<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: DOs and DON&#8217;Ts for malware/virus/botnet writer/user.</title>
	<atom:link href="http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/feed/" rel="self" type="application/rss+xml" />
	<link>http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/</link>
	<description></description>
	<lastBuildDate>Sat, 26 Sep 2009 04:58:59 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Janet  &#124; Web Design</title>
		<link>http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/#comment-1845</link>
		<dc:creator>Janet  &#124; Web Design</dc:creator>
		<pubDate>Wed, 08 Jul 2009 08:14:57 +0000</pubDate>
		<guid isPermaLink="false">http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/#comment-1845</guid>
		<description>I have just come across this blog and have found it interesting and informative.

I will be coming back soon.:)</description>
		<content:encoded><![CDATA[<p>I have just come across this blog and have found it interesting and informative.</p>
<p>I will be coming back soon.:)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mhz</title>
		<link>http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/#comment-1510</link>
		<dc:creator>mhz</dc:creator>
		<pubDate>Wed, 21 Nov 2007 19:42:42 +0000</pubDate>
		<guid isPermaLink="false">http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/#comment-1510</guid>
		<description>Tisker, Download like John says Icesword
Avshell is run by 2 seperate processes, 1 is the process itself the other is a process 2 prevent the virus from getting deleted or modified. if you delete the second process you,ll be able 2 stop your cpu from shutting down. if you manage 2 do this go in your register editor, there is this reg_sz file that loads when your cpu boots
and deleting it is no use since it regenerates after 1 second. putting the section in quarantine should do fix it

John, ty for you the advice. it really made a difference</description>
		<content:encoded><![CDATA[<p>Tisker, Download like John says Icesword<br />
Avshell is run by 2 seperate processes, 1 is the process itself the other is a process 2 prevent the virus from getting deleted or modified. if you delete the second process you,ll be able 2 stop your cpu from shutting down. if you manage 2 do this go in your register editor, there is this reg_sz file that loads when your cpu boots<br />
and deleting it is no use since it regenerates after 1 second. putting the section in quarantine should do fix it</p>
<p>John, ty for you the advice. it really made a difference</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tisker</title>
		<link>http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/#comment-1232</link>
		<dc:creator>tisker</dc:creator>
		<pubDate>Sat, 25 Aug 2007 17:30:53 +0000</pubDate>
		<guid isPermaLink="false">http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/#comment-1232</guid>
		<description>that stupid spylocked is on my pc I think. whatd you do to pull it out?</description>
		<content:encoded><![CDATA[<p>that stupid spylocked is on my pc I think. whatd you do to pull it out?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: john0312</title>
		<link>http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/#comment-1057</link>
		<dc:creator>john0312</dc:creator>
		<pubDate>Wed, 27 Jun 2007 10:26:29 +0000</pubDate>
		<guid isPermaLink="false">http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/#comment-1057</guid>
		<description>IceSword it or procxp it.</description>
		<content:encoded><![CDATA[<p>IceSword it or procxp it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mhz</title>
		<link>http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/#comment-1055</link>
		<dc:creator>mhz</dc:creator>
		<pubDate>Wed, 27 Jun 2007 09:13:47 +0000</pubDate>
		<guid isPermaLink="false">http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/#comment-1055</guid>
		<description>John just a question how do you stop something
If it shutsdown your cpu in 30 seconds
trough cmd\shutdown
It disables ctrl+alt+del
something called AVshell?</description>
		<content:encoded><![CDATA[<p>John just a question how do you stop something<br />
If it shutsdown your cpu in 30 seconds<br />
trough cmd\shutdown<br />
It disables ctrl+alt+del<br />
something called AVshell?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: john0312</title>
		<link>http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/#comment-938</link>
		<dc:creator>john0312</dc:creator>
		<pubDate>Tue, 05 Jun 2007 12:27:17 +0000</pubDate>
		<guid isPermaLink="false">http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/#comment-938</guid>
		<description>Nice point on ring0 access. Fully agree, especially on the point on Vista. Vista stinks...

