Warden Scan Info menu

Shout-Out

User Tag List

Page 2 of 2 FirstFirst 12
Results 16 to 23 of 23
  1. #16
    Evieh's Avatar Contributor
    Reputation
    92
    Join Date
    Aug 2006
    Posts
    191
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Warden doesn't seem active for me, memory is allocated that matches Warden size from warden mapping code however the memory is VirtualFree'd right after. Why does this happen? It has been like this ever since warden started being 'active'.

    Warden Scan Info
  2. #17
    Beaving's Avatar Sergeant
    Reputation
    21
    Join Date
    Apr 2010
    Posts
    67
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Warden module is.copied to.various locations. Also it wont exist there long, because it.will.scan a bit and then it will get freed. It repeats that process to random locations.

  3. #18
    Evieh's Avatar Contributor
    Reputation
    92
    Join Date
    Aug 2006
    Posts
    191
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Beaving View Post
    Warden module is.copied to.various locations. Also it wont exist there long, because it.will.scan a bit and then it will get freed. It repeats that process to random locations.
    Ah, you're right. I never logged the calls long enough to actually see them being called multiple times.

  4. #19
    TheArkanaProject's Avatar Private
    Reputation
    1
    Join Date
    Jun 2012
    Posts
    7
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Me again with another possibly silly question.

    How does warden utilize VQEx, exactly? Is it just scanning for code caves (allocated memory which shouldn't be), or doing something more complex?

    Sorry if I'm annoying with all the questions.
    Last edited by TheArkanaProject; 06-26-2012 at 09:45 PM.

  5. #20
    DrGonzo's Avatar Contributor
    Reputation
    145
    Join Date
    Jun 2009
    Posts
    132
    Thanks G/R
    0/60
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Shot in the dark, but checking memory pages set to executable?

  6. #21
    TheArkanaProject's Avatar Private
    Reputation
    1
    Join Date
    Jun 2012
    Posts
    7
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Also, as far as the "fake" scans go, I think they might be scanning various system functions (checking to see if, say, virtualqueryex has been tampered with), although I can't prove it. Would certainly make sense for them to want to watch them.

  7. #22
    anonym0use's Avatar Corporal
    Reputation
    8
    Join Date
    Jun 2012
    Posts
    20
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Where Warden called from? Does it run in separate thread? Is it possible to do memory swapping in Win kernel thread manager?

  8. #23
    Beaving's Avatar Sergeant
    Reputation
    21
    Join Date
    Apr 2010
    Posts
    67
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Called from ff 95 90 fb ff ff 84 c0 74 08 8b 0d

Page 2 of 2 FirstFirst 12

Similar Threads

  1. What does warden scan for?
    By Dovah in forum World of Warcraft General
    Replies: 1
    Last Post: 04-08-2014, 07:16 PM
  2. Hook Warden Scan
    By demonguy in forum WoW Memory Editing
    Replies: 15
    Last Post: 02-28-2013, 11:03 AM
  3. Warden Scan Info 1.0.3
    By Beaving in forum Diablo 3 Memory Editing
    Replies: 11
    Last Post: 07-15-2012, 06:31 AM
  4. Warden Scanning for Viruses???
    By GliderPro in forum WoW Memory Editing
    Replies: 6
    Last Post: 09-05-2009, 08:25 AM
All times are GMT -5. The time now is 12:36 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2025 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Google Authenticator verification provided by Two-Factor Authentication (Free) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search