Forums: How To Trick Anti-virus Systems .... - Forums

Jump to content

  • (5 Pages)
  • +
  • 1
  • 2
  • 3
  • 4
  • Last »
  • You cannot start a new topic
  • You cannot reply to this topic

How To Trick Anti-virus Systems .... Makeing things undetectable...

#16 User is offline   mrBob 

  • Sergeant First Class
  • Icon
  • Group: Specialist
  • Posts: 321
  • Joined: 12-August 03

Post icon  Posted 24 December 2003 - 06:12 AM

nice tut m8!!
upx is a great tool
nice info
0

#17 User is offline   Cyrus 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 65
  • Joined: 15-December 03

Posted 24 December 2003 - 07:25 AM

Nice tutorial :=
Theres another fine packer called Cexe
0

#18 User is offline   absolution 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 41
  • Joined: 22-October 03

Posted 24 December 2003 - 08:33 AM

This tutorial is kinda pointless now, Every major AV has got UPX tagged.
0

#19 User is offline   GhostCow 

  • Sergeant First Class
  • Icon
  • Group: Members
  • Posts: 345
  • Joined: 20-September 03

Posted 24 December 2003 - 10:15 AM

FSG is a good packer, but its very buggy...
i recommend the UPX/morphine combo, it worx every time...
here it is for yall...
http://www.websamba..../Morphine12.rar
0

#20 User is offline   jimmy 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 135
  • Joined: 21-December 03

Posted 24 December 2003 - 10:23 AM

there are more and better ways to do the job. hexediting and stuff ...
0

#21 User is offline   zero-maitimax 

  • Sergeant First Class
  • Icon
  • Group: Members
  • Posts: 309
  • Joined: 16-December 03

Posted 24 December 2003 - 04:15 PM

jimmy, on Dec 24 2003, 06:23 PM, said:

there are more and better ways to do the job. hexediting and stuff ...

that does the tool do aphex fcp

is change crc32 md5 ad byts it make a complet diffrent program
0

#22 User is offline   passi 

  • Sergeant First Class
  • Icon
  • Group: Members
  • Posts: 301
  • Joined: 09-September 03

Posted 25 December 2003 - 04:55 AM

great tuorial. thanks a lot for it
0

#23 User is offline   Double-=V=- 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 90
  • Joined: 22-September 03

Posted 25 December 2003 - 01:06 PM

Kaspersky detects all these methods. If you add 200 bytes pack it, scramble it, bind it, use aphex fcp it still detects it :)
0

#24 User is offline   AlessandroIT 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 48
  • Joined: 07-September 03

Posted 25 December 2003 - 03:50 PM

I've tried to Patch with upx hxdef0.8.4...It not work..

Som1 can tell me about patch of this rootkit?? :rolleyes:
0

#25 User is offline   r00tless 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 29
  • Joined: 11-August 03

Posted 25 December 2003 - 04:16 PM

Great Tutorial

Thanks man!
0

#26 User is offline   zero-maitimax 

  • Sergeant First Class
  • Icon
  • Group: Members
  • Posts: 309
  • Joined: 16-December 03

Posted 25 December 2003 - 04:48 PM

Double-=V=-, on Dec 25 2003, 09:06 PM, said:

Kaspersky detects all these methods. If you add 200 bytes pack it, scramble it, bind it, use aphex fcp it still detects it :)

i olso use avp/kavp

well they will not detected with this that's why it's very nice :D
0

#27 Guest_uk-nutta_*

  • Group: Guests

Posted 25 December 2003 - 06:55 PM

What a load of cack if u ask me, but then thats my opinion. Dont mind me folks i just watch :), yes i'm another one of those pesky watchers.
0

#28 User is offline   matiano 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 59
  • Joined: 21-September 03

Posted 29 December 2003 - 03:23 PM

for KAV undetected must use the...

- EOP (change entrypoint)
- NOP (put asm code 90= no operation,4time after the entrypoint from file)

... method and have fun :D
0

#29 User is offline   GhostCow 

  • Sergeant First Class
  • Icon
  • Group: Members
  • Posts: 345
  • Joined: 20-September 03

Posted 29 December 2003 - 03:57 PM

that fcp loox good!

edit: no, it sucks... f*cked up my pe...
0

#30 Guest_Hexboy_*

  • Group: Guests

Posted 29 December 2003 - 06:00 PM

I've had luck with hexediting / scrambling (when possible). UPX is pretty well known aye.
0

  • (5 Pages)
  • +
  • 1
  • 2
  • 3
  • 4
  • Last »
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting