What happened to the Messenger Plus! forums on msghelp.net?
Shoutbox » MsgHelp Archive » Skype & Technology » Tech Talk » MD5 Virus Hashes

MD5 Virus Hashes
Author: Message:
CookieRevised
Elite Member
*****

Avatar

Posts: 15517
Reputation: 173
– / Male / Flag
Joined: Jul 2003
Status: Away
RE: RE: MD5 Virus Hashes
quote:
Originally posted by DJeX
quote:
Originally posted by CookieRevised
They are detected by signatures.
Ok then tell me how to do this.
Compare a not infected file with an infected file. The difference is your virus. Do this for multiple infected files (from the same virus) and the common same bytes are your signature. This is extremely simple explained though, but it is the basic principle.

To make proper signatures, you must be very fluent in hex editing, understanding executable file formats, knowing ASM, etc.. etc.. In other words, you must have a deep knowledge of how programs are executed and stuff. In fact, what you ask is exactly what professional virus companies do ;)

This post was edited on 12-14-2005 at 11:22 PM by CookieRevised.
.-= A 'frrrrrrrituurrr' for Wacky =-.
12-14-2005 11:20 PM
Profile PM Find Quote Report
« Next Oldest Return to Top Next Newest »

Messages In This Thread
MD5 Virus Hashes - by DJeX on 12-14-2005 at 03:57 AM
RE: MD5 Virus Hashes - by Eljay on 12-14-2005 at 12:03 PM
RE: MD5 Virus Hashes - by Ezra on 12-14-2005 at 01:45 PM
RE: MD5 Virus Hashes - by RaceProUK on 12-14-2005 at 02:02 PM
RE: RE: MD5 Virus Hashes - by segosa on 12-14-2005 at 06:28 PM
RE: MD5 Virus Hashes - by CookieRevised on 12-14-2005 at 11:10 PM
RE: MD5 Virus Hashes - by DJeX on 12-14-2005 at 11:14 PM
RE: RE: MD5 Virus Hashes - by CookieRevised on 12-14-2005 at 11:20 PM
RE: MD5 Virus Hashes - by DJeX on 12-15-2005 at 12:50 AM


Threaded Mode | Linear Mode
View a Printable Version
Send this Thread to a Friend
Subscribe | Add to Favorites
Rate This Thread:

Forum Jump:

Forum Rules:
You cannot post new threads
You cannot post replies
You cannot post attachments
You can edit your posts
HTML is Off
myCode is On
Smilies are On
[img] Code is On