<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8757966904836155171</id><updated>2012-02-16T07:39:21.067-08:00</updated><title type='text'>Malware Collecting Blog</title><subtitle type='html'>Blog about malware collecting and malware exchange</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://malwarecollecting.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://malwarecollecting.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>VirusBuster</name><uri>http://www.blogger.com/profile/06798218908877392347</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>16</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8757966904836155171.post-4245559640875992931</id><published>2009-10-28T10:56:00.000-07:00</published><updated>2009-10-28T10:57:18.470-07:00</updated><title type='text'>Bye!</title><content type='html'>Bye, malware collectors of the world!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8757966904836155171-4245559640875992931?l=malwarecollecting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwarecollecting.blogspot.com/feeds/4245559640875992931/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://malwarecollecting.blogspot.com/2009/10/bye.html#comment-form' title='49 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/4245559640875992931'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/4245559640875992931'/><link rel='alternate' type='text/html' href='http://malwarecollecting.blogspot.com/2009/10/bye.html' title='Bye!'/><author><name>VirusBuster</name><uri>http://www.blogger.com/profile/06798218908877392347</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>49</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8757966904836155171.post-7228920674145168451</id><published>2009-10-16T17:30:00.000-07:00</published><updated>2009-10-16T17:32:41.128-07:00</updated><title type='text'>Anyone out there?</title><content type='html'>Hi malware collectors of the world!&lt;br /&gt;&lt;br /&gt;Lately I´m not writing new posts much often because I don´t get any feedback.&lt;br /&gt;&lt;br /&gt;I don´t know if I´m writing for anyone or just for myself.&lt;br /&gt;&lt;br /&gt;If anyone is listening I´ld appreciate some comments. If there is no feedback I will understand that there is no interest on this blog and I´ll stop it.&lt;br /&gt;&lt;br /&gt;Regards.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8757966904836155171-7228920674145168451?l=malwarecollecting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwarecollecting.blogspot.com/feeds/7228920674145168451/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://malwarecollecting.blogspot.com/2009/10/anyone-out-there.html#comment-form' title='2 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/7228920674145168451'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/7228920674145168451'/><link rel='alternate' type='text/html' href='http://malwarecollecting.blogspot.com/2009/10/anyone-out-there.html' title='Anyone out there?'/><author><name>VirusBuster</name><uri>http://www.blogger.com/profile/06798218908877392347</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8757966904836155171.post-396438743766231218</id><published>2009-09-21T01:56:00.001-07:00</published><updated>2009-09-21T02:21:13.085-07:00</updated><title type='text'>Example of the importance of unpacking</title><content type='html'>Hi, malware collectors of the world!&lt;br /&gt;&lt;br /&gt;Today I will make an  entry in the blog to talk about the importance of unpacking packed samples.&lt;br /&gt;&lt;br /&gt;Remember that with packed samples I mean setup, installations, embedded files, files that can be dropped to disk, auto-extractable files (Rar, ZIP, etc).&lt;br /&gt;&lt;br /&gt;KAV can help you to identify that kind of files. Just enable the "Show pack info in the report" option. You can find it at "Options" menu.&lt;br /&gt;&lt;br /&gt;To prove  the importance of unpacking I will show an example.&lt;br /&gt;&lt;br /&gt;9E3F66B6.EX_ is a packed file. Let´s see how many time needs KAV to scan it:&lt;br /&gt;&lt;br /&gt;c:\test\9E3F66B6.EX_/file7 Infected Backdoor.Win32.PcClient.bdud&lt;br /&gt;Scan time 05:50&lt;br /&gt;&lt;br /&gt;Almost 6 minutes to scan the packed file! And that is in a Core i7 computer!!!&lt;br /&gt;&lt;br /&gt;Imagine you have 300 files like that one. Scan them would take over a complete day, probably much more in slower computers, to scan just 300 files. Crazy!&lt;br /&gt;&lt;br /&gt;Now let´s see how many time is required to detect the detected sample inside the packed file:&lt;br /&gt;&lt;br /&gt;c:\test\MSDN_VC.EXE    Infected    Backdoor.Win32.PcClient.bdud    &lt;cd0000.0.e&gt;&lt;br /&gt;Scan time      00:00&lt;br /&gt;&lt;br /&gt;The file is scanned in no time.&lt;br /&gt;&lt;br /&gt;Big big difference, isn´t it?&lt;br /&gt;&lt;br /&gt;Now you should realize the real importance and impact that unpacking stuff may have in the required time to scan your collection.&lt;br /&gt;&lt;br /&gt;See you in next post!&lt;/cd0000.0.e&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8757966904836155171-396438743766231218?l=malwarecollecting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwarecollecting.blogspot.com/feeds/396438743766231218/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://malwarecollecting.blogspot.com/2009/09/example-of-importance-of-unpacking.html#comment-form' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/396438743766231218'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/396438743766231218'/><link rel='alternate' type='text/html' href='http://malwarecollecting.blogspot.com/2009/09/example-of-importance-of-unpacking.html' title='Example of the importance of unpacking'/><author><name>VirusBuster</name><uri>http://www.blogger.com/profile/06798218908877392347</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8757966904836155171.post-8380435700340664414</id><published>2009-09-18T10:14:00.001-07:00</published><updated>2009-09-18T10:43:24.761-07:00</updated><title type='text'>Speed up collection scanning</title><content type='html'>Hi, malware collectors of the world!&lt;br /&gt;&lt;br /&gt;Nowadays one of the problems that collectors have is the required amount of time  to generate new logs. Today I will discuss several methods to speed up collection scanning times.&lt;br /&gt;&lt;br /&gt;In the past virus collections used to take around 200 or 300 MB. With that size it was possible to generate new logs every day, even using several antivirus.&lt;br /&gt;&lt;br /&gt;After year 2000 the amount of samples started to increase heavily and collectors began to generate new logs weekly instead of daily. At the same time all the antivirus used to exchange were dropped and only KAV remained, being  the standard antivirus to  exchange.&lt;br /&gt;&lt;br /&gt;Actually KAV is still the standard antivirus for malware exchange as I commented in other post. So apart of generic ways, I will focus in methods to speed up KAV scanning.&lt;br /&gt;&lt;br /&gt;1.- The most obvious way to boost things is to &lt;span style="font-weight: bold;"&gt;use the best available hardware&lt;/span&gt;. The Intel Core i7 is a good choice. The amount of RAM is not so important but a fast H.D. is.&lt;br /&gt;&lt;br /&gt;2.- An even more obvious way to speed up log creation is to &lt;span style="font-weight: bold;"&gt;use several computers&lt;/span&gt;. Just share the task load between several computers.&lt;br /&gt;&lt;br /&gt;3.- If you are creating logs to trade &lt;span style="font-weight: bold;"&gt;scan only your exchange collection&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;The exchange collection will be formed by unique samples. Don´t keep several copies of the same identified sample.&lt;br /&gt;&lt;br /&gt;4.- Something that slows down KAV very much are the packed samples, so &lt;span style="font-weight: bold;"&gt;unpack all possible packed samples&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Extract detected files from setups/installations, embedded and dropper files.&lt;br /&gt;&lt;br /&gt;Examples of that kind of samples are setups created with: NSIS, Setup Factory, autoextractable files (RAR, ZIP, ...), etc.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Don´t extract compressed files&lt;/span&gt;. I mean files packed with UPX, Armadillo, Themida, MEW, etc. Only extract that kind of files when a setup or installation file is compressed with any of them.&lt;br /&gt;&lt;br /&gt;You will recognize what stuff you must unpack looking at KAV log. Here you can see some examples of the kind of stuff you should process:&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;c:\test\ASTRUM.EX_/data0004 Infected Backdoor.IRC.Seiseni &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\ASTRUM.EX_/data0008 Infected Backdoor.IRC.Seiseni &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\ASTRUM.EX_/data0009 Infected not-a-virus:Client-IRC.Win32.mIRC.601 &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\HMIMYS.EX_/123.exe Infected Backdoor.Win32.Hupigon.ejub &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\INIT1.EX_/data0000 Infected Trojan.Win32.Chinaad.ni &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\INIT2.EX_/data0000 Infected Trojan.Win32.Chinaad.ne &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\INNO.EX_/file19 Infected not-a-virus:FraudTool.Win32.AntiSpywareSoldier.b &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\INNO2.EX_/data0032 Infected not-a-virus:Monitor.Win32.ParentsFriend.a &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\INSTYLER.EX_/astem.as Infected Backdoor.IRC.Zapchast &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\INSTYLER.EX_/bstem.as Infected Backdoor.IRC.Zcrew &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\INSTYLER.EX_/oystem.er Infected Backdoor.IRC.Zcrew &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\KAOS.EX_/data0000.cab/2.exe Infected Backdoor.Win32.Hupigon.ehnx &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\MSC.EX_/MSC.EX_ Infected Trojan-Downloader.Win32.Banload.ddh &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\NBINDER1.EX_/ppp.exe Infected Backdoor.Win32.Turkojan.bkn &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\NBINDER2.EX_/testxxx4.exe/rbot2.exe Infected Backdoor.Win32.Rbot.wnl &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\NBINDER3.EX_/server.exe-crypted.exe Infected Trojan-Dropper.Win32.VB.azv &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\NBINDER4.EX_/svchost.exe Infected Backdoor.Win32.SdBot.ewp &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\NBINDER5.EX_/crypted1.exe Infected Backdoor.Win32.Bifrose.uzu &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\NBINDER6.EX_/dl.exe Infected Trojan-Downloader.Win32.Agent.ahbi &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\NSIS.EX_/data0002 Infected Backdoor.Win32.Visel.afy &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\NSPACKER.EX_/data0000.cab/SERVER~1.EXE Infected Backdoor.Win32.Hupigon.dsx &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\ORIEN.EX_/data0000.cab/SERVER~1.EXE Infected Backdoor.Win32.Hupigon.dsx &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\ORIEN2.EX_/data0000.cab/7.exe Infected Trojan-GameThief.Win32.OnLineGames.tkws &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\PCGUARD1.EX_/data0000.cab/server.exe Infected Trojan.Win32.Midgare.aamx &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\PCGUARD2.EX_/data0000.cab/server.exe Infected Trojan.Win32.Midgare.aadg &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\QBFC.EX_/1 Infected Flooder.Win32.Assault.10 &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\QBFC2.EX_/0 Infected Backdoor.Win32.Netbus.170 &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\RAP.EX_/rinst.exe Infected Trojan.Win32.KillAV.dt &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\SEA.EX_/setup.zip/1/ver.2/AUR.exe Infected IM-Flooder.Win32.AUR.c &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\SEA.EX_/setup.zip/5/HM_comC.exe Infected Trojan.Win32.Delf.kl &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\SEA.EX_/setup.zip/6/icq-brute.exe Infected HackTool.Win32.BruteForce.u &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\SEA.EX_/setup.zip/8/1.5.191_Pro/IPDbrute_1.5.191.exe Infected not-a-virus:PSWTool.Win32.IpdBrute.15 &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\SEA.EX_/setup.zip/8/IPDbrute_2.0_Lite/IPDbrute_2.0_Lite.exe Infected not-a-virus:PSWTool.Win32.IpdBrute.20 &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\SEA.EX_/setup.zip/8/IPDbrute_2.0_Pro_old/IPDbrute2.exe Infected not-a-virus:PSWTool.Win32.IpdBrute.20 &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\SEA.EX_/setup.zip/11/recover.exe Infected not-a-virus:PSWTool.Win32.ICQ.y &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\SEA.EX_/setup.zip/12/UIC.exe Infected Flooder.Win32.Agent.bb &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\SEA.EX_/setup.zip/16 Infected not-a-virus:PSWTool.Win32.ICQ.v &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\SEA2.EX_/setup.zip/25 Infected not-a-virus:Client-IRC.Win32.mIRC.603 &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\SEA2.EX_/setup.zip/26 Infected not-a-virus:RiskTool.Win32.HideWindows &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\SIM.EX_/data1 Infected Trojan.BAT.KillFiles.ge &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\SVKP.EX_/data0000.cab/4_BK_BK.exe Infected Packed.Win32.PolyCrypt.b &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\THINSTAL.EX_/AQ.exe Infected Trojan-Downloader.Win32.Small.akjq &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\UPACK.EX_/data0000.cab/lin2.exe Infected Trojan-Downloader.Win32.BHO.un &lt;cd0000.0.e&gt;&lt;br /&gt;c:\test\UPACK.EX_/data0000.cab/rmt-live.exe Infected Trojan.Win32.Inject.ihr &lt;cd0000.0.e&gt;&lt;br /&gt;&lt;/pre&gt;5.- &lt;span style="font-weight: bold;"&gt;Don´t scan very old files&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;Move apart old files (files you got from year 2002 and older) and don´t scan them every week. Maybe once per month will be enough.&lt;br /&gt;&lt;br /&gt;Why this? Because KAV probably will not change the identification names of that samples, so the ID will remain equal week after week.&lt;br /&gt;&lt;/span&gt;&lt;span class="gensmall"&gt;&lt;/span&gt;&lt;br /&gt;If anyone have any other trick to speed up log creation he will be welcome.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8757966904836155171-8380435700340664414?l=malwarecollecting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwarecollecting.blogspot.com/feeds/8380435700340664414/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://malwarecollecting.blogspot.com/2009/09/speed-up-collection-scanning.html#comment-form' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/8380435700340664414'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/8380435700340664414'/><link rel='alternate' type='text/html' href='http://malwarecollecting.blogspot.com/2009/09/speed-up-collection-scanning.html' title='Speed up collection scanning'/><author><name>VirusBuster</name><uri>http://www.blogger.com/profile/06798218908877392347</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8757966904836155171.post-3573783700897763641</id><published>2009-09-04T02:22:00.000-07:00</published><updated>2009-09-04T02:55:58.588-07:00</updated><title type='text'></title><content type='html'>Hi, malware collectors of the world. I hope you have had nice holidays!&lt;br /&gt;&lt;br /&gt;After a vacational stop I continue the activity of the blog.&lt;br /&gt;&lt;br /&gt;Today I will make an entry commenting how many collections you should have and what kind of trader you can be.&lt;br /&gt;&lt;br /&gt;I suggest you build two malware collections:&lt;br /&gt;&lt;br /&gt;Collection number one would be a collection used to exchange with other collectors. This collection must contain only unique samples; That means one file for each uniquely identified malware, virus, worm or whatever. We will call this collection the 'trading collection'.&lt;br /&gt;&lt;br /&gt;Collection number two would be a collection containing all the malware samples you got minus the samples you already have in the collection number one. We will call this collection as the 'main collection'.&lt;br /&gt;&lt;br /&gt;You should scan and make new log of trading collection weekly. Depending of the size of this collection and the hardware you use, it should not take more than a few hours to scan it.&lt;br /&gt;&lt;br /&gt;Main collection, depending also of its size and the hardware you use, will take much more time than trading collection to scan. You will have to evaluate the amount of time required to scan main collection and decide how often you want to scan it.&lt;br /&gt;&lt;br /&gt;The objective of scanning main collection should be to find new unique malwares and add them to trading collection.&lt;br /&gt;&lt;br /&gt;There are two types of malware collectors: there is the traditional collector that only exchanges new unique samples and there is a collector that will exchange samples using a hash to know if a sample is new for him.&lt;br /&gt;&lt;br /&gt;In the first case, the collector that exchanges for unique samples uses KAV log to know what he has in the collection and what he misses from other trader´s logs.&lt;br /&gt;&lt;br /&gt;In the second case, the collector does not need to make KAV logs because he uses MD5, SHA-1 or whatever hash to exchange. This kind of collector would not need to make a trading and a main collection. He only would build a main collection.&lt;br /&gt;&lt;br /&gt;Mainly you will meet traditional collectors, people that will exchange for unique samples using KAV log. Some of them will accept to make hash trades also. The problem with hash trades is the amount of information that must be exchanged. Doing hash trades over internet will be really difficult.&lt;br /&gt;&lt;br /&gt;See you soon!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8757966904836155171-3573783700897763641?l=malwarecollecting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwarecollecting.blogspot.com/feeds/3573783700897763641/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://malwarecollecting.blogspot.com/2009/09/hi-malware-collectors-of-world.html#comment-form' title='2 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/3573783700897763641'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/3573783700897763641'/><link rel='alternate' type='text/html' href='http://malwarecollecting.blogspot.com/2009/09/hi-malware-collectors-of-world.html' title=''/><author><name>VirusBuster</name><uri>http://www.blogger.com/profile/06798218908877392347</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8757966904836155171.post-5648961424876505579</id><published>2009-07-31T14:21:00.001-07:00</published><updated>2009-07-31T15:01:47.156-07:00</updated><title type='text'>How to sort a malware collection</title><content type='html'>Hi, malware collectors of the world!&lt;br /&gt;&lt;br /&gt;Today I´ll discuss the different options we can decide about how to sort our malware collection.&lt;br /&gt;&lt;br /&gt;Collection packed or collection unpacked?&lt;br /&gt;&lt;br /&gt;I always have considered that having the collection packed is the best decission for multiple reasons. Almost every consideration is a pro for having the collection packed and there are no contras almost; meanwhile  having the collection unpacked has lots of contras in my opinion.&lt;br /&gt;&lt;br /&gt;Pros of having the collection packed:&lt;br /&gt;&lt;br /&gt;* Making backups will be  easier.&lt;br /&gt;&lt;br /&gt;You  create new archives containing new stuff so backups are incremental, no need to backup everything everytime.&lt;br /&gt;&lt;br /&gt;* C0llection will take less space on hard disk.&lt;br /&gt;&lt;br /&gt;* KAV scans a packed collection as fast as an unpacked one. Some tests even say that it´s faster.&lt;br /&gt;&lt;br /&gt;* Verifying the integrity of the collection is easier.&lt;br /&gt;&lt;br /&gt;You just need to run the test function of WinZIP to know if everything is ok. Checking if something is wrong with an unpacked collections takes more time as you must run a check of the whole drive storing the collection.&lt;br /&gt;&lt;br /&gt;The only contra is the amount of time required to compress new files but as we will compress just a few files every day that´s not relevant.&lt;br /&gt;&lt;br /&gt;There are other reasons but I´ll discuss some of them in future posts.&lt;br /&gt;&lt;br /&gt;How to name files?&lt;br /&gt;&lt;br /&gt;Some traders used to like to name files by the identification  given by KAV. I always considered this as a mistake because identifications may be modified so the file name would be wrong.&lt;br /&gt;&lt;br /&gt;I consider that it has more advantages having the files named by a hash, like MD5, SHA-1 or SHA-256.&lt;br /&gt;&lt;br /&gt;You can use RenFiles to rename files to MD5 or SHA-256.&lt;br /&gt;&lt;br /&gt;How to name file extensions?&lt;br /&gt;&lt;br /&gt;Using KAV the file extension is not relevant as identification will not change depending if the file has the right extension or not.&lt;br /&gt;&lt;br /&gt;Some collectors prefer extensions like .VXE or .VLL instead .EXE and .DLL to avoid infections.&lt;br /&gt;&lt;br /&gt;A good collector should be able to manage a collection having the right extensions on files because he manages the files in a safe environment. A safe environment is that one where you can not run a virus or malware accidentally.&lt;br /&gt;&lt;br /&gt;If you want to name files by their right extension use RenFiles.&lt;br /&gt;&lt;br /&gt;What folder structure should I use to store the collection?&lt;br /&gt;&lt;br /&gt;If you decide to follow my tip and keep the collection packed you don´t need a folder structure. Just decide a file size limit for the ZIP (I recommed ZIP to pack) and add new files until you reach the limit. When you reach it continue compressing on next archive. You can use consecutive numbers to name archives. Like:&lt;br /&gt;&lt;br /&gt;MALW00001.ZIP&lt;br /&gt;MALW00002.ZIP&lt;br /&gt;MALW00003.ZIP&lt;br /&gt;MALW00004.ZIP&lt;br /&gt;.&lt;br /&gt;.&lt;br /&gt;.