Jump to content
Tuts 4 You

Recommended Posts

Posted

Hi all please help me to virus reverse engineering and find virus source code Through

reverse engineering

Posted

Alarm bells ringing... Give one good reason please...

Posted

Only for learn !

and make anti virus

Posted

Its not usuallty that simple, first you usually have to be able to reverse engineer very well then you move onto viruses and malware.. This is typical and done to stop script / virus kiddies getting new viruses and malware

Posted

do you can put tutorial from virus reverse engineering here for all?hypocrite.gif

Posted

Nope i cant, have you actually even done reverse engineering before?, cos writing an anti virus (your plan..right?) is not that easy..drivers are involved etc and requires a fair amount of technical knowledge and expertise..

  • Like 1
  • 2 weeks later...
Posted

Virus are like other programs with malicious intructions so download a Virus (not hard),

*Load it on Ollydbg Vmware XP machine (Just to be safe and use DeepFreeze )

*Donwnload RegMon and FileMon to see what is written to your computer at opening .exe

*Check that file registry and file change on olly dbg most of virus modified registry to autostart and change explorer.exe

Writte your advances and move on more complicated Virus like Fake Antivirus

Posted (edited)

Hi all please help me to virus reverse engineering and find virus source code Through

reverse engineering

Not sure if I should do this,but .....


http://www.opensc.ws/trojan-malware-samples/http://zeltser.com/combating-malicious-software/malware-sample-sources.htmlhttp://www.offensivecomputing.net/

..should get you started..

edit: oh,btw.. you have to register on offensivecomputing site, and you have to state reasons why should they grant

you an access to their huge DB..

If they accept it,you will be validated and given access..

..but if that's your answer,forget about it. smile.png

Edited by Jaymz
  • Like 1
  • 1 month later...
Posted

trash olly and go with IDA..static analyses and hex dump cross-references is the only reliable way anyways. You'll also need it for RISC binaries.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...