making the keylogger undectable again

No explicit questions like "how do I hack xxx.com" please!
Post Reply
User avatar
skywing
Newbie
Newbie
Posts: 4
Joined: 25 Jan 2008, 17:00
16

making the keylogger undectable again

Post by skywing »

so, i was able to get a keylogger undetectable by kaspersky and AVG (by chaging the keyloggers hex values) until somedays ago, now another string gets detected by AVG, but its a single value, C0, in the middle of mutiple 00, im a newbie so i dont know what to do now, any ideas? heres an image:

Image

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Post by ayu »

Well it's hard to say exactly what "method" AVG is using to detect the files, as in what parts of the files it is using as the signature for it.

You might want to try and "scramble" the file, or add bytes to it to try to make it undetectable again.

Either way, try experimenting with it, like remove that byte that you marked. make backups of the original and play around ^^ that's what i would have done at least.
"The best place to hide a tree, is in a forest"

User avatar
skywing
Newbie
Newbie
Posts: 4
Joined: 25 Jan 2008, 17:00
16

Post by skywing »

when i first started chaging the hex values i only had in mind making it UD for kaspersky, after some weeks I made it undetactable for AVG for "scrambling" the string detected by kaspersky and the one by AVG, now, after some scans this happened, a new string is detected, the "C0", I'm trying to "scramble" but everytime I change "C0" from it place the keylogger no longer works = /

User avatar
CommonStray
Forum Assassin
Forum Assassin
Posts: 1215
Joined: 20 Aug 2005, 16:00
18

Post by CommonStray »

have you attempted not using hex and disassembling the keylogger, and perhaps running it in a debug mode so it steps through every line?

User avatar
skywing
Newbie
Newbie
Posts: 4
Joined: 25 Jan 2008, 17:00
16

Post by skywing »

i dont know how to do that... :oops:

User avatar
Gogeta70
^_^
^_^
Posts: 3275
Joined: 25 Jun 2005, 16:00
18

Post by Gogeta70 »

Download a program called ollydbg and use google to find a tutorial for it.
¯\_(ツ)_/¯ It works on my machine...

User avatar
skywing
Newbie
Newbie
Posts: 4
Joined: 25 Jan 2008, 17:00
16

Post by skywing »

i've been using W32dasm the thing is, the "C0" offset is less than 1000, and W32dasm only shows offsets starting at 1000

Post Reply