&lt;br /&gt;&lt;br /&gt;If you decide you want an unpacked collection then continue reading.&lt;br /&gt;&lt;br /&gt;Years ago many collectors liked having the folder structure based in the KAV identification name. Something like:&lt;br /&gt;&lt;br /&gt;C:\COLLECTION\T\Trojan\Win32\Example\a\FILE.EXE&lt;br /&gt;&lt;br /&gt;or&lt;br /&gt;&lt;br /&gt;C:\COLLECTION\T\Trojan.Win32.Example.a\FILE.EXE&lt;br /&gt;&lt;br /&gt;Several tools were created to process files and copy/move them to such structures using KAV logs.&lt;br /&gt;&lt;br /&gt;If you like that folder structure method to sort the collection you can download VS2000 GUI and use it. You can get VS2000 GUI from &lt;a href="http://kavdefs.net23.net/vs2000%20gui/vs2000%20gui.rar"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;You have that feature under "Virus organizer" tab.&lt;br /&gt;&lt;br /&gt;There are 5 different folder structure types available. You can see examples of how collection will look like clicking in the "?" buttons.&lt;br /&gt;&lt;br /&gt;If I´m forced to use a folder structure then the folder structure method I prefer is the one called "Bulk". It´s based in the hash of the file. There is a root folder and inside 16 folders, from 0-9 and A-F. Inside those folders there are other 16 subfolders with the first 2 chars of the hash. 16*16 folders in total. Something like:&lt;br /&gt;&lt;br /&gt;C:\MALWARE\0\00&lt;br /&gt;C:\MALWARE\0\01&lt;br /&gt;C:\MALWARE\0\02&lt;br /&gt;.&lt;br /&gt;.&lt;br /&gt;C:\MALWARE\A\A0&lt;br /&gt;C:\MALWARE\A\A1&lt;br /&gt;C:\MALWARE\A\A2&lt;br /&gt;.&lt;br /&gt;.&lt;br /&gt;C:\MALWARE\F\FE&lt;br /&gt;C:\MALWARE\F\FF&lt;br /&gt;&lt;br /&gt;This is one of the five available structures in VS2000 GUI.&lt;br /&gt;&lt;br /&gt;And that´s all you must decide about how to sort your malware collection. A fast resume:&lt;br /&gt;&lt;br /&gt;Decide if you want collection packed or unpacked&lt;br /&gt;&lt;br /&gt;Decide how to name files&lt;br /&gt;&lt;br /&gt;Decide how to name extensions&lt;br /&gt;&lt;br /&gt;If you decide an unpacked collection then decide the folder structure.&lt;br /&gt;&lt;br /&gt;My "setup" is:&lt;br /&gt;&lt;br /&gt;Collection packed (using ZIP format).&lt;br /&gt;&lt;br /&gt;File names by their SHA-256&lt;br /&gt;&lt;br /&gt;Files having the right extension&lt;br /&gt;&lt;br /&gt;File size for archives: around 200 and 300 MB. More can be problematic for KAV.&lt;br /&gt;&lt;br /&gt;File names for archives: VIRUS001.ZIP, VIRUS002.ZIP, etc&lt;br /&gt;&lt;br /&gt;And that´s all for now. See you soon!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8757966904836155171-5648961424876505579?l=malwarecollecting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwarecollecting.blogspot.com/feeds/5648961424876505579/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/how-to-sort-malware-collection.html#comment-form' title='2 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/5648961424876505579'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/5648961424876505579'/><link rel='alternate' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/how-to-sort-malware-collection.html' title='How to sort a malware collection'/><author><name>VirusBuster</name><uri>http://www.blogger.com/profile/06798218908877392347</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8757966904836155171.post-7308508587181098611</id><published>2009-07-30T07:23:00.000-07:00</published><updated>2009-07-30T07:32:56.883-07:00</updated><title type='text'>RenFiles: the file renamer for malware collectors</title><content type='html'>Hi, malware collectors of the world!&lt;br /&gt;&lt;br /&gt;Today I´ll introduce  RenFiles.&lt;br /&gt;&lt;br /&gt;RenFiles is a tool (command line) designed to rename file names and file extensions on demand.&lt;br /&gt;&lt;br /&gt;This tool is recursive, so you can specify a folder and all files inside will be renamed.&lt;br /&gt;&lt;br /&gt;RenFiles is able to rename file names to their CRC32, MD5 or SHA-256 hash depending of the used command.&lt;br /&gt;&lt;br /&gt;RenFiles is also able to rename file extensions to the proper of each file with big accuracy.&lt;br /&gt;&lt;br /&gt;Having the files named by their proper extension used to be very important because some antivirus were giving a different report depending of the file extension. KAV 4.5 doesn´t have this problem but anyway having files named properly is more "professional".