ANTICHAT.XYZ    VIDEO.ANTICHAT.XYZ    НОВЫЕ СООБЩЕНИЯ    ФОРУМ  
Баннер 1   Баннер 2
Antichat снова доступен.
Форум Antichat (Античат) возвращается и снова открыт для пользователей. Здесь обсуждаются безопасность, программирование, технологии и многое другое. Сообщество снова собирается вместе.
Новый адрес: forum.antichat.xyz
Вернуться   Форум АНТИЧАТ > Безопасность и Уязвимости > Безопасность > Защита ОС: вирусы, антивирусы, файрволы.
   
Ответ
 
Опции темы Поиск в этой теме Опции просмотра

Hexediting
  #1  
Старый 03.10.2007, 19:59
Аватар для nikize
nikize
Новичок
Регистрация: 30.09.2007
Сообщений: 17
Провел на форуме:
31256

Репутация: 9
По умолчанию Hexediting

So basically what i know, is that antiviruses search for some specific signatures in virus. I haven't been able to find these definitions ( it took 4 hours to clear this up for myself ), but basically, the idea is simple.
You just get hex editor, then open your virus with it, and remove certain signatures, that antivirus has in its database.

unfortunately i am too inexperienced in this, and thats why i am unable to find signatures in the internet, that antivirus searches for when scanning a file, though i see many people posting hints on how to do it, but i was unable to gather any important info for doing this.

Anyway, this is probably the best way to make your virus/keylogger undetectable, only if someone knew what to delete with the hexeditor.

So if anyone knows what to delete and how, could be kind enough to enlighten me?

more info ( well the basic idea is explained in here more specifically http://community.vietfun.com/printthread.php?t=279822)

-Nikize
 
Ответить с цитированием

  #2  
Старый 03.10.2007, 20:10
Аватар для n0ne
n0ne
Постоянный
Регистрация: 01.01.2007
Сообщений: 796
Провел на форуме:
2693408

Репутация: 861


По умолчанию

There are alot of encrypting soft for such tasks. But if u want to wright your own soft i think it'll be easier with basic knowledge of Assembler and a bit of experience about encryption. For example download such public soft, encrypt any virus\trojan with it and compare to original one. Btw, i think google might help you with articles and sources of such things

In google we trust.
 
Ответить с цитированием

  #3  
Старый 03.10.2007, 20:15
Аватар для n0ne
n0ne
Постоянный
Регистрация: 01.01.2007
Сообщений: 796
Провел на форуме:
2693408

Репутация: 861


По умолчанию

Btw, i think it'd be useful for u: read books written by Kris Kaspersky.
 
Ответить с цитированием

  #4  
Старый 03.10.2007, 20:29
Аватар для nikize
nikize
Новичок
Регистрация: 30.09.2007
Сообщений: 17
Провел на форуме:
31256

Репутация: 9
По умолчанию

That book is about encryption and stuff? Is it written on English?
And guys, you can answer me in Russian, i am 100% Russian and its my mother language, but i am just having trouble writing it =P

I have a little experience in C++ and Php and Pascal, and sure i could learn them in a month or two, but i would need the keylogger ready to use as quickly as possible ( i am just lazy too )

-Nikize
 
Ответить с цитированием

  #5  
Старый 03.10.2007, 20:33
Аватар для n0ne
n0ne
Постоянный
Регистрация: 01.01.2007
Сообщений: 796
Провел на форуме:
2693408

Репутация: 861


По умолчанию

Nah, it's ok about English :P As i said you need to learn Assembler, i think basic knowledge'd be enough. Then find some sources and examine it But if u need just to encrypt things - it cost about 0.5$-1$ What do u need exactly?\

Those books are originaly in English afaik. They are about career of Kris and he sharing his knowledge about viruses and stuff.
 
Ответить с цитированием

  #6  
Старый 03.10.2007, 20:39
Аватар для nikize
nikize
Новичок
Регистрация: 30.09.2007
Сообщений: 17
Провел на форуме:
31256

Репутация: 9
По умолчанию

Well the very basic thing what everyone in this section of forum are doing, i want to make my keylogger undetectable

Are you offering a service, i would be glad to discuss about it.

BUT!
I scanned in jottis virusscan my keylogger, and only avast detected it, but when i sent it to my victim, he detected it with avira, even though in the list avira didn't detect it!
Whats the problem? Is it about Jottis engine?
 
Ответить с цитированием

  #7  
Старый 03.10.2007, 20:55
Аватар для Fugitif
Fugitif
Постоянный
Регистрация: 23.09.2007
Сообщений: 416
Провел на форуме:
1781065

Репутация: 869
По умолчанию

u can try to make it undetectable with Daemon Cyrpt
 
Ответить с цитированием

  #8  
Старый 03.10.2007, 21:00
Аватар для Piflit
Piflit
Banned
Регистрация: 11.08.2006
Сообщений: 1,522
Провел на форуме:
5128756

Репутация: 2032


Отправить сообщение для Piflit с помощью ICQ
По умолчанию

nikize that may be some proactive technologies in Avira engine (i donna exactly if they really exist), so they are detecting ur malware...

As for signatures, which are being detected by antiviruses, it's a very very private information, about of only AV developers are aware ^^

As to Russian or English language, answering in eng makes many понты=))
 
Ответить с цитированием

  #9  
Старый 03.10.2007, 21:05
Аватар для nikize
nikize
Новичок
Регистрация: 30.09.2007
Сообщений: 17
Провел на форуме:
31256

Репутация: 9
По умолчанию

Цитата:
Сообщение от Piflit  
nikize that may be some proactive technologies in Avira engine (i donna exactly if they really exist), so they are detecting ur malware...

As for signatures, which are being detected by antiviruses, it's a very very private information, about of only AV developers are aware ^^

As to Russian or English language, answering in eng makes many понты=))
you know, actually you can digg the information up from antiviruses database, some people post the information in the internet, but the site is quickly deleted.
But im sure someone knows some information, because hey, this is Russian forum, everyone here are basically hackers

Thats a good fact!

keep info coming, i appreciate this really much!
-Nikize
 
Ответить с цитированием
Ответ





Здесь присутствуют: 1 (пользователей: 0 , гостей: 1)
 


Быстрый переход




ANTICHAT.XYZ