Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 36 guests and 2 members online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow Ghost file/ entry created by program. Any help appreciated
EH-Net
May 19, 2013, 02:36:31 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Ghost file/ entry created by program. Any help appreciated  (Read 9061 times)
0 Members and 1 Guest are viewing this topic.
hardvibes
Newbie
*
Offline Offline

Posts: 4


View Profile
« on: July 25, 2007, 08:59:56 PM »

Hey all, new here and I hope i posted this in the right forum if not please redirect it to appropiate section. Appologies upfront.

Like to copy past my problem and maybe the real question I have what files or entrys this program creates during installation. I am german so please excuse my grammer.

---------------------

Problem: Cracking or erasing an entry to overcome a trial period expiry of a small program.

Program: Xaimer, Poolstation or Pool buddy.




Dear reader,

I am no computer wiz but I know a few things or two.

My problem is this program made for Yahoo Games Pool. While playing it helps you aiming a shot. Unfortunately it is a trial software and expires after 7 days than you need to pay the $24.95 or whatever. When you install the program it must create either some sort of ghost file or an entry in a registar so it knows when the 7 days are up. Heaps of websites offer cracks but they dont work so I made it a mission to crack it.. Their must be a way to find out during installation and than executing the program to find out what or where the program add's to the registar or creates a ghost file.. I also noticed that when you leave the software on for days past the trail time it still works.. so it must when you start it look and confirm with the entry when the software has been initialy installed..

- this is so far my try and fail.-

I downloaded the program to one of my network pc's which never had this software installed however before that I downloaded a registar alert program to alert me while during execution or installation any win registar files are created or changed.. Not much success. So once installed i run it and no registar alert either. So i used the search function to search for any files (inc. hidden file search) created or modified during the time period of 1day when it was installed. apart from the usual installed program files I found 2 XML documents that have been created and 2 *dll files that have been modified. I deleted the XML files and used a dll file editor to have a closer look which didnt tell me to much of what the file really is so since those two *.dll file have been created on that day I deleted them. Search continued for anything (File name and context containing the file name) and everything I have found i deleted.

Back to the main computer where the trial run up.. Searching for the same files and entry’s and deleting those.. So know that every single file or entry was erased that i could find had something to do with the program I went into dos and done a search again (created/ modified files) hoping that I might get more results.. Nada, seemed like that any file association was erased.

Thinking now that if I reinstall it will work I was disappointed by getting again the screen "Trial period expired". I even got as desperate to go into bios and change the time backwards to the day it was installed with no success. I also forced format c:/mbr to clean the boot record. No luck.. This is really getting frustrating for me and somewhat I'am sure you get that to that I won't give up. So my last resort is to ask people with a bit more programming and lib experience to solve this.

The program is called XAimer and can be downloaded from here.. I uploaded it to my host as the developer does not seem to offer it anymore.

(Direct temp download link)
http://www.ozisu.com/christemp/xaimer3.exe


Their are also 2 other programs like "Pool Station" and "Pool Buddy" which seem to have the same interface and same deal with the 7Day trial period.

Download link for pool station is:

http://www.stationsoftware.com/pool/index.html

and pool buddy is:

http://www.playbuddy.com/download/PBudYSetup.exe


I also tried both of these with the same method however still got the same result getting the "Trial expired screen". I would say that xaimer and poolstation copied the coding of Pool Buddy or even they are the same developers. Please do not post links to cracks as I have tried them all and do not work unless you know a link that is 100% legit.

If you find a solution or maybe point me in a direction to solve this myself it will be most appreciated. Can't offer you fame or fortune but host space, I am into music production so happy to send production softwares, plugins and even post on cd 20GB of samples.

Preferably email me your results to chris_schumann1982@yahoo.com.au or reply here.

Thank you for your time.

Kind regards,

Chris






Logged
nebu10uz
Sr. Member
****
Offline Offline

Posts: 368



View Profile WWW
« Reply #1 on: July 25, 2007, 11:17:53 PM »


Sorry buddy, I don't  think anybody here is going to help you. EH-Net is dedicated to ethical hacking, security, defense and etc. But no cracking here  Wink especially for a trial version software. If you want to continue to use the prog, I recommend that you buy it.
« Last Edit: July 25, 2007, 11:20:43 PM by blackazarro » Logged

Security+, OSCP, CEH
boney
Jr. Member
**
Offline Offline

Posts: 61



View Profile
« Reply #2 on: July 26, 2007, 10:43:16 AM »

hey brother its EHnet.

im with blackazarro

Lets make EHnet a better source of information, rather than a resource for cracking codes.

In case i get any info, i'll PM u !
Logged

C|EH

All my life I wanted a computer...
Now I want my life back !
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« Reply #3 on: July 26, 2007, 01:58:13 PM »

Should I remove this topic or leave it as an example of the type of information we don't want?

Hardvibes,

Although we agree with your desire to learn all you can about how a program works, we can't offer help in this matter. If you have any security questions, I'm sure you'll find a wealth of info on this site. Thanks for understanding.