&lt;br /&gt;&lt;br /&gt;RenFiles has other features but the most important ones are the described above.&lt;br /&gt;&lt;br /&gt;You can find a manual of RenFiles &lt;a href="http://kavdefs.net23.net/renfiles/renfiles%20manual.rar"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;You can get RenFiles binary &lt;a href="http://kavdefs.net23.net/renfiles/renfiles.rar"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Next posts will be related to collection storage and sorting methods.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8757966904836155171-7308508587181098611?l=malwarecollecting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwarecollecting.blogspot.com/feeds/7308508587181098611/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/renfiles-file-renamer-for-malware.html#comment-form' title='1 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/7308508587181098611'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/7308508587181098611'/><link rel='alternate' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/renfiles-file-renamer-for-malware.html' title='RenFiles: the file renamer for malware collectors'/><author><name>VirusBuster</name><uri>http://www.blogger.com/profile/06798218908877392347</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8757966904836155171.post-5339102171202413011</id><published>2009-07-27T10:55:00.000-07:00</published><updated>2009-07-27T11:05:34.971-07:00</updated><title type='text'>StripLog: the right hand of VS2000</title><content type='html'>Hi, malware collectors of the world!&lt;br /&gt;&lt;br /&gt;Today I´ll talk about StripLog.&lt;br /&gt;&lt;br /&gt;StripLog is a tool designed to work with antivirus logs, specially KAV 4.5 logs.&lt;br /&gt;&lt;br /&gt;The main objective of StripLog is to copy/move/delete the files that appear in logs.&lt;br /&gt;&lt;br /&gt;Imagine you receive a request from other trader of 100 files. You must take the 100 files from the request, copy them to a folder and pack the files to send. StripLog will do this work for you.&lt;br /&gt;&lt;br /&gt;StripLog has the ability to unpack files from ZIP/RAR/7Z files.&lt;br /&gt;&lt;br /&gt;StripLog is able to do other tasks like killing empty directories or delete zero byte files.&lt;br /&gt;&lt;br /&gt;You can read about all StripLog functions and the manual. Get it from &lt;a href="http://kavdefs.net23.net/striplog/striplog%20manual.rar"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;You can get StripLog from &lt;a href="http://kavdefs.net23.net/striplog/striplog.rar"&gt;here&lt;/a&gt;. Inside the RAR package you will find 2 DLLs. You must copy them to %WINDIR%\System32.&lt;br /&gt;&lt;br /&gt;There is not much to say about StripLog but it´s really an useful tool for collectors. It makes the work of managing files pretty easy.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8757966904836155171-5339102171202413011?l=malwarecollecting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwarecollecting.blogspot.com/feeds/5339102171202413011/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/striplog-right-hand-of-vs2000.html#comment-form' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/5339102171202413011'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/5339102171202413011'/><link rel='alternate' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/striplog-right-hand-of-vs2000.html' title='StripLog: the right hand of VS2000'/><author><name>VirusBuster</name><uri>http://www.blogger.com/profile/06798218908877392347</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8757966904836155171.post-4381775591607288146</id><published>2009-07-25T07:59:00.001-07:00</published><updated>2009-07-25T08:52:57.523-07:00</updated><title type='text'>File Weeding: Keep clean your collection of duplicate files</title><content type='html'>Hi, malware collectors of the world!&lt;br /&gt;&lt;br /&gt;Today I will comment about file weeders.&lt;br /&gt;&lt;br /&gt;A file weeder is a tool that looks for identical files and by default or on demand deletes them. Some  weeders allow the user to choose what duplicate files to delete and what ones to keep.&lt;br /&gt;&lt;br /&gt;In terms of malware collecting the most important thing to consider before deciding what file weeder to use is what hash algorithm we want to use.&lt;br /&gt;&lt;br /&gt;In the first years of collecting most collectors used ThunderByte Weeder aka TbWeeder. This weeder was done by the same author of ThunderByte Antivirus, Frans Veