Forums: Ways To Make Files Undetected Without Source Code? - Forums

Jump to content

  • (4 Pages)
  • +
  • 1
  • 2
  • 3
  • 4
  • You cannot start a new topic
  • You cannot reply to this topic

Ways To Make Files Undetected Without Source Code?

#16 User is offline   crafty 

  • Private
  • Icon
  • Group: Members
  • Posts: 12
  • Joined: 28-March 04

Posted 17 January 2005 - 08:41 PM

ive found PC Guard For Win32 or PC Guard for DOS, works the best...

:D

beats all AV in one hit...
No graphics in signatures. Read the rules. -Ryan
0

#17 User is offline   herman2k 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 41
  • Joined: 29-December 03

Posted 20 January 2005 - 02:23 PM

Spiffypat, on Jan 18 2005, 01:54 AM, said:

Wow, very nice list you got there. I think going in and hexing the detected part is pretty easy, It only takes me 4-5 min to do a server per AV, and works 95% of the time.

I think u dont know what realy up ;)
Your hexing method is not more sure.
Maybe AVs same Norton :D

Some Avs (example KAV) changing by famous RATs (bifrost) the signature after updates.

And why change same AVs the signature,
because lot of people use the Hex method, (before avpoffset,ok not more work)and today like offsetfinder AVdevil.

And second, not all Signatures can you easy change.i mean same signatures are hard in code and when you change this... the file is then broken.

And your Hex Method does not 95% work!


btw:nice undetected thread from here

best regards

herman2k
0

#18 User is offline   Xion 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 38
  • Joined: 30-November 03

Posted 20 January 2005 - 02:50 PM

crafty, on Jan 18 2005, 04:41 AM, said:

ive found PC Guard For Win32 or PC Guard for DOS, works the best...

:D

beats all AV in one hit...

Do you have the serial for this soft ?

WARNED FOR THE LAST TIME ....read the rules account disabled for 10 days for serial request
0

#19 User is offline   lev 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 49
  • Joined: 10-October 04

Post icon  Posted 21 January 2005 - 09:34 AM

Pseudonym, on Jan 11 2005, 06:43 AM, said:

Just wondering what are all the ways to make a file undetected without the source?


Here are some

- Packing
- Binding
- Crypting
- Hex modifying
- Packing, then removing the packers headers.
- Changing the entry point.
- Using something like code pervertor which can replace instructions
in the file with other instructions which will do the same thing.

Can anybody else think of any other methods?


Here's some good sites for this:

hxxp://www.exetools.com/
hxxp://protools.cjb.net/
hxxp://unpack.cjb.net/
hxxp://yodap.cjb.net/

Another way to get close to the same goal is to make the file difficult to delete ;)
0

#20 Guest_Jay_*

  • Group: Guests

Posted 21 January 2005 - 09:38 AM

We will not tolerate your request for serials. Your posting ability has been disabled and I want to know why you broke GSO rules.

Just remember registration is closed so if you value your membership follow the rules.
0

#21 User is offline   matiano 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 59
  • Joined: 21-September 03

Posted 21 January 2005 - 11:42 AM

1. For Macafee is changing the recource section good.

2. For KAV ist good the NOP method with changing the entrypoint.

3. Rebasing the server file is an other good method

4. For Norton, we dont must speak about that :D

another good link

When somebody want know more about make undetected, ive a top-secret link about lot of undetected methods they can write me a PM!... im free4chat :)

btw: somebody know how i can make files undetected for Ewido Security Suite without crypter.

Who this can is some one the best!

best regards,

matiano
0

#22 User is offline   fulvioo 

  • Staff Sergeant
  • Icon
  • Group: Specialist
  • Posts: 251
  • Joined: 27-March 04

Posted 21 January 2005 - 12:05 PM

Top secret link?

Why you say that, share the knowledge you know... thats the propouse of forums, isnt?


This is a nice tutorial made by IDESpinner

http://www.governmen...ndpost&p=104148
0

#23 User is offline   matiano 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 59
  • Joined: 21-September 03

Posted 21 January 2005 - 01:51 PM

The reason why i dont make the link puplic is,
because when the website master see that, that i post the link here,
maybe he dont make more puplic his secrets!

His website is for the AV producer :)
0

#24 User is offline   AdmiralB 

  • Sergeant First Class
  • Icon
  • Group: Members
  • Posts: 312
  • Joined: 24-December 03

Posted 21 January 2005 - 05:47 PM

i find using a combination of packing and perhaps crypting or binding best to avoid detection
0

#25 User is offline   Progressor 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 72
  • Joined: 14-December 03

Posted 23 January 2005 - 12:58 AM

Quote

2. For KAV ist good the NOP method with changing the entrypoint.


No, it doesn't work for KAV. You better add section to file or try opcode substitute.
0

#26 User is offline   Lie8 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 40
  • Joined: 05-October 04

Posted 27 January 2005 - 12:34 AM

hmmm .... the pcguard method works .... but the size gets bigger of the server .... not tested much but it skips well .... thnx for the info.
0

#27 User is offline   matiano 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 59
  • Joined: 21-September 03

Posted 09 February 2005 - 09:15 AM

Progressor, on Jan 23 2005, 08:58 AM, said:

Quote

2. For KAV ist good the NOP method with changing the entrypoint.


No, it doesn't work for KAV. You better add section to file or try opcode substitute.

The NOP method does work with standart scan KAV!
0

#28 User is offline   Lie8 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 40
  • Joined: 05-October 04

Posted 09 February 2005 - 09:34 AM

@matiano,

pmed u twice ... can u pls PM me the top secret link of urs or add me in MSN .... thnx inadvance.

0

#29 User is offline   matiano 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 59
  • Joined: 21-September 03

Posted 10 February 2005 - 02:16 AM

Lie8, on Feb 9 2005, 05:34 PM, said:

@matiano,

pmed u twice ... can u pls PM me the top secret link of urs or add me in MSN .... thnx inadvance.


sorry i dont trust u because u have only 2 postings :)
0

#30 User is offline   jase_uk 

  • Private
  • Icon
  • Group: Members
  • Posts: 13
  • Joined: 13-October 04

Posted 10 February 2005 - 02:41 PM

lol
I im still working on making my file UD.

I have a program called stealth tools 2 but its not much help to be honest.

I might try and use some software protecters, but i mean if anyone has any good ideas then let us know.

I tryed cutting up the server and scanning each little bit, but not a single bit of it came as a virus, so i dunno what was going on there.

i mean if anyone knows anything about hex editing then let us know. :P
0

  • (4 Pages)
  • +
  • 1
  • 2
  • 3
  • 4
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting