A forum for reverse engineering, OS internals and malware analysis 

Forum for announcements and questions about tools and software.
 #16077  by Buster_BSA
 Wed Oct 17, 2012 9:56 am
Hi.

One of the features I have had in the Buster Sandbox Analyzer´s TO-DO list was a malware disinfector.

The idea is to use the list of changes made to system file and registry reported by BSA and generate a file that could be used to revert the changes.

Would be anyone interested in developing a tool that using a special file generated by BSA works as disinfector?
 #16161  by nex
 Fri Oct 19, 2012 1:48 pm
I'd love to do a similar thing for my sandbox too, but it would need some kind of machine-learning-like component to discriminate from a trained set of legitimate "events" performed on the system before being able to automatically identify which ones are malicious or not.
Of course your sandbox is already able to do that, I'm not really familiar with it.
 #16345  by Dmitry Varshavsky
 Tue Oct 30, 2012 8:48 am
Buster_BSA wrote:Hi.

One of the features I have had in the Buster Sandbox Analyzer´s TO-DO list was a malware disinfector.

The idea is to use the list of changes made to system file and registry reported by BSA and generate a file that could be used to revert the changes.

Would be anyone interested in developing a tool that using a special file generated by BSA works as disinfector?
Current private version of Vba32 Arkit is able to cure the system with a special crafted script. We can add support for BSA generated files in some near beta. Write me PM, if you're interested.