Process Hacker and Windows discussion

 
Andy202
New User
Posts: 2
Joined: 25 Jun 2018 10:37

.xyz

25 Jun 2018 10:45

Hello!

Well, my question is simple, I'm working on searching injected auto clickers for the game I moderate, however, it's really a hard task. These guys inject a .exe or a .jar to the game, then when asking for a screenshare they delete this .exe or .jar that is named with strange names (then searching on regedit registries will not help) and delete prefetch, temp, %temp%, recent, LastActivityViewer, UserAssistViewer information. I want to know if I can use process hacker to see if any .exe or .jar used by the user can be still found in there, and how I can get to it. If more than a manner is possible, I would appreciate it.
 
User avatar
TETYYS
Contributor
Posts: 515
Joined: 23 Apr 2013 10:37
OS: Win 10 x64

Re: .xyz

30 Jun 2018 15:05

you could try searching games' memory for specific strings or byte blocks that could identify an auto clicker
 
User avatar
Controversed
Member
Posts: 14
Joined: 26 Oct 2017 13:09
OS: Windows 7 64bit
Location: France

Re: .xyz

02 Jul 2018 01:00

Mais lol
 
Andy202
New User
Posts: 2
Joined: 25 Jun 2018 10:37

Re: .xyz

03 Jul 2018 01:37

you could try searching games' memory for specific strings or byte blocks that could identify an auto clicker
The problem is that there are tons of strings, and I would have to catch the autoclicker itself to get some specific strings to search for