<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>VC爱好者 v3.0 &#187; 病毒</title>
	<atom:link href="http://www.vcfans.com/tag/%e7%97%85%e6%af%92/feed" rel="self" type="application/rss+xml" />
	<link>http://www.vcfans.com</link>
	<description>生活的天平本不平衡，只有通过努力改变其偏向。</description>
	<lastBuildDate>Tue, 22 Nov 2011 17:32:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>zz 鬼影里的ZwSystemDebugControl</title>
		<link>http://www.vcfans.com/2010/03/zz-ghost-inside-zwsystemdebugcontrol.html</link>
		<comments>http://www.vcfans.com/2010/03/zz-ghost-inside-zwsystemdebugcontrol.html#comments</comments>
		<pubDate>Sun, 21 Mar 2010 14:08:58 +0000</pubDate>
		<dc:creator>lonkil</dc:creator>
				<category><![CDATA[编程开发]]></category>
		<category><![CDATA[病毒]]></category>
		<category><![CDATA[逆向]]></category>

		<guid isPermaLink="false">http://www.vcfans.com/?p=1106</guid>
		<description><![CDATA[作者：Fypher

分析了一下“鬼影”病毒，从里面扒了段代码出来。

该段代码调用 ZwDebugSystemControl 在 Ring3 恢复 SSDT，并摘除
PsSetLoadImageNotifyRoutine、PsSetCreateProcessNotifyRoutine、
PsSetCreateThreadNotifyRoutine 三个钩子。

代码里 bug 较多，我用注释标示出来了，保留原味儿，未做修改。

逆向 by Fypher
http://hi.baidu.com/nmn714[......]<p class='read-more'><a href='http://www.vcfans.com/2010/03/zz-ghost-inside-zwsystemdebugcontrol.html'>Read More »</a></p>]]></description>
		<wfw:commentRss>http://www.vcfans.com/2010/03/zz-ghost-inside-zwsystemdebugcontrol.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>和谐掉系统的文件保护一分钟</title>
		<link>http://www.vcfans.com/2009/12/harmony-out-the-system-file-protection-for-one-minute.html</link>
		<comments>http://www.vcfans.com/2009/12/harmony-out-the-system-file-protection-for-one-minute.html#comments</comments>
		<pubDate>Wed, 09 Dec 2009 08:51:22 +0000</pubDate>
		<dc:creator>lonkil</dc:creator>
				<category><![CDATA[编程开发]]></category>
		<category><![CDATA[VC]]></category>
		<category><![CDATA[病毒]]></category>
		<category><![CDATA[逆向]]></category>

		<guid isPermaLink="false">http://www.vcfans.com/?p=1072</guid>
		<description><![CDATA[从某AutoRun中逆出来的，利用微软未公布的API,sfc_os.dll中的ordinal为5函数，关闭文件保护一分钟。[......]<p class='read-more'><a href='http://www.vcfans.com/2009/12/harmony-out-the-system-file-protection-for-one-minute.html'>Read More »</a></p>]]></description>
		<wfw:commentRss>http://www.vcfans.com/2009/12/harmony-out-the-system-file-protection-for-one-minute.html/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>警惕：IE70DAY攻击代码已经遭挂马攻击利用</title>
		<link>http://www.vcfans.com/2008/12/alert-ie70day-attack-code-has-been-linked-to-the-use-of-attacks-horse.html</link>
		<comments>http://www.vcfans.com/2008/12/alert-ie70day-attack-code-has-been-linked-to-the-use-of-attacks-horse.html#comments</comments>
		<pubDate>Tue, 09 Dec 2008 16:41:31 +0000</pubDate>
		<dc:creator>lonkil</dc:creator>
				<category><![CDATA[本站杂谈]]></category>
		<category><![CDATA[安全]]></category>
		<category><![CDATA[病毒]]></category>
		<category><![CDATA[网络]]></category>

		<guid isPermaLink="false">http://www.vcfans.com/?p=780</guid>
		<description><![CDATA[//IE又来了，FireFox今天也看到挂马劫持的报道。不是软件没漏洞，是用的人还不够多。by lonkil[......]<p class='read-more'><a href='http://www.vcfans.com/2008/12/alert-ie70day-attack-code-has-been-linked-to-the-use-of-attacks-horse.html'>Read More »</a></p>]]></description>
		<wfw:commentRss>http://www.vcfans.com/2008/12/alert-ie70day-attack-code-has-been-linked-to-the-use-of-attacks-horse.html/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>国外的挂马方式比熊猫烧香还招摇</title>
		<link>http://www.vcfans.com/2008/08/foreign-install-torjan-way.html</link>
		<comments>http://www.vcfans.com/2008/08/foreign-install-torjan-way.html#comments</comments>
		<pubDate>Wed, 13 Aug 2008 14:26:08 +0000</pubDate>
		<dc:creator>lonkil</dc:creator>
				<category><![CDATA[本站杂谈]]></category>
		<category><![CDATA[病毒]]></category>

		<guid isPermaLink="false">http://www.vcfans.com/?p=390</guid>
		<description><![CDATA[今天我罗大侠居然神奇的中了国外一款病毒，Nod32报“Win32/TrojanDownloader.FakeAlert.DJ 特洛伊木马”。真是太为难罗大侠了，经常出入于国外论坛，力顶友邦的AV事业。居然让他中招了，友邦人土太不厚道了。这款病毒属于BMP捆绑型病毒，由于我对病毒的“行情”不了解，这种技术应该属于比较老的了，不过居然让我罗大侠给碰上了。

让我感兴趣的是该病毒特有的绑定方式，比熊猫烧香招摇多了。熊猫不就改了一个小小的ICO嘛，这个病毒到挺狠。直接将绑了毒的BMP的图片，设成了桌面背景。那图片上还用蓝底黄色三号字,告诉他你已中毒。[......]<p class='read-more'><a href='http://www.vcfans.com/2008/08/foreign-install-torjan-way.html'>Read More »</a></p>]]></description>
		<wfw:commentRss>http://www.vcfans.com/2008/08/foreign-install-torjan-way.html/feed</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>在网上看到一份ARP欺骗的代码</title>
		<link>http://www.vcfans.com/2008/08/arp-online-to-see-a-cheat-code.html</link>
		<comments>http://www.vcfans.com/2008/08/arp-online-to-see-a-cheat-code.html#comments</comments>
		<pubDate>Tue, 05 Aug 2008 16:08:48 +0000</pubDate>
		<dc:creator>lonkil</dc:creator>
				<category><![CDATA[编程开发]]></category>
		<category><![CDATA[VC]]></category>
		<category><![CDATA[病毒]]></category>
		<category><![CDATA[网络]]></category>

		<guid isPermaLink="false">http://www.vcfans.com/?p=385</guid>
		<description><![CDATA[今天在网上看到这份代码，以前在公司深受其害，感觉不错就转了过来。

来自：http://hi.baidu.com/fengze/blog/item/445474c698714f1e9c163d3b.html

编译环境：WINXP SP2+VC6.0+Winpcap开发包[......]<p class='read-more'><a href='http://www.vcfans.com/2008/08/arp-online-to-see-a-cheat-code.html'>Read More »</a></p>]]></description>
		<wfw:commentRss>http://www.vcfans.com/2008/08/arp-online-to-see-a-cheat-code.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>AutoRun导致双击打不开移动硬盘的盘符</title>
		<link>http://www.vcfans.com/2008/06/autorun-lead-to-double-click-on-trying-to-open-the-mobile-hard-disk-drive-letter.html</link>
		<comments>http://www.vcfans.com/2008/06/autorun-lead-to-double-click-on-trying-to-open-the-mobile-hard-disk-drive-letter.html#comments</comments>
		<pubDate>Sun, 01 Jun 2008 10:32:18 +0000</pubDate>
		<dc:creator>lonkil</dc:creator>
				<category><![CDATA[本站杂谈]]></category>
		<category><![CDATA[奇技淫巧]]></category>
		<category><![CDATA[病毒]]></category>