A point on hypervisor: I don&#039;t think all CPUs have VMX extension, in fact, only high end computers get them. My laptop&#039;s a recent one ( see my previous blogpost on a review on it. ), but it doesn&#039;t have the VMX extension... ( Intel Core Duo CPU ). Furthermore, reading through the section on VMX in the Intel Developer&#039;s Manual for Software Designer, is a pure headache, trapping intterrupt and stuff...

IceSword&#039;s good stuff... sometime I feel that I am a bit over-reliant on it... In fact, it is involved in the process of removal of Spylocked.

Oh, and on social engineering. It&#039;s quite sad that there&#039;s so many IT illiteracy around the place. No wonder Microsoft can secure their market.

Oh, crackmes, I have done two at the moment. the first one&#039;s more difficult then the second. The second can be found in this blog, written in TASM. I bet it won&#039;t be anywhere near challenging to you. I will dig up my first one and send it to you. Sunny cracked it already.</description>
		<content:encoded><![CDATA[<p>Nice point on ring0 access. Fully agree, especially on the point on Vista. Vista stinks&#8230;</p>
<p>A point on hypervisor: I don&#8217;t think all CPUs have VMX extension, in fact, only high end computers get them. My laptop&#8217;s a recent one ( see my previous blogpost on a review on it. ), but it doesn&#8217;t have the VMX extension&#8230; ( Intel Core Duo CPU ). Furthermore, reading through the section on VMX in the Intel Developer&#8217;s Manual for Software Designer, is a pure headache, trapping intterrupt and stuff&#8230;</p>
<p>IceSword&#8217;s good stuff&#8230; sometime I feel that I am a bit over-reliant on it&#8230; In fact, it is involved in the process of removal of Spylocked.</p>
<p>Oh, and on social engineering. It&#8217;s quite sad that there&#8217;s so many IT illiteracy around the place. No wonder Microsoft can secure their market.</p>
<p>Oh, crackmes, I have done two at the moment. the first one&#8217;s more difficult then the second. The second can be found in this blog, written in TASM. I bet it won&#8217;t be anywhere near challenging to you. I will dig up my first one and send it to you. Sunny cracked it already.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: opcode0x90</title>
		<link>http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/#comment-929</link>
		<dc:creator>opcode0x90</dc:creator>
		<pubDate>Mon, 04 Jun 2007 10:47:45 +0000</pubDate>
		<guid isPermaLink="false">http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/#comment-929</guid>
		<description>Sorry for double posting. I accidently pressed back and submit again. :P</description>
		<content:encoded><![CDATA[<p>Sorry for double posting. I accidently pressed back and submit again. <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: opcode0x90</title>
		<link>http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/#comment-928</link>
		<dc:creator>opcode0x90</dc:creator>
		<pubDate>Mon, 04 Jun 2007 10:46:07 +0000</pubDate>
		<guid isPermaLink="false">http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/#comment-928</guid>
		<description>Before you can mess around kernel, you need access to ring0 which can be quite costly nowadays. Most AV and even Firewall (namely ZoneAlarm) intercepts the driver loading function so going into kernel can be quite a problem. To mess up the problem even more comes Windows Vista, which promises only a paid and digitally-signed virus are allowed into kernel. ;)

Okay set that aside. I suggest that a future virus should take advantage of &quot;hypervisor&quot; of the new processors. It is extremely hard to detect such a virus, as it host the OS inside fake &quot;nothing is wrong&quot; environment and sit in between the hardware.

As for disabling Task Manager, you dont need to do that at all since your virus is well hidden from sight. DLL injection alone is not enough, but DLL injection + PEB hiding should keep your virus from prying eyes for a very very long time. (unless your virus happens to infect leet users who knows how to use IceSword :P, but that is none of our concern)

Virtualization is a very nice trick to keep your virus from being reverse engineered. It renders a lot of tricks virtually useless. You can see the virus, but youll never know what it does. An extra dose of creativity can guarentee AV vendors some headache. ;)

------------------------------------------------------------------------------------
     Possible off-topic warning
------------------------------------------------------------------------------------

I like to point out a sad fact is that a lot of people still fall for simple social engineering tricks like i_loev_you.jpg.vbs. People may have learned not to open attachments from email, but it seems they didnt realize not to trust any downloads they get off the net. You can easily snip a keylogger into a DoTA Blue Server installer and release it into the wild. You may be amazed by how easily people can fall for such tricks.

It wasnt the first time people came to me yelling &quot;zomg my pc is full of spyware&quot; and be amazed, they are infected with the same spyware for the 10000000000th ... again. It was a simple virus that hid inside a pendrive, activated by autorun.ini. Guess what, AVs like AVG Free and NOD32 doesnt raise any alarm at ALL ! Theres another guy that is infected with that spyware told me &quot;AV is not needed, cause I have ZoneAlarm&quot;. .................. speechless?

So we came to a conclusion, user lack of awareness about malwares is the problem. It takes only a noob virus to infect noob users. 

------------------------------------------------------------------------------------

PS. You write crackmes eh? So when can I get my hand on one of those ? ;)</description>
		<content:encoded><![CDATA[<p>Before you can mess around kernel, you need access to ring0 which can be quite costly nowadays. Most AV and even Firewall (namely ZoneAlarm) intercepts the driver loading function so going into kernel can be quite a problem. To mess up the problem even more comes Windows Vista, which promises only a paid and digitally-signed virus are allowed into kernel. <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Okay set that aside. I suggest that a future virus should take advantage of &#8220;hypervisor&#8221; of the new processors. It is extremely hard to detect such a virus, as it host the OS inside fake &#8220;nothing is wrong&#8221; environment and sit in between the hardware.</p>
<p>As for disabling Task Manager, you dont need to do that at all since your virus is well hidden from sight. DLL injection alone is not enough, but DLL injection + PEB hiding should keep your virus from prying eyes for a very very long time. (unless your virus happens to infect leet users who knows how to use IceSword <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> , but that is none of our concern)</p>
<p>Virtualization is a very nice trick to keep your virus from being reverse engineered. It renders a lot of tricks virtually useless. You can see the virus, but youll never know what it does. An extra dose of creativity can guarentee AV vendors some headache. <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
     Possible off-topic warning<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>I like to point out a sad fact is that a lot of people still fall for simple social engineering tricks like i_loev_you.jpg.vbs. People may have learned not to open attachments from email, but it seems they didnt realize not to trust any downloads they get off the net. You can easily snip a keylogger into a DoTA Blue Server installer and release it into the wild. You may be amazed by how easily people can fall for such tricks.</p>
<p>It wasnt the first time people came to me yelling &#8220;zomg my pc is full of spyware&#8221; and be amazed, they are infected with the same spyware for the 10000000000th &#8230; again. It was a simple virus that hid inside a pendrive, activated by autorun.ini. Guess what, AVs like AVG Free and NOD32 doesnt raise any alarm at ALL ! Theres another guy that is infected with that spyware told me &#8220;AV is not needed, cause I have ZoneAlarm&#8221;. &#8230;&#8230;&#8230;&#8230;&#8230;&#8230; speechless?</p>
<p>So we came to a conclusion, user lack of awareness about malwares is the problem. It takes only a noob virus to infect noob users. </p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>PS. You write crackmes eh? So when can I get my hand on one of those ? <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: opcode0x90</title>
		<link>http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/#comment-927</link>
		<dc:creator>opcode0x90</dc:creator>
		<pubDate>Mon, 04 Jun 2007 10:44:47 +0000</pubDate>
		<guid isPermaLink="false">http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/#comment-927</guid>
		<description>Before you can mess around kernel, you need access to ring0 which can be quite costly nowadays. Most AV and even Firewall (namely ZoneAlarm) intercepts the driver loading function so going into kernel can be quite a problem. To mess up the problem even more comes Windows Vista, which promises only a paid and digitally-signed virus are allowed into kernel. ;)

Okay set that aside. I suggest that a future virus should take advantage of &quot;hypervisor&quot; of the new processors. It is extremely hard to detect such a virus, as it host the OS inside &quot;nothing is wrong&quot; fake environment and sit in between the hardware.

As for disabling Task Manager, you dont need to do that at all since your virus is well hidden from sight. DLL injection alone is not enough, but DLL injection + PEB hiding should keep your virus from prying eyes for a very very long time. (unless your virus happens to infect leet users who knows how to use IceSword :P, but that is none of our concern)

Virtualization is a very nice trick to keep your virus from being reverse engineered. It renders a lot of tricks virtually useless. You can see the virus, but youll never know what it does. An extra dose of creativity can guarentee AV vendors some headache. ;)

------------------------------------------------------------------------------------
     Possible off-topic warning
------------------------------------------------------------------------------------

I like to point out a sad fact is that a lot of people still fall for simple social engineering tricks like i_loev_you.jpg.vbs. People may have learned not to open attachments from email, but it seems they didnt realize not to trust any downloads they get off the net. You can easily snip a keylogger into a DoTA Blue Server installer and release it into the wild. You may be amazed by how easily people can fall for such tricks.

It wasnt the first time people came to me yelling &quot;zomg my pc is full of spyware&quot; and be amazed, they are infected with the same spyware for the 10000000000th ... again. It was a simple virus that hid inside a pendrive, activated by autorun.ini. Guess what, AVs like AVG Free and NOD32 doesnt raise any alarm at ALL ! Theres another guy that is infected with that spyware told me &quot;AV is not needed, cause I have ZoneAlarm&quot;. .................. speechless?

So we came to a conclusion, user awareness about malwares is the problem. It takes only a noob virus to infect noob users. 

------------------------------------------------------------------------------------

PS. You write crackmes eh? So when can I get my hand on one of those ? ;)</description>
		<content:encoded><![CDATA[<p>Before you can mess around kernel, you need access to ring0 which can be quite costly nowadays. Most AV and even Firewall (namely ZoneAlarm) intercepts the driver loading function so going into kernel can be quite a problem. To mess up the problem even more comes Windows Vista, which promises only a paid and digitally-signed virus are allowed into kernel. <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Okay set that aside. I suggest that a future virus should take advantage of &#8220;hypervisor&#8221; of the new processors. It is extremely hard to detect such a virus, as it host the OS inside &#8220;nothing is wrong&#8221; fake environment and sit in between the hardware.</p>
<p>As for disabling Task Manager, you dont need to do that at all since your virus is well hidden from sight. DLL injection alone is not enough, but DLL injection + PEB hiding should keep your virus from prying eyes for a very very long time. (unless your virus happens to infect leet users who knows how to use IceSword <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> , but that is none of our concern)</p>
<p>Virtualization is a very nice trick to keep your virus from being reverse engineered. It renders a lot of tricks virtually useless. You can see the virus, but youll never know what it does. An extra dose of creativity can guarentee AV vendors some headache. <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
     Possible off-topic warning<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>I like to point out a sad fact is that a lot of people still fall for simple social engineering tricks like i_loev_you.jpg.vbs. People may have learned not to open attachments from email, but it seems they didnt realize not to trust any downloads they get off the net. You can easily snip a keylogger into a DoTA Blue Server installer and release it into the wild. You may be amazed by how easily people can fall for such tricks.</p>
<p>It wasnt the first time people came to me yelling &#8220;zomg my pc is full of spyware&#8221; and be amazed, they are infected with the same spyware for the 10000000000th &#8230; again. It was a simple virus that hid inside a pendrive, activated by autorun.ini. Guess what, AVs like AVG Free and NOD32 doesnt raise any alarm at ALL ! Theres another guy that is infected with that spyware told me &#8220;AV is not needed, cause I have ZoneAlarm&#8221;. &#8230;&#8230;&#8230;&#8230;&#8230;&#8230; speechless?</p>
<p>So we came to a conclusion, user awareness about malwares is the problem. It takes only a noob virus to infect noob users. </p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>PS. You write crackmes eh? So when can I get my hand on one of those ? <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: john0312</title>
		<link>http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/#comment-925</link>
		<dc:creator>john0312</dc:creator>
		<pubDate>Fri, 01 Jun 2007 08:38:43 +0000</pubDate>
		<guid isPermaLink="false">http://john0312.wordpress.com/2007/05/27/dos-and-donts-for-malwarevirusbotnet-writeruser/#comment-925</guid>
		<description>I don&#039;t write virus anymore, I only write crackmes.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t write virus anymore, I only write crackmes.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
