<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: A malware with my name	</title>
	<atom:link href="https://ntcore.com/a-malware-with-my-name/feed/" rel="self" type="application/rss+xml" />
	<link>https://ntcore.com/a-malware-with-my-name/</link>
	<description></description>
	<lastBuildDate>Sat, 15 Sep 2012 13:50:56 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9</generator>
	<item>
		<title>
		By: Daniel Pistelli		</title>
		<link>https://ntcore.com/a-malware-with-my-name/#comment-243</link>

		<dc:creator><![CDATA[Daniel Pistelli]]></dc:creator>
		<pubDate>Sat, 15 Sep 2012 13:50:56 +0000</pubDate>
		<guid isPermaLink="false">http://rcecafe.net/?p=163#comment-243</guid>

					<description><![CDATA[Sure, just ask me what you are interested to know. :)]]></description>
			<content:encoded><![CDATA[<p>Sure, just ask me what you are interested to know. 🙂</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Zarko		</title>
		<link>https://ntcore.com/a-malware-with-my-name/#comment-242</link>

		<dc:creator><![CDATA[Zarko]]></dc:creator>
		<pubDate>Fri, 14 Sep 2012 14:47:57 +0000</pubDate>
		<guid isPermaLink="false">http://rcecafe.net/?p=163#comment-242</guid>

					<description><![CDATA[Daniel can you tell me some personal information about you if you can, it interest me :) ?]]></description>
			<content:encoded><![CDATA[<p>Daniel can you tell me some personal information about you if you can, it interest me 🙂 ?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: lol		</title>
		<link>https://ntcore.com/a-malware-with-my-name/#comment-241</link>

		<dc:creator><![CDATA[lol]]></dc:creator>
		<pubDate>Tue, 14 Feb 2012 22:30:57 +0000</pubDate>
		<guid isPermaLink="false">http://rcecafe.net/?p=163#comment-241</guid>

					<description><![CDATA[Don&#039;t come here with your MS false positives, this guy is cool.

If you&#039;re using MS essentials, then you&#039;re using malware. 

NO ONE NEEDS an Anti-virus/anti-malware, at least anyone who is a REAL IT specialist.

For scriptkiddies: IF you are coding in .net find a GOOD commercial/self-made obfuscator, there gui hack solved. 

Set the registry permission on the &#039;run&#039;/runonce key to read only( for everyone)

If you do this in the services key it will require a restart (drivers/services). &#060;--this isn&#039;t advisible since some programs require you install drivers, but it&#039;s good protection for existing services, and to prevent malware.

On the Windows NT key (winlogon/userinit), only allow the system access to read and write, and set your username and other accounts to read only.]]></description>
			<content:encoded><![CDATA[<p>Don&#8217;t come here with your MS false positives, this guy is cool.</p>
<p>If you&#8217;re using MS essentials, then you&#8217;re using malware. </p>
<p>NO ONE NEEDS an Anti-virus/anti-malware, at least anyone who is a REAL IT specialist.</p>
<p>For scriptkiddies: IF you are coding in .net find a GOOD commercial/self-made obfuscator, there gui hack solved. </p>
<p>Set the registry permission on the &#8216;run&#8217;/runonce key to read only( for everyone)</p>
<p>If you do this in the services key it will require a restart (drivers/services). &lt;&#8211;this isn&#039;t advisible since some programs require you install drivers, but it&#039;s good protection for existing services, and to prevent malware.</p>
<p>On the Windows NT key (winlogon/userinit), only allow the system access to read and write, and set your username and other accounts to read only.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Daniel Pistelli		</title>
		<link>https://ntcore.com/a-malware-with-my-name/#comment-240</link>

		<dc:creator><![CDATA[Daniel Pistelli]]></dc:creator>
		<pubDate>Fri, 07 Oct 2011 21:56:32 +0000</pubDate>
		<guid isPermaLink="false">http://rcecafe.net/?p=163#comment-240</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://ntcore.com/a-malware-with-my-name/#comment-239&quot;&gt;dougal holloway&lt;/a&gt;.

There&#039;s no way to stop something like this I&#039;m afraid :)
However, it really didn&#039;t create much of a problem, few people complained to me.
I don&#039;t think that many really think as you said that a real malware writer would sign with his own name its creature.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://ntcore.com/a-malware-with-my-name/#comment-239">dougal holloway</a>.</p>
<p>There&#8217;s no way to stop something like this I&#8217;m afraid 🙂<br />
However, it really didn&#8217;t create much of a problem, few people complained to me.<br />
I don&#8217;t think that many really think as you said that a real malware writer would sign with his own name its creature.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: dougal holloway		</title>
		<link>https://ntcore.com/a-malware-with-my-name/#comment-239</link>

		<dc:creator><![CDATA[dougal holloway]]></dc:creator>
		<pubDate>Wed, 05 Oct 2011 03:09:22 +0000</pubDate>
		<guid isPermaLink="false">http://rcecafe.net/?p=163#comment-239</guid>

					<description><![CDATA[hi guys,,  couldnt help but notice we all saw the same name attached to this cank malware,,  however this was quite a good 1 and took me about 4 hours to remove it froma customers pc,  regardless of google info,, however, my trustee mbam got the better of it thru safe mode,  but just wanted to clarify, that its blatantly obvious that daniel pistelli wouldnt put his name to sucj a stupid malware,,  ( if u created a virus  eg, conficker,  would u REALLY put ur name to it??? ) I DONT THINK SO,, !!,,  however,, top marks for whoever DID create this,, as,,    to be honest,, im a pc engineer, and it STILL took me 4 hours to rid its infection,, so well done,,  thats 4 hours of my life i aint getting back, and round a complete strangers house no less,,  ,, unlucky daniel that ppl are slating u for this malware,,   id look into that if i was u,, see if there was a way u can stop that,,]]></description>
			<content:encoded><![CDATA[<p>hi guys,,  couldnt help but notice we all saw the same name attached to this cank malware,,  however this was quite a good 1 and took me about 4 hours to remove it froma customers pc,  regardless of google info,, however, my trustee mbam got the better of it thru safe mode,  but just wanted to clarify, that its blatantly obvious that daniel pistelli wouldnt put his name to sucj a stupid malware,,  ( if u created a virus  eg, conficker,  would u REALLY put ur name to it??? ) I DONT THINK SO,, !!,,  however,, top marks for whoever DID create this,, as,,    to be honest,, im a pc engineer, and it STILL took me 4 hours to rid its infection,, so well done,,  thats 4 hours of my life i aint getting back, and round a complete strangers house no less,,  ,, unlucky daniel that ppl are slating u for this malware,,   id look into that if i was u,, see if there was a way u can stop that,,</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Daniel Pistelli		</title>
		<link>https://ntcore.com/a-malware-with-my-name/#comment-238</link>

		<dc:creator><![CDATA[Daniel Pistelli]]></dc:creator>
		<pubDate>Mon, 25 Jul 2011 20:01:13 +0000</pubDate>
		<guid isPermaLink="false">http://rcecafe.net/?p=163#comment-238</guid>

					<description><![CDATA[Hello POPTARTCAT,
thanks, I know sandboxie. :)
On x64 the safety sandboxie provides is limited (so be careful), but anyway I would never run any kind of malware on my system, even if sandboxed. Better to use a virtual machine.]]></description>
			<content:encoded><![CDATA[<p>Hello POPTARTCAT,<br />
thanks, I know sandboxie. 🙂<br />
On x64 the safety sandboxie provides is limited (so be careful), but anyway I would never run any kind of malware on my system, even if sandboxed. Better to use a virtual machine.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: POPTARTCAT		</title>
		<link>https://ntcore.com/a-malware-with-my-name/#comment-237</link>

		<dc:creator><![CDATA[POPTARTCAT]]></dc:creator>
		<pubDate>Mon, 25 Jul 2011 18:07:10 +0000</pubDate>
		<guid isPermaLink="false">http://rcecafe.net/?p=163#comment-237</guid>

					<description><![CDATA[Hey Daniel,
 
      It might already be a bit late to tell you;but anyway, you can safely run the malware version of your software in a program called &quot;Sandboxie&quot;. I think it&#039;s just a fun thing to be able to do; running malware without infecting your computer. It&#039;s just a thought, but if you haven&#039;t seen your program&#039;s doppelganger as-of-yet, I strongly believe it will help you.]]></description>
			<content:encoded><![CDATA[<p>Hey Daniel,</p>
<p>      It might already be a bit late to tell you;but anyway, you can safely run the malware version of your software in a program called &#8220;Sandboxie&#8221;. I think it&#8217;s just a fun thing to be able to do; running malware without infecting your computer. It&#8217;s just a thought, but if you haven&#8217;t seen your program&#8217;s doppelganger as-of-yet, I strongly believe it will help you.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: lol		</title>
		<link>https://ntcore.com/a-malware-with-my-name/#comment-236</link>

		<dc:creator><![CDATA[lol]]></dc:creator>
		<pubDate>Thu, 06 Jan 2011 21:36:00 +0000</pubDate>
		<guid isPermaLink="false">http://rcecafe.net/?p=163#comment-236</guid>

					<description><![CDATA[haw haw he &quot;hacked&quot; the gui lol....

your software is beautiful.

no matter....]]></description>
			<content:encoded><![CDATA[<p>haw haw he &#8220;hacked&#8221; the gui lol&#8230;.</p>
<p>your software is beautiful.</p>
<p>no matter&#8230;.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Xylitol		</title>
		<link>https://ntcore.com/a-malware-with-my-name/#comment-235</link>

		<dc:creator><![CDATA[Xylitol]]></dc:creator>
		<pubDate>Tue, 07 Dec 2010 11:45:33 +0000</pubDate>
		<guid isPermaLink="false">http://rcecafe.net/?p=163#comment-235</guid>

					<description><![CDATA[Hello Daniel,
that not about your great article
but just for says, someone have ripped one of your software called &quot;Driver List&quot;
by a guys called Martik.
You can see the rip on his blog here: http://martik-scorp.blogspot.com/2010/12/show-me-loaded-drivers.html
renamed the title etc and says he have coded it, in reallity he have just hacked your GUI with a ressource editor...

regards
__
/Xylitol]]></description>
			<content:encoded><![CDATA[<p>Hello Daniel,<br />
that not about your great article<br />
but just for says, someone have ripped one of your software called &#8220;Driver List&#8221;<br />
by a guys called Martik.<br />
You can see the rip on his blog here: <a href="http://martik-scorp.blogspot.com/2010/12/show-me-loaded-drivers.html" rel="nofollow ugc">http://martik-scorp.blogspot.com/2010/12/show-me-loaded-drivers.html</a><br />
renamed the title etc and says he have coded it, in reallity he have just hacked your GUI with a ressource editor&#8230;</p>
<p>regards<br />
__<br />
/Xylitol</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Daniel Pistelli		</title>
		<link>https://ntcore.com/a-malware-with-my-name/#comment-234</link>

		<dc:creator><![CDATA[Daniel Pistelli]]></dc:creator>
		<pubDate>Wed, 06 Oct 2010 10:41:29 +0000</pubDate>
		<guid isPermaLink="false">http://rcecafe.net/?p=163#comment-234</guid>

					<description><![CDATA[Well, look in the registry in the run and the location can be easily spot the task manager (or task explorer). Just look for a 3-letter named process like &quot;klb.exe&quot;. It uses random letters. Kill it, remove the file, remove the entry in the registry (Run) and that should be it.
I haven&#039;t executed it, but it&#039;s not very difficult.]]></description>
			<content:encoded><![CDATA[<p>Well, look in the registry in the run and the location can be easily spot the task manager (or task explorer). Just look for a 3-letter named process like &#8220;klb.exe&#8221;. It uses random letters. Kill it, remove the file, remove the entry in the registry (Run) and that should be it.<br />
I haven&#8217;t executed it, but it&#8217;s not very difficult.</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>
