?
Solved

how can i get antivirus detection(s)

Posted on 2009-12-29
6
Medium Priority
?
284 Views
Last Modified: 2012-05-08
hello guys,
i'm trying to figure out a way to get an application to be detected by most (if not all) anti viruses.
normally i would use the EICAR test file BUT i cant use it in this because its too small...
i tried using it as a string in an .exe witch i found out doesnt work because..
[quote]The first 68 characters is the known string. It may be optionally appended by any combination of whitespace characters with the total file length not exceeding 128 characters.[/quote]
and its also .com not .exe
So, does anyone know a way to get AV detections (without harmful code)?
(i was thinking, a downloader that doesn't download anything surprisingly that wasn't very detected...)

0
Comment
Question by:electrodude102
  • 3
  • 3
6 Comments
 
LVL 1

Expert Comment

by:delphibr
ID: 26142847
Hello!

Have your heard about W32/Induc-A virus? Have a look in this link: http://isc.sans.org/diary.html?storyid=7009

I was infected sometime ago, and looking for the sysconst.dcu contaminated file to send to you...

You can use http://www.virustotal.com to test your "contaminated" file...

Wait for my return.

DelphiBR
0
 
LVL 1

Accepted Solution

by:
delphibr earned 375 total points
ID: 26142898
Hello again,

This link shows the code of the "virus", for you to change the file sysconst.pas (inside "Source\Rtl\Sys"):

http://www.viruslist.com/en/weblog?weblogid=208187826

Use www.virustotal.com for check.

I hope this help you!

DelphiBR
0
 
LVL 1

Author Comment

by:electrodude102
ID: 26143144
hmm that is a great idea,
however if you run that code it will 'infect' you (if they have Delphi...) even though its harmless i don't really want to go around spreading a worm.

if no one else answers(better) ill accept yours.
0
VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

 
LVL 1

Expert Comment

by:delphibr
ID: 26143202
Well, you can "change" that code in order to not infect other files...

Another idea is to use some "keyboard hook" code found on internet. Most of then are detected by antivirus... have a look:

http://www.google.com.br/search?source=igrlz=&q=delphi+keyboard+hook

DelphiBR
0
 
LVL 1

Author Comment

by:electrodude102
ID: 26143294
'that' isn't the whole induc.a code, its actually about 110~ lines long (i found it if you want me to post it)
i [i]could[/i] use it i'm just looking for something smaller, and would have to edit less, first.
0
 
LVL 1

Author Closing Comment

by:electrodude102
ID: 31670926
wasn't exactly what i was looking for but its usable.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article explains how to create forms/units independent of other forms/units object names in a delphi project. Have you ever created a form for user input in a Delphi project and then had the need to have that same form in a other Delphi proj…
In this tutorial I will show you how to use the Windows Speech API in Delphi. I will only cover basic functions such as text to speech and controlling the speed of the speech. SAPI Installation First you need to install the SAPI type library, th…
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…
With just a little bit of  SQL and VBA, many doors open to cool things like synchronize a list box to display data relevant to other information on a form.  If you have never written code or looked at an SQL statement before, no problem! ...  give i…
Suggested Courses
Course of the Month15 days, 7 hours left to enroll

840 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question