		<guid isPermaLink="false">http://192.168.1.12/?p=308</guid>
		<description><![CDATA[

我自认为有一个很好的使用电脑的习惯，加上对自己的机器作了一些防范，我中毒很少，在我印象中好像就没有自己中毒，而重做系统的。在网上混了这么多年，还是比较值得欣慰的。

今天在朋友的机器里用移动硬盘拷...[......]<p class='read-more'><a href='http://www.vcfans.com/2008/06/autorun-lead-to-double-click-on-trying-to-open-the-mobile-hard-disk-drive-letter.html'>Read More »</a></p>]]></description>
		<wfw:commentRss>http://www.vcfans.com/2008/06/autorun-lead-to-double-click-on-trying-to-open-the-mobile-hard-disk-drive-letter.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>新黑客程序可在操作系统外运行</title>
		<link>http://www.vcfans.com/2008/05/new-hacker-program-can-be-run-in-the-operating-system.html</link>
		<comments>http://www.vcfans.com/2008/05/new-hacker-program-can-be-run-in-the-operating-system.html#comments</comments>
		<pubDate>Sun, 11 May 2008 09:10:26 +0000</pubDate>
		<dc:creator>lonkil</dc:creator>
				<category><![CDATA[本站杂谈]]></category>
		<category><![CDATA[ASM]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[病毒]]></category>

		<guid isPermaLink="false">http://192.168.1.12/?p=273</guid>
		<description><![CDATA[美国佛罗里达州安全企业Clear Hat Consulting的两位研究人员日前宣布，他们开发出了一款概念性的rootkit黑客程序，能够在操作系统外运行，无法被任何现有杀毒软件或防火墙察觉。
这一新安全威胁的奥妙来自于它的运行...[......]<p class='read-more'><a href='http://www.vcfans.com/2008/05/new-hacker-program-can-be-run-in-the-operating-system.html'>Read More »</a></p>]]></description>
		<wfw:commentRss>http://www.vcfans.com/2008/05/new-hacker-program-can-be-run-in-the-operating-system.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>File Format Identifier v1.4</title>
		<link>http://www.vcfans.com/2008/03/file-format-identifier-v14.html</link>
		<comments>http://www.vcfans.com/2008/03/file-format-identifier-v14.html#comments</comments>
		<pubDate>Fri, 07 Mar 2008 17:04:38 +0000</pubDate>
		<dc:creator>lonkil</dc:creator>
				<category><![CDATA[常用工具]]></category>
		<category><![CDATA[病毒]]></category>
		<category><![CDATA[程序]]></category>

		<guid isPermaLink="false">http://localhost/?p=199</guid>
		<description><![CDATA[本工具是一款辅助进行病毒分析的工具，它包括各种文件格式识别功能，使用超级巡警的格式识别引擎，集查壳、虚拟机脱壳、PE文件编辑、PE文件重建、导入 表抓取(内置虚拟机解密某些加密导入表)、进程内存查看/DUMP、附...[......]<p class='read-more'><a href='http://www.vcfans.com/2008/03/file-format-identifier-v14.html'>Read More »</a></p>]]></description>
		<wfw:commentRss>http://www.vcfans.com/2008/03/file-format-identifier-v14.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>卡巴斯基再次误杀世界之窗 开发组表示强烈愤慨</title>
		<link>http://www.vcfans.com/2008/03/kaspersky-again-manslaughter-window-of-the-world-development-group-expressed-strong-indignation.html</link>
		<comments>http://www.vcfans.com/2008/03/kaspersky-again-manslaughter-window-of-the-world-development-group-expressed-strong-indignation.html#comments</comments>
		<pubDate>Fri, 07 Mar 2008 17:03:49 +0000</pubDate>
		<dc:creator>lonkil</dc:creator>
				<category><![CDATA[病毒]]></category>

		<guid isPermaLink="false">http://localhost/?p=198</guid>
		<description><![CDATA[

由于卡巴斯基在安全厂商中所处的一线领袖地位,每次卡巴斯基误报发生后,随之而来的,是更多“安全软件”对世界之窗的误报.
幸运的是,我们每次都及时的得到了卡巴斯基产品经理友好的回应.
不幸的是,后来的两次,卡...[......]<p class='read-more'><a href='http://www.vcfans.com/2008/03/kaspersky-again-manslaughter-window-of-the-world-development-group-expressed-strong-indignation.html'>Read More »</a></p>]]></description>
		<wfw:commentRss>http://www.vcfans.com/2008/03/kaspersky-again-manslaughter-window-of-the-world-development-group-expressed-strong-indignation.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AutoRuns for Windows v9.13</title>
		<link>http://www.vcfans.com/2008/02/autoruns-for-windows-v913.html</link>
		<comments>http://www.vcfans.com/2008/02/autoruns-for-windows-v913.html#comments</comments>
		<pubDate>Thu, 28 Feb 2008 16:07:13 +0000</pubDate>
		<dc:creator>lonkil</dc:creator>
				<category><![CDATA[本站杂谈]]></category>
		<category><![CDATA[病毒]]></category>

		<guid isPermaLink="false">http://localhost/?p=182</guid>
		<description><![CDATA[官方说明：

This utility, which has the most comprehensive knowledge of auto-starting locations of any startup monitor, shows you what programs are configured to run during system bootup or login, a...[......]<p class='read-more'><a href='http://www.vcfans.com/2008/02/autoruns-for-windows-v913.html'>Read More »</a></p>]]></description>
		<wfw:commentRss>http://www.vcfans.com/2008/02/autoruns-for-windows-v913.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>冰刃</title>
		<link>http://www.vcfans.com/2008/01/bingren.html</link>
		<comments>http://www.vcfans.com/2008/01/bingren.html#comments</comments>
		<pubDate>Thu, 24 Jan 2008 16:35:45 +0000</pubDate>
		<dc:creator>lonkil</dc:creator>
				<category><![CDATA[常用工具]]></category>
		<category><![CDATA[病毒]]></category>
		<category><![CDATA[系统]]></category>

		<guid isPermaLink="false">http://localhost/?p=149</guid>
		<description><![CDATA[//充满混乱的网络上，太没安全感了，IceSword是我常用的一款工具，专用来对付那些牛鬼蛇神的。by Lonkil

这是一斩断黑手的利刃, 它适用于Windows 2000/XP/2003 操作系统, 其内部功能是十分强大, 用于查探系统中的...[......]<p class='read-more'><a href='http://www.vcfans.com/2008/01/bingren.html'>Read More »</a></p>]]></description>
		<wfw:commentRss>http://www.vcfans.com/2008/01/bingren.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Photoshop文件不能保存</title>
		<link>http://www.vcfans.com/2007/07/photoshop-files-can-not-be-saved.html</link>
		<comments>http://www.vcfans.com/2007/07/photoshop-files-can-not-be-saved.html#comments</comments>
		<pubDate>Fri, 13 Jul 2007 15:41:14 +0000</pubDate>
		<dc:creator>lonkil</dc:creator>
				<category><![CDATA[本站杂谈]]></category>
		<category><![CDATA[奇技淫巧]]></category>
		<category><![CDATA[病毒]]></category>

		<guid isPermaLink="false">http://localhost/?p=130</guid>
		<description><![CDATA[

公司美工MM，说Photoshop文件修改不能保存，叫偶帮她看看。

开始以为是暂存盘满了，ps太占空间了。

不是那个问题，百思不得其解，看一切都正确，只有Gif的文件能保存。可是psd、bmp等格式均不能保存。不解...[......]<p class='read-more'><a href='http://www.vcfans.com/2007/07/photoshop-files-can-not-be-saved.html'>Read More »</a></p>]]></description>
		<wfw:commentRss>http://www.vcfans.com/2007/07/photoshop-files-can-not-be-saved.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>google又一次证明其强憾</title>
		<link>http://www.vcfans.com/2007/03/google-once-again-proved-its-strong-regret.html</link>
		<comments>http://www.vcfans.com/2007/03/google-once-again-proved-its-strong-regret.html#comments</comments>
		<pubDate>Mon, 19 Mar 2007 15:01:52 +0000</pubDate>
		<dc:creator>lonkil</dc:creator>
				<category><![CDATA[本站杂谈]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[病毒]]></category>

		<guid isPermaLink="false">http://localhost/?p=117</guid>
		<description><![CDATA[我在Google查找OpenCV开发包的资料时，查一个到网址．点击进去以后．发现Google给我这么一个提示：＂您要访问的网站可能会损害您的计算机＂，我晕，这么强悍．如下图：


我报着怀疑和看个究尽的心态，进入那个网...[......]<p class='read-more'><a href='http://www.vcfans.com/2007/03/google-once-again-proved-its-strong-regret.html'>Read More »</a></p>]]></description>
		<wfw:commentRss>http://www.vcfans.com/2007/03/google-once-again-proved-its-strong-regret.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>病毒，挻热的嘛！</title>
		<link>http://www.vcfans.com/2007/02/virus-yan-hot.html</link>
		<comments>http://www.vcfans.com/2007/02/virus-yan-hot.html#comments</comments>
		<pubDate>Thu, 08 Feb 2007 07:53:13 +0000</pubDate>
		<dc:creator>lonkil</dc:creator>
				<category><![CDATA[本站杂谈]]></category>
		<category><![CDATA[病毒]]></category>

		<guid isPermaLink="false">http://localhost/?p=97</guid>
		<description><![CDATA[现在病毒貌视很猖獗嘛，据小道消息透露，我的某位同仁，带到施工现场的几套程序，居然全都无法运行，系统接近于瘫痪。害的我要在公司给他们重新刻碟，寄过去。

看样子反病毒行业是一个很前途的行业哦！为某位同仁...[......]<p class='read-more'><a href='http://www.vcfans.com/2007/02/virus-yan-hot.html'>Read More »</a></p>]]></description>
		<wfw:commentRss>http://www.vcfans.com/2007/02/virus-yan-hot.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>熊猫烧香病毒分析及解决方案</title>
		<link>http://www.vcfans.com/2007/02/panda-burning-incense-virus-analysis-and-solutions.html</link>
		<comments>http://www.vcfans.com/2007/02/panda-burning-incense-virus-analysis-and-solutions.html#comments</comments>
		<pubDate>Fri, 02 Feb 2007 06:56:42 +0000</pubDate>
		<dc:creator>lonkil</dc:creator>
				<category><![CDATA[编程开发]]></category>
		<category><![CDATA[汇编]]></category>
		<category><![CDATA[病毒]]></category>
		<category><![CDATA[逆向]]></category>

		<guid isPermaLink="false">http://localhost/?p=91</guid>
		<description><![CDATA[loveboom，对熊猫烧香变种的一次反汇编分析。PDF格式，看的非常的爽。有兴趣的朋友可以下回去研究一下，转自看雪。

[donwload id="21"][......]<p class='read-more'><a href='http://www.vcfans.com/2007/02/panda-burning-incense-virus-analysis-and-solutions.html'>Read More »</a></p>]]></description>
		<wfw:commentRss>http://www.vcfans.com/2007/02/panda-burning-incense-virus-analysis-and-solutions.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

