PDA

View Full Version : Reverse Engineering a Trojan?


Sir Hellboy
07-21-2009, 01:36 PM
Hello there I am enquiring as to whether anyone here knows how to reverse engineer a virus using OllyDbg or ASM assembler etc. that is binded to a file. What I would like to learn is how to reverse engineer it so that the original file can be used without chances of your information being sent to that ftp server they always get sent to....

eg. a song is infected with trojan, i want to remove the trojan from the song/make the trojan useless so just remove the ftp server part of the code, does anyone know how to do this?

i have very basic knowledge of how to use ollydbg.

Git
07-22-2009, 06:33 AM
Just use any of the usual virus checkers with Repair option, it will remove the trojan for you.

Git

Sir Hellboy
07-22-2009, 07:19 AM
Just use any of the usual virus checkers with Repair option, it will remove the trojan for you.

Git

it doesnt work with almost all trojans....or it ends up corrupting the file so it wont open correctly

foffa
07-22-2009, 09:49 PM
are you try to reverse a song :D

it is amazing executable which could have a trojan binded to it :mad:

Git
07-23-2009, 06:13 AM
Can't you just rip the song out of it with a hex editor or is DRM involved?

Git

yogi_saw
07-24-2009, 10:35 AM
eg. a song is infected with trojan, i want to remove the trojan from the song/make the trojan useless so just remove the ftp server part of the code, does anyone know how to do this?

I don't think any virus would like to affect song file or any of data file (without micros) which is really of no use b'coz it can not load if attached to data file