Jump to content

simple technique to Lock File


mary
 Share

Recommended Posts

I want to lock file using the same technique as Panda-USB-Vaccine .

It seams that this technique modify FS attributes by editing the file in hex mode.

I used winhex tools to edit the USB sector as shown on 'autorun.gif' file.

as you can notice that the actual attribute of 'autorun.inf' is '20' of hex value,

After you alter from '20' to 'E5' and saved, the 'autorun.inf' file cannot be deleted,

or contents of file cannot be view by others and cannot be autorun also, it just act as

a dummy autorun file.

You can reset back from 'E5' to '20' by winhex.

I used this method to protect my USB drive from autorun virus.

So my question is : how to do that with autoit ?

Thanks

post-16143-12713411922765_thumb.gif

Edited by mary
Link to comment
Share on other sites

  • Moderators

mary,

how to do that with autoit ?

By using binary mode. :(

Open the file in binary mode (16 + whatever else you want) and read the contents. You get a string beginning "0x" followed by the hex bytes. Change the bytes you want using the string functions and then save it again.

I sometimes find that using Binary to force the contents into a binary variant before saving helps - once in a while AutoIt has begun believing that it is dealing with a string. :)

M23

Public_Domain.png.2d871819fcb9957cf44f4514551a2935.png Any of my own code posted anywhere on the forum is available for use by others without any restriction of any kind

Open spoiler to see my UDFs:

Spoiler

ArrayMultiColSort ---- Sort arrays on multiple columns
ChooseFileFolder ---- Single and multiple selections from specified path treeview listing
Date_Time_Convert -- Easily convert date/time formats, including the language used
ExtMsgBox --------- A highly customisable replacement for MsgBox
GUIExtender -------- Extend and retract multiple sections within a GUI
GUIFrame ---------- Subdivide GUIs into many adjustable frames
GUIListViewEx ------- Insert, delete, move, drag, sort, edit and colour ListView items
GUITreeViewEx ------ Check/clear parent and child checkboxes in a TreeView
Marquee ----------- Scrolling tickertape GUIs
NoFocusLines ------- Remove the dotted focus lines from buttons, sliders, radios and checkboxes
Notify ------------- Small notifications on the edge of the display
Scrollbars ----------Automatically sized scrollbars with a single command
StringSize ---------- Automatically size controls to fit text
Toast -------------- Small GUIs which pop out of the notification area

 

Link to comment
Share on other sites

@Melba23, he's patching the attribute of file entry in the FAT directory, not the file itself.

@Mary, this may work, as long as no tool will enforce FAT conventions. I believe this trick is non standard and could cause deception in some circunstances with conforming software. Setting System and Read-Only bits is fine, but bits 7 & 6 are reserved and undefined.

You should be able to set System and Read-Only bits with FileSetAttrib but I doubt it would allow you to patch undefined bits. BTW, I also doubt such a simple tactics will stop a determined malware. That's security theatre IMO.

Edited by jchd

This wonderful site allows debugging and testing regular expressions (many flavors available). An absolute must have in your bookmarks.
Another excellent RegExp tutorial. Don't forget downloading your copy of up-to-date pcretest.exe and pcregrep.exe here
RegExp tutorial: enough to get started
PCRE v8.33 regexp documentation latest available release and currently implemented in AutoIt beta.

SQLitespeed is another feature-rich premier SQLite manager (includes import/export). Well worth a try.
SQLite Expert (freeware Personal Edition or payware Pro version) is a very useful SQLite database manager.
An excellent eBook covering almost every aspect of SQLite3: a must-read for anyone doing serious work.
SQL tutorial (covers "generic" SQL, but most of it applies to SQLite as well)
A work-in-progress SQLite3 tutorial. Don't miss other LxyzTHW pages!
SQLite official website with full documentation (may be newer than the SQLite library that comes standard with AutoIt)

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...