top |
|
 |
|