Monday, June 09, 2008

Get Past (most) Trojans & Viruses

Today I spent a long time setting up and installing a modded version of XP onto a 1TB Raid-0. With my new system I wanted some new programs. Keep everything fresh.

Just a little background on some trojans and viruses. They usually dont "embed" or "insert" themselves into executables. They generally embed the executable into them, they appear exactly like the executable. And when their run they execute their malicious code, THEN they execute the executable to ensure you dont notice anything suspicious.

So I *Legally* Got myself a copy of Windows Media Player 12. Except it had an embedded trojan. The modded version of XP had 7Zip installed and integrated, I was confused when the context menu included 7Zip for exe files.

So I messed about and extracted the exe. Viola! I found the original Windows Media Player 12 install inside the trojan exe. Completely bypassing it!

1 comment:

Kikimaru said...

"Get past Trojans & Viruses, K-ISM style"
1. Get a Mac.
2. ???
3. LOL