Boney,

I appreciate your willingness to help other members, but please don't use our PM system or offer to help in these matters on the site. It makes people think that if they ask enough times or push the members, that they will eventually help.

So I agree with you and blackazarro - let's not make this a site for cracking legitimate programs.

Thanks,
Don
Logged

CISSP, MCSE, CSTA, Security+ SME
boney
Jr. Member
**
Offline Offline

Posts: 61



View Profile
« Reply #4 on: July 26, 2007, 02:53:22 PM »

Yes chief !
Logged

C|EH

All my life I wanted a computer...
Now I want my life back !
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« Reply #5 on: July 26, 2007, 03:04:05 PM »

 Grin
Logged

CISSP, MCSE, CSTA, Security+ SME
hardvibes
Newbie
*
Offline Offline

Posts: 4


View Profile
« Reply #6 on: July 26, 2007, 05:15:44 PM »

No problems guys. Thanks for the info though.

Maybe I should rather refrais my question to

Due to security perposes, how can I find out what a program creates and writes in a registar during installation.
Logged
nebu10uz
Sr. Member
****
Offline Offline

Posts: 368



View Profile WWW
« Reply #7 on: July 27, 2007, 02:15:31 AM »


Hey Don, IMO, I think should leave this post. It's a good example for others to see.

Hmmm... hardvibes rephrased the question. Don, what should we do here? Should hardvibes create a new post with his new question?
Logged

Security+, OSCP, CEH
What90
Full Member
***
Offline Offline

Posts: 120


View Profile WWW
« Reply #8 on: July 27, 2007, 05:13:47 AM »

Don, my vote is to remove this. It's well out of the ethical boundaries

Is it just me or is this thread reminiscent of the dead parrot sketch?
“But it a dead parrot!” “Not it not, it's just resting…”  http://www.youtube.com/watch?v=2H6DSoqZz_s

Once a dead parrot, always a dead parrot.  Grin
Logged

hardvibes
Newbie
*
Offline Offline

Posts: 4


View Profile
« Reply #9 on: July 28, 2007, 07:35:32 AM »

Iam sure I excused myself upfront pointing out I am new here and this might be in the wrong forum/section. I appologised upfront.

Feel free to delete it and if happy with my reformulation I rather like to dicuss this problem. Rather than posting Should or not, and yes or no and I am so smart lets post a link from an old Monty Python sketch which hardly has anything todo with my actuall question and if it somewhat should say that my post is dead than sorry they have been 8 replys and a post cannot die.

a code cannot die in the correct form only life is. if your unsure what that really means than here.

LIFE:
the condition that distinguishes organisms from inorganic objects and dead organisms, being manifested by growth through metabolism, reproduction, and the power of adaptation to environment through changes originating internally.

DEATH:
the act of dying; the end of life; the total and permanent cessation of all the vital functions of an organism.


but like i said i rather would like to discuss how a program can create (in my point of view) a untracable entry/file. *Above program is onyl an example.

Regards

Logged
boney
Jr. Member
**
Offline Offline

Posts: 61



View Profile
« Reply #10 on: July 28, 2007, 01:22:08 PM »

i dont think we should vote to remove this post.

Well, it is an good example for other members, only if they see this post here without any replies to exploit the games or the codes and hardvibes did already apologize for asking the question.

There are millions out there who dont understand the basic difference between a hacker and the craker. So when we get questions like this, its an opportunity for us to educate them that v r hackers, ethical hackers and not blackhats.
Logged

C|EH

All my life I wanted a computer...
Now I want my life back !
hardvibes
Newbie
*
Offline Offline

Posts: 4


View Profile
« Reply #11 on: July 29, 2007, 07:19:57 PM »

Gee. not to sure what to say now.. I am a forum owner myself and been running it for 7 years and see these kind of posts to often. Someone asks in the wrong section or a wrong question everyone else just hijacks the posts and just complete noonces comes out of it.

Please either delete my innital ask question and we should rename it "Lets vote. Post stay or go" we should also insert a poll along with it... jada jada jada.

I know the difference between a hacker and a cracker...

Let me formulate my whole question (One last time) so someone actually instead of hijacking this post rather is interested in helping me.. Here it goes:


Hi all, I am a hot 25 year old blonde from california.. My cup size is DD and I love computer hackers.. However Iwould love to create a program that creates untraceable files during installation so i can get information for my hacking bennefits. If you can provide an asnwer to my question you will win a date with me..


Does this help at all??
Logged
Kev
Guest
« Reply #12 on: August 06, 2007, 03:49:27 PM »

My standard response to this kind of question is, if you really like the program then don’t pay for it and don’t rip it off.  Why not take the time to learn programming and write your own. Usually aimbot programs are not that complex any way.  Who knows, if the program comes out nice, you might even try and sell it for cheaper than your competitor and make a little money. If you go this route you will learn so much more and feel better about yourself in the long run.  Also, it’s getting harder to defeat trial period programs. This is really a case of cat and mouse. It used to be very easy way back in the day, but now the better companies are writing it in the code in such a way and with online authentication makes using a simple keygen or registry change, etc.. not effective.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.087 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.