ppi less undetectable... i think (look)

tripphxc

Power Member
Joined
Mar 23, 2008
Messages
511
Reaction score
191
well, i tryed doing something that some people may have of tryed doing... and that is trying to make the ppi installer less undetectable or completly undetectable


well... this is how far i have gotten but not sure if it will work cause im assuming it may of messed up the whole ppi.exe file.


but take a look



this is the waverevenue ppi exe


This is the orginal file



File: wr-1-1671.exe
Status: INFECTED/MALWARE
MD5: e783d15381bacf8afd5d2ae0c9023e28
Packers detected:
Bit9 reports: File not found

Scan taken on 29 Mar 2008 21:52:03 (GMT)
A-Squared
Found nothing

AntiVir
Found TR/Crypt.ULPM.Gen

ArcaVir
Found Trojan.Downloader.Small.Tnt

Avast
Found Win32:Small-JMH

AVG Antivirus
Found Downloader.Agent.15.A

BitDefender
Found Trojan.Retapu.D

ClamAV
Found nothing

CPsecure
Found nothing

Dr.Web
Found Trojan.DownLoader.54163

F-Prot Antivirus
Found nothing

F-Secure Anti-Virus
Found Trojan-Downloader.Win32.Small.tnt

Fortinet
Found nothing

Ikarus
Found Virus.Win32.Small.JMH

Kaspersky Anti-Virus
Found Trojan-Downloader.Win32.Small.tnt

NOD32
Found Win32/TrojanDownloader.Small.IAW

Norman Virus Control
Found nothing

Panda Antivirus
Found nothing

Rising Antivirus
Found nothing

Sophos Antivirus
Found Mal/DownLdr-O

VirusBuster
Found nothing

VBA32
Found nothing
Now this is the edit file of the waverevenue ppi.exe



File: wr-1-1671.exe
Status: INFECTED/MALWARE
MD5: e783d15381bacf8afd5d2ae0c9023e28
Packers detected: -
Bit9 reports: File not found



Scan taken on 29 Mar 2008 21:54:58 (GMT)

A-Squared
Found nothing

AntiVir
Found nothing

ArcaVir
Found Trojan.Downloader.Small.Tnt

Avast
Found nothing

AVG Antivirus
Found Downloader.Agent.15.A

BitDefender
Found nothing

ClamAV
Found nothing

CPsecure
Found nothing

Dr.Web
Found Trojan.DownLoader.54163

F-Prot Antivirus
Found nothing

F-Secure Anti-Virus
Found nothing

Fortinet
Found nothing

Ikarus
Found nothing

Kaspersky Anti-Virus
Found nothing

NOD32
Found nothing

Norman Virus Control
Found nothing

Panda Antivirus
Found nothing

Rising Antivirus
Found nothing

Sophos Antivirus
Found nothing

VirusBuster
Found nothing

VBA32
Found nothing




Notice how the edited ppi was only detected by three a/v programs....



any advice... think this would work...?


thanks
 
So how did you end up doing this?

i will eventullay tell.... im sure some other members know how....


i just remembered back from my hacking days... i always did this to make my virus/trojan undetectable... and it still worked so thats why i think it may work but then again.... im sure a trojan virus is different then a ppi installer
 
but I assume ZoneAlarm has a lot of users
 
Another list of A/V programs with the edited file


Some of the A.V progs are listed in the above (first post)



Antivirus Version Last Update Result
AhnLab-V3 2008.3.29.0 2008.03.29 -
AntiVir 7.6.0.78 2008.03.28 -
Authentium 4.93.8 2008.03.29 -
Avast 4.7.1098.0 2008.03.29 -
AVG 7.5.0.516 2008.03.29 Downloader.Agent.15.A
BitDefender 7.2 2008.03.29 -
CAT-QuickHeal 9.50 2008.03.28 -
ClamAV 0.92.1 2008.03.29 -
DrWeb 4.44.0.09170 2008.03.29 Trojan.DownLoader.54163
eSafe 7.0.15.0 2008.03.18 -
eTrust-Vet 31.3.5653 2008.03.29 -
Ewido 4.0 2008.03.29 -
FileAdvisor 1 2008.03.29 -
Fortinet 3.14.0.0 2008.03.29 -
F-Prot 4.4.2.54 2008.03.28 -
F-Secure 6.70.13260.0 2008.03.29 -
Ikarus T3.1.1.20 2008.03.29 -
Kaspersky 7.0.0.125 2008.03.29 -
McAfee 5262 2008.03.28 -
Microsoft 1.3301 2008.03.28 -
NOD32v2 2984 2008.03.29 -
Norman 5.80.02 2008.03.28 -
Panda 9.0.0.4 2008.03.29 -
Prevx1 V2 2008.03.29 Generic.Malware
Rising 20.37.51.00 2008.03.29 -
Sophos 4.28.0 2008.03.29 -
Sunbelt 3.0.978.0 2008.03.18 -
Symantec 10 2008.03.29 -
TheHacker 6.2.92.258 2008.03.29 -
VBA32 3.12.6.3 2008.03.25 -
VirusBuster 4.3.26:9 2008.03.29 -
Webwasher-Gateway 6.6.2 2008.03.29 Trojan.Crypt.ULPM.Gen



Additional information
File size: 82944 bytes
MD5: e783d15381bacf8afd5d2ae0c9023e28
SHA1: abda14c0bf9915888e870c9af05815f40bff3c25
PEiD: -
 
The problem is you didn't check it with the biggest two...Norton and McAfee (they even come bundled with tons of computers). Also I believe AVG might be number three which caught it. I'm surprised Kapersky and NOD32 didn't catch it, a lot of people swear by it. I know you don't need every install to work, but the top two Norton and McAfee have a large share of installs. They are worth testing on.
 
Are you manually editing the .exe to change the filesize & MD5, to make it less detectable? If so, Nova pretty much took the question right out of my mouth in this post.
 
im guessing your cutting the file in half with a hex editor and saving both halves to find out which contains the trojan signature, and then repeating the process until you find the exact 4 bytes that contain the signature and editing them. I did this with the waverevenue exe and made it undetetable to a lot of anti viruses, you've just gotta be careful and make sure the exe still actually works after you've edited it!
 
im guessing your cutting the file in half with a hex editor and saving both halves to find out which contains the trojan signature, and then repeating the process until you find the exact 4 bytes that contain the signature and editing them. I did this with the waverevenue exe and made it undetetable to a lot of anti viruses, you've just gotta be careful and make sure the exe still actually works after you've edited it!



sounds good =]
 
is their anyway i can test out this edit ppi installer like a self test... instead of actullay binding it to a software and uploading...

thanks
 
is their anyway i can test out this edit ppi installer like a self test... instead of actullay binding it to a software and uploading...

thanks

VMWare Workstation or Microsoft Virtual PC '07. PM me for details.
 
What do you mean saying they will report it? Where and why is it bad?


Meaning, they may and will send it to antivirus programmers/creators so they will be aware of it
 
Little update:


The edited ppi installer seems to be working... just uploaded a torrent and got 2 sales =]
 
Back
Top