Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #16  
Old 11-15-2005, 01:25
Franeppe Franeppe is offline
Friend
 
Join Date: Aug 2005
Location: Thrinakie
Posts: 82
Rept. Given: 9
Rept. Rcvd 5 Times in 3 Posts
Thanks Given: 2
Thanks Rcvd at 0 Times in 0 Posts
Franeppe Reputation: 5
Quote:
Originally Posted by heXer

4. Have you write to running.exe success?
Yes, i can write to running.exe file.

How did you solve the problem?

Last edited by Franeppe; 11-15-2005 at 01:27.
Reply With Quote
  #17  
Old 11-15-2005, 08:47
heXer heXer is offline
Friend
 
Join Date: Aug 2005
Posts: 25
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 3
Thanks Rcvd at 1 Time in 1 Post
heXer Reputation: 0
@Teerayoot
The nod32 is too foolish.
Reply With Quote
  #18  
Old 11-15-2005, 22:42
Sten Sten is offline
Friend
 
Join Date: Jan 2002
Posts: 50
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
Sten Reputation: 0
Quote:
Originally Posted by Franeppe
How did you solve the problem?
He uses:

MoveFileA(<original.exe>, <original.bak>);
CopyFileA(<original.bak>, <original.exe>);
WaitForSingleObject(hProcess, INIFINITE);
DeleteFileA(<original.bak>);

Just as I've proposed above. Nothing extremely interesting.
Reply With Quote
  #19  
Old 11-16-2005, 09:02
Maximus Maximus is offline
Friend
 
Join Date: Nov 2005
Posts: 39
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
Maximus Reputation: 0
If you have time to spend and admin rights on the system, you might try to play with "\\.\PhysicalDriveN" access -be careful, anyway.
(CreateFile&DeviceIOControl)
Reply With Quote
  #20  
Old 11-16-2005, 17:15
Kerlingen
 
Posts: n/a
If your file system is NTFS, you could get into very big trouble when accessing the drive on psysical level, since much of NTFS is still undocumented and many structures change with every Windows version (or even service pack).

My idea would be to use WinHex scripting. I don't know if this works, but with the normal WinHex you can hex-edit files directly on disk when browsing psysical or logical disks. So I guess with the WinHex scripting system you could do the same.

Last edited by Kerlingen; 11-16-2005 at 17:22.
Reply With Quote
  #21  
Old 11-17-2005, 00:54
Maximus Maximus is offline
Friend
 
Join Date: Nov 2005
Posts: 39
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
Maximus Reputation: 0
And buggy...
I faced an incredible NTFS bug that blocked, in order:
WinXp, Win2k, WinXp Installer CD, Win2k Installer CD, UBCD winXP(!!).
I installed Linux on an fresh mounted hd -the only way to run sw-, formatted 1st partition to fat, and recovered there.
*deadly* code somewhere...
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Running DeepSeek R1 locally chants General Discussion 25 07-12-2025 20:44
Running program from memory Spiyre General Discussion 6 09-18-2004 09:34
Need to find a pattern in a running file merlin General Discussion 14 07-20-2002 06:59


All times are GMT +8. The time now is 05:59.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )