File splitter to split our servers to find out where the virus signature is to modify it.
Now go grab the server you want to edit mine is going to be a Spyrex keylogger server you can use any keylogger server like neptune,ardamax,elite..etcetc.
You result may vary on AV your using.
Okay now once you have placed the server in a file lets scan it.
OMG it got caught
In
the file splitter browse to the server you want to split and choose
Custom size. Now it tells me that this server is exactly 53,495 bytes
and I want to split it into 4 pieces. So I go to Calc and divide it by 4
now place the number you got after dividing it and place it in the
splitter custom size box like I have at the bottom. Now click on Split.
once you made new folder named 3 open up file splitter and browse to
the file that got detected mine was test.exe.3.3 and pick the output
directory to the folder we just made witch was the folder named 3.
browse to the new folder and scan the new files we split. As you can
see test.exe.3.3.4 was detected so I'm gonna make a new folder and name
it 4.
Now lets scan the new files and see witch got detected ocne we find it open it up with the HEX editor and see if its still to big to figure out what we need to change.
the virus signature is in here don't get scared its not that hard now
my method of figuring it is looking for something that stands out or
guesssing. All you really have to do is change a letter from capital to a
lower case one now what worked for me was changing D to a lower case
from the word DLLHOOKSTRUCT.
Now compiling I will show you one example and you can figure out the rest by your own.
Now you see the splitter icon inside your folder click on it and it will recompile the file.
Now
once you made that file copy it and go back one directory and past it
then it will ask you to replace it click yes and keep doing this till
you go back to first directory. And your done.
0 nhận xét:
Post a Comment
Click to see the code!
To insert emoticon you must added at least one space before the code.