twitter
    Find out what I'm doing, Follow Me :)
Showing posts with label Trojan. Show all posts
Showing posts with label Trojan. Show all posts

Wednesday, April 20, 2011

HOW TO MAKE A VIRUS/TROJAN UNDETECTABLE BY ANTIVIRUS....


Before we start, let me tell u one thing straight. This document is purely intended for educational purposes. I do not want anyone to use this information (or any information on this blog) to actually hack into computers or do other illegal things. So I cannot be held responsible for the acts of other people who took parts of this document and used it for illegal purposes. If you don't agree, then you are not allowed to continue to access this website...so leave this website immediately. Always remember one thing


"HACK TO LEARN, DON'T LEARN TO HACK"...


I am writing this article to inform you about how Hexing is actually done using Dsplit. Dsplit is a software used to detect virus signature. Hexing is very much important for us to evade antivirus detection. If you will learn how to bypass antivirus by hexing, you don't have to search for FUD key loggers and Trojans. You can hex files to make them FUD.

I will be using Dsplit as virus signature detector and Ice Gold Freezer as virus over here. You can use any other virus containing file you want.
Download these two files:
1. Avira antivirus (Because I've used it in tute).

2. Ice Gold Freezer and Dsplit.exe programme (used for detecting virus signature).

Fast of all. let me tell you one thing Ice Gold Freezer is detected as "SPR/Tool.Freezer.8" virus (actually malware as Avira.com) by my Avira antivirus which I use on my computer. So, I will be telling you how to bypass Avira detection for Ice Gold Freezer. So, let's start.

STEP 1: Download Avira antivirus, Dsplit and Ice Gold Freezer from links provided above. Extract Dsplit folder to desktop.

STEP 2: Scan Ice Gold Freezer.exe file you have downloaded with antivirus. My Avira says its "SPR/Tool.Freezer.8" malware. So, let's work on it.

Thursday, April 7, 2011

TOP FIVE FACEBOOK SCRIPT HACKS

The following are the top Ten Facebook hacks that can be rally fun! But sadly most of them are not working now but still you can check for your self.


1. How to Remove Annoying Facebook Advertisement
Get rid of some of the Facebook advertising and sponsored by sections with this tool.

Get it Here http://userscripts.org/scripts/show/27121

2. How to see Real Profiles from Public Pages
This script redirects to real profiles from the Facebook people pages (public profiles). There is a risk of an infinite redirect loop if not logged in, so be logged in.

Get it Here http://userscripts.org/scripts/show/27011

3. How to Undo Facebook Changes
If you hate some or all of the new Facebook changes, undo them with these scripts and use what you liked previously.

Get it Here http://userscripts.org/scripts/show/8482

4. How to View All the Photos from a Person
You can search for pictures of a Facebook member who has tight privacy settings and view all his/ her pictures without his/ her consent.

Get it Here http://userscripts.org/scripts/show/11218

5. How to Find More Friends at Facebook
Suppose some of your friends have newly joined Facebook and you didn’t even knew. Use this script and it will help you go through your friends’ friends list and find them out.

Get it Here http://www.facebook.com/applications/More_Friends/2419601767

Sunday, March 13, 2011

Speed up internet by 20%


Microsoft reserves 20% of your available bandwidth for their own purposes like Windows Updates and interrogating your PC etc

You can get it back:

Click Start then Run and type "gpedit.msc" without quotes.This opens the group policy editor. Then go to:



Local Computer Policy -->Computer Configuration --> Administrative Templates t- -> Network --> QOS Packet Scheduler and --> to Limit Reservable Bandwidth.


Double click on Limit Reservable bandwidth. It will say it is not configured, but the truth is under the 'Explain' tab i.e."By default, the Packet Scheduler limits the system to 20 percent of the bandwidth of a connection, but you can use this setting to override the default."


So the trick is to ENABLE reservable bandwidth, then set it to ZERO. This will allow the system to reserve nothing, rather than the default 20%.It works on Win 2000 as well.


Friday, February 4, 2011

Android Trojan Geinimi Steals User Data


Android Trojan Geinimi Steals User Data


Spreads via third-party Chinese App Stores packaged in games and other apps
    Though Google Android operating system is based on Linux-based kernel, it's not completely secured. In April we reported about the Mariposa botnet targeted at Android phones. Hackers have quietly sneaked in a new Trojan Horse malware - Geinimi - that spreads on Android phones via Games and other Apps, reported PC World. Kevin Mahaffey, CTO of Lookout Mobile Security that develops mobile security software said that Geinimi Trojan appears to be the first one with botnet-capabilities targeted at Android mobiles.



    Geinimi Trojan is "grafted" to work on the repackaged Apps that includes mostly games and is distributed via third-party Chinese App Store. Once the malicious Trojan packaged App is downloaded, the App asks Android phone users for a larger set of permissions than it's supposed to verify. The Trojan gains information about the phone and performs the following activities of sending data to a remote server:

    - Send location coordinates (fine location)
    - Send device identifiers (IMEI and IMSI)
    - Download and prompt the user to install an app
    - Prompt the user to uninstall an app
    - Enumerate and send a list of installed apps to the server


    All this data is sent to a command-and-control server that connects multiple domains. However, Lookout is yet to determine the true purpose of the Geinimi Trojan. Since the malware can connect to several domains and get instructions from the remove server, Lookout termed its operation very botnet-like.


    Though the Trojan spreads only through Third-Party Chinese App Store, all Android phones users must resist downloading Apps from untrusted sources. Always read and then allow the necessary permissions to the Apps. In case of any unusual behavior, get the mobile security Apps and get the mobile system checked.

    Boonana Trojan Attacks Mac OS X




    Usually spreads via messages sent on social networks like Facebook and runs in background

            Clearly, malicious code writers don't spare any platform. If you thought your Mac system wasn't going to be affected by any Trojan or malicious code, this new Boonana Trojan will make you think again. Security Firm Secure Mac has reported that new Trojan dubbed Trojan.osx.boonana.a is spreading through popular social networking sites like Facebook. In pretext of luring a video, the malicious link eventually leads to installation of malware in Mac OS X. Now users are bound to surf social networks like Facebook and others. At such social networks, the user receives message with subject "Is this you in this video?" When the user clicks on the infected link, it activates and runs Java Applet that downloads certain malicious files including an installer on the Mac OS X system. The installer launches automatically, modifies the system files and bypasses the password verification. Then the Trojan sets itself to run at startup invisibly in the background. Since the Trojan spreads by running Java Appalet, SecureMac pointed out that it can infect both Mac OS X and Windows platform. However, no specific details about how it can affect Windows were mentioned. Disabling Java in Safari, Chrome or Firefox on Mac OS X can certain help you to avoid getting your system infected. Just in case you think your Mac has been infected by Boonana Trojan, download this Removal Tool and run it on your Mac OS X.