Pull out a horse in sheepskin"

Source: Internet
Author: User

Bundling Trojans in normal programs has always been a common means of hacker intrusion attacks. Hackers often use special file bundle programs, such as EXEbind and Hammer binder, to bundle a specified Trojan program to a popular software to spread it over the network.
There are two ways to prevent file bundling attacks. Do not download and execute unreliable software programs from informal websites. Remember the file size of some common software. Once the file size changes, you can determine that the program has been bound to another program. These two methods are basically impossible for cainiao who support piracy. Therefore, only the last trick is to use a dedicated File bundle analysis tool!

I. view the file Bundle by using the MT bundle.
By analyzing the file header signature of the program, you can check whether the file is bound with a Trojan. All the programs that are bound with the trojan are in its eyes.
The MT bundle is very small and easy to use. After running the program, click the "Browse" button on the interface to browse and select the executable files to be detected in the hard disk. Then, click the "analysis" button on the interface. The bundle wizard automatically analyzes the program and displays the analysis results in the middle window. In the analysis result, we can see the file size and the number of executable headers in the file header (1 ). This analysis result is very important. In a normal program, the number of executable headers is generally one. If there are two or more executable file headers, this indicates that this file must have been bound. Be careful!

TIPS: You can also select the program analysis option on the interface. You can check the analysis "File Header". If you want to perform a comprehensive inspection by program, you can check the "input table" item again. In addition, this small software also provides an interface replacement solution. You can choose to change to Windows XP or MacOS in the drop-down list on the right.


If you encounter any suspicious program in the future, you can bind the host to identify the virus and trojan programs in the file.

2. Find out the trojan bound to the program
If you find that a program is bound with a Trojan, you can delete the program without mercy. But it happens that this program is in urgent need. What should you do? Then we can make the "Fearless Bound File Detector" program amazing.
Fearless Bound File Detector not only detects the trojan virus Bound to the program, but also clears it from the program. The usage of this tool is also very simple. After running the tool, browse and select the program or file to be detected, and then click the "Process" button on the interface to analyze the file. The analysis result is displayed soon (2 ).

The first sentence indicates the bundle and its position in the program code; the second sentence indicates the size of the bundled program file.
Now that this program is bound with a Trojan, we have to clear it. Click the "Clean File" button on the interface to bring up the warning dialog box (3), because the cleaning process may cause damage to the source program, therefore, ask if you really want to clear the bundled programs in the file. After you confirm the cleanup, you can see that the cleanup is started. Finally, you can see whether the cleanup operation is successful in the middle window (4 ). Successfully has been cleared Successfully, and now the program is clean. You can execute the program without any concerns.

The unique feature of "Fearless Bound File Detector" is that it not only detects EXE program files, but also detects images and other files in various formats, which is especially effective against image Trojans!

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.