+ Reply to Thread
Page 1 of 2 12 LastLast
Results 1 to 10 of 14
  1. #1
    Senior Member slayer616's Avatar
    Join Date
    Dec 2007
    Location
    Earth
    Posts
    1,474

    Best AV/FW Killer + Startup!

    After reading 8 books about Windows/Processes/Threads/APIs i've found something interessting...
    In the Registrypart of a paper about Windows something about the "Image File Execution Options" Regkey was written. After reading what this regkey is good for(Debugging) i noticed that this is the ULTIMATIVE Processkiller...
    NOW let me explain what this Regkey does:
    User starts exe(unnamed.exe)----->Windows checks for Debuggers in the IMAGE FILE EXECUTION OPTIONS Regkey:
    If found .exename in this Regkey its starts the Debugger... else it starts the .exe!
    So for example avp.exe is going to be started you could add a regkey with avp.exe and the path to your Backdoor/RAT/Trojan! Everytime avp.exe is started your server will be started and not avp.exe .
    Now how can we implement this:
    We need a list of AV/FW processes and a list of Processses of Windows which are not "useful".
    We add all this .exenames to the Registry:
    HKLM/Software/Microsoft/WindowsNT/CurrentVersion/Image File Execution Options/"your .exe name" and we create a key named "Debugger" and set the Path to our Server.exe !
    When you wish I could code it Opensource, but i think big guys here (Krip/Steve/Binary/Syntax/Akama/Silent etc.) should understand what i am trying to explain!

    Quote Originally Posted by francewar View Post
    TBH, i dont fucking care if we have a good rep @ OpenSc. Its the biggest skid forum ever. HF has alot more mature people then this forum.
    Doing custom coding. PM me for requests.

  2. #2
    Member
    Join Date
    Jun 2008
    Posts
    30
    So if i understand this right: we just create a registry key with the name Debugger and point it to our server? Shouldn't be so hard to do.

    Great find also, i might use this as an option in my crypter ill give credits.

    Comodo Firewall defense+ asks user if allow writing into that place though, and i think kaspersky might give "access denied" unless it only protects its own keys.

  3. #3
    Senior Member slayer616's Avatar
    Join Date
    Dec 2007
    Location
    Earth
    Posts
    1,474
    aahh yes... plz gimme Credits
    @SMZ: Yes its so simple

    Quote Originally Posted by francewar View Post
    TBH, i dont fucking care if we have a good rep @ OpenSc. Its the biggest skid forum ever. HF has alot more mature people then this forum.
    Doing custom coding. PM me for requests.

  4. #4
    Senior Member Syntax_err's Avatar
    Join Date
    Jun 2008
    Posts
    593
    hey slayer616 , great idea but :

    1st im not one of the big guys
    2nd a learned that move 4m TuneUp Processes viewer when u check replace with Windows taskmgr , i found the reg path 4m that ..


    any way , u could replace it with any app and set that app as an arrgement so the user won't know , like this taskmgr.exe-->server.exe -tsk ,
    and if the command = -tsk then u execute the taskmanager , or just but the path

    but :@ i think KAV/KIS's proactive defence detect that :@ i don't remmember , and i don't have KAV these days to check

    any way , keep working and have a nice day


    pm to -silent- :@ allow more than 4 smilies :@
    لا إله إلا الله محمد رسول الله
    Non c?? dio solo allah e Mohammed ?? il messaggero di Allah
    There is no God but allah ,and Mohammed is the messenger of Allah


    Мустафа

  5. #5
    Senior Member slayer616's Avatar
    Join Date
    Dec 2007
    Location
    Earth
    Posts
    1,474
    unhook APIs and then Write it to Registry

    Quote Originally Posted by francewar View Post
    TBH, i dont fucking care if we have a good rep @ OpenSc. Its the biggest skid forum ever. HF has alot more mature people then this forum.
    Doing custom coding. PM me for requests.

  6. #6
    Senior Member Syntax_err's Avatar
    Join Date
    Jun 2008
    Posts
    593
    btw- i remmemberd an old trick , detected but may help ppl and i deloped it to be undetected 4m KAV :@

    i saw a virus make him self the parent or the opreator of exe files , like when u opened txt file , its path moved to notepad , so u make the exe's moved to ur app and then execute them , and don't execute AV's

    Code:
    HKEY_CLASSES_ROOT\exefile\shell\open\command
    but KAV family detect any modifing on the open key :S and u can't do the trick with out the open key , so :

    make ur own key like "Syntax" , make the Key Defult value = Open , and make the "HKEY_CLASSES_ROOT\exefile\shell" key value = "Syntax" so the defult Open key will be ur , not the detected one , and it's text will be "Open"

    have a nice c0d3 ,,,
    لا إله إلا الله محمد رسول الله
    Non c?? dio solo allah e Mohammed ?? il messaggero di Allah
    There is no God but allah ,and Mohammed is the messenger of Allah


    Мустафа

  7. #7
    Senior Member slayer616's Avatar
    Join Date
    Dec 2007
    Location
    Earth
    Posts
    1,474
    but the problem could be: explorer.exe f.e. wont be executed right?

    Quote Originally Posted by francewar View Post
    TBH, i dont fucking care if we have a good rep @ OpenSc. Its the biggest skid forum ever. HF has alot more mature people then this forum.
    Doing custom coding. PM me for requests.

  8. #8
    Senior Member Syntax_err's Avatar
    Join Date
    Jun 2008
    Posts
    593
    use : "urServer.exe explorer.exe" as a value , so u can execute the explorer.exe by ur self

    and btw- could u tell me , how can i unhook KAV hooks ?

    note : NtLoadDriver , NtOpenSection and CreateService is hooked
    لا إله إلا الله محمد رسول الله
    Non c?? dio solo allah e Mohammed ?? il messaggero di Allah
    There is no God but allah ,and Mohammed is the messenger of Allah


    Мустафа

  9. #9
    Senior Member slayer616's Avatar
    Join Date
    Dec 2007
    Location
    Earth
    Posts
    1,474
    i cant unhook the hooks too....
    but it should be possible...

    Quote Originally Posted by francewar View Post
    TBH, i dont fucking care if we have a good rep @ OpenSc. Its the biggest skid forum ever. HF has alot more mature people then this forum.
    Doing custom coding. PM me for requests.

  10. #10
    Senior Member Syntax_err's Avatar
    Join Date
    Jun 2008
    Posts
    593
    thats wht im talking about

    any way , change computer time , do ur fucking detected things (injection , copying , registry editing , keys hooking ), and then restore the old time , notice that KAV diabled after 10 secs , so be pations ,

    have a nice code
    لا إله إلا الله محمد رسول الله
    Non c?? dio solo allah e Mohammed ?? il messaggero di Allah
    There is no God but allah ,and Mohammed is the messenger of Allah


    Мустафа

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Bot Killer
    By stoopid in forum Snippets
    Replies: 9
    Last Post: 01-07-2009, 23:00
  2. Programmer or Serial Killer? Can you tell?
    By Urban in forum Off-Topic
    Replies: 14
    Last Post: 11-10-2008, 04:11
  3. app killer
    By biax in forum Malware sources
    Replies: 1
    Last Post: 19-06-2008, 04:20
  4. Exe killer
    By ratws in forum Snippets
    Replies: 0
    Last Post: 08-10-2005, 23:59
  5. EXE Killer
    By dNs- in forum Snippets
    Replies: 0
    Last Post: 08-10-2005, 22:02

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

Search Engine Friendly URLs by vBSEO 3.6.0 ©2011, Crawlability, Inc.