Register for your free account! | Forgot your password?

Go Back   elitepvpers > Coders Den > General Coding > Coding Tutorials
You last visited: Today at 05:43

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



[Howto] Scan Files | keyloggers, trojans and other maleware

Discussion on [Howto] Scan Files | keyloggers, trojans and other maleware within the Coding Tutorials forum part of the General Coding category.

Reply
 
Old   #1

 
Adroxxx's Avatar
 
elite*gold: 15
Join Date: Nov 2005
Posts: 13,021
Received Thanks: 5,324
[Howto] Scan Files | keyloggers, trojans and other maleware

▲ [HowTo] Scan files for keyloggers, trojans and other maleware ▲


This is a small HowTo and collection of links / programs, which could help you to scan files for trojans and other maleware. We have a lot of users here and some of them try to distribute trojans and keyloggers. Because of that it is very important to scan files and help the community and other members to find this infected files and ban the users.

I'll show you some ways to scan those files.


#Content:
[-]Online Virus Scan
[-]Online Sandbox
[-]Own Sandbox
[-]End


[-]Online Virus Scan


The first step before you execute an unsafe hack, is the virus scan.
Some usefull websites are:
  • *hot*

The problem is, that you can't be 100% sure that the file is clean. If the file is packed or it's an unkown/selfcoded trojan/keylogger it's difficult to find this with the most scanners.

The other problem is, that the scanners show also packed files. So if you pack your hack with themida, upx or other packers it could be possible that online scanners show it as an virus,too. That are false-positiv results. And some dll injectors were shown as suspicious files,too.

Some examples for real trojans / keyloggers are scanresults like that:
Quote:
BackDoor-AWQ.b!dk
Sober.F
Bagle.DR2
Some examples for false-positives:
Quote:
Win32/MalPackedB.suspicious
W32/Packed_RLPack.O
Suspicious file
Trojan.Win32.Packer.RLPackV1.21 (v)
You see it's not so easy to find out whats true. Some scanners show executeables packed with a packer (RLPack) as Win32/Packed_RLPack or only as Suspicious file. But other say thats a trojan: Trojan.Win32.Packer.RLPackV1.21

The best way is to google the name. If you know that RLPack is only a packer and not a trojan you can feel safer.



[-]Online Sandbox


The next step would be to analyze the file in a sandbox. There are a few online sandbox services like:
  • *hot*
  • *only flash/pdf/javascript*

To scan files with a sandbox service is a much safer. You submit your file, like in a online virus scanner. Then this file will get analyzed and you get the result. In some Services there come a text like: File is maleware/trojan or File is no maleware/trojan.
But in other scanners you get only the facts. Like what changes that file do.

Keep in Mind: A normal Hack or patched bypass exe, will never make files in your system folder or something.

Here is a sample report for an infected file:



On the Top you see a brief summary.

Autostart capabilities.
Creates files in the Windows system directory.
Performs File Modification and Destruction.


If you see this, you can be sure thats a trojan/keylogger/virus or whatever.

I know there are a lot of information and the most of you, don't understand that information. But with the time you will learn it


[-]Own Sandbox


Another way is to create an own sandbox. The best way for that is to install VMWare and an virtual system.

Emulators:

Then you need some analyzing tools here is a short list of very usefull tools:

There are some debuggers, disassemblers, hex editors, network analyzers and other usefull tools.
You should read the readme of this tools and learn to use them.




[-]End


I hope I could help you a little bit.
And one thing: It's very usefull for other members, if you post the scan results into the post. It's enougth if one person do that. But then the other people can take a look into the results and maybe see something that you didn't saw and can help to figure out, if it's a maleware or not. So if you don't understand the whole anubis scan result you post it and other people can figure it out

best regards
Adroxxx
Adroxxx is offline  
Thanks
27 Users
Old 07/07/2009, 00:31   #2



 
elite*gold: 0
Join Date: Nov 2008
Posts: 20,557
Received Thanks: 9,134
Gleich schön in meine Sektion reinpacken =)
Rikkami is offline  
Old 10/19/2009, 12:41   #3
 
elite*gold: 0
Join Date: Oct 2009
Posts: 2
Received Thanks: 0
thanks so much i get so many viruses
Fiop22 is offline  
Old 10/20/2009, 16:25   #4
 
DizzySan's Avatar
 
elite*gold: 0
Join Date: Sep 2006
Posts: 37
Received Thanks: 0
Wonderful information. I hope others read it! Thx!
DizzySan is offline  
Old 10/21/2009, 19:55   #5
 
fieser-hund's Avatar
 
elite*gold: 20
Join Date: Jun 2008
Posts: 831
Received Thanks: 218
ty
very useful information
fieser-hund is offline  
Old 04/24/2011, 00:40   #6
 
elite*gold: 0
Join Date: Apr 2011
Posts: 904
Received Thanks: 203
Wirklich schöner Thread ! Habe viel daraus mitgenommen , weiter so !


auch wenns schon was her ist...
MoRegelt is offline  
Old 01/22/2013, 20:41   #7
 
elite*gold: 0
Join Date: Oct 2011
Posts: 259
Received Thanks: 21
Sorry for bumping old thread, but this is still useful.
I have a question, about this file:

and

Hope that's enough to determine if it's clean or not! Thanks
bbq1337 is offline  
Reply


Similar Threads Similar Threads
Where to check scan files for virus
06/20/2008 - Cabal Hacks, Bots, Cheats, Exploits & Macros - 1 Replies
Hi, where can I scan my files to check whether there is virus or keylogger? thanks.
[TUT] For users that do not understand how to scan their files.
02/08/2008 - Flyff - 3 Replies
Well heya, Im doing this tut because of people that dosnt understand to scan their files when they are, downloading it from this homepage. Alrighty Then Lets Start. You have 2 choices of scanning, 1 there is. Online malware scan http://i30.tinypic.com/2zi81g1.jpg How to scan a file, alright then look on my pictures. Then you also got
Where do i go 2 scan files?
06/02/2007 - Conquer Online 2 - 3 Replies
i know viruscheif.com or something but it doesnt have many engines is there some1 i can go that has alot so i can make sure something is safe?
Protect against trojans, keyloggers
07/16/2006 - Conquer Online 2 - 1 Replies
What are u using ! and its seems to be good !



All times are GMT +1. The time now is 05:44.


Powered by vBulletin®
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2026 elitepvpers All Rights Reserved.