Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 01-14-2005, 20:31
tr1stan
 
Posts: n/a
Quote:
Originally Posted by dyn!o
In my humble opinion the best way is to detect Daemon Tools by its MINI-PORT driver and BUS driver. If you will use window/class names then it takes fer seconds to change them and you will fail. If you will use generic like methods (drivers scanning) then you always are able to detect it. Of course do not try to detect them (drivers) by name but properties.
Correct but then you have only detected dtools not disabled the
emulation, it would be better to scan the system to find the position
of the dtools dll or exe file and disable all usefull stuff...
the question what else can you do to search for those files if changing
the registry entries failed?
Reply With Quote
  #2  
Old 01-14-2005, 22:14
dyn!o's Avatar
dyn!o dyn!o is offline
Friend
 
Join Date: Nov 2003
Location: Own mind
Posts: 214
Rept. Given: 1
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 8
Thanks Rcvd at 0 Times in 0 Posts
dyn!o Reputation: 1
A complete miss. Listen to my words, not only read

Obtaining location of exe/dll gives you nothing. Read my previous post once again. You should understand what role a driver plays in the system - notice it operates on kernel level.... You can kill/disable DaemonTools in a proper (professional) way.

"what else can you do to search for those files if changing the registry entries failed?"
Forget this idea - it is too simple and not effective.

Scanning files/directories/registry is not the way. What if I will change file name? What if I will change registry key location? What if I will change registry data?

Think about it.

Good luck.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Methods of detecting dongle emulator MeteO General Discussion 4 02-17-2006 09:43


All times are GMT +8. The time now is 00:12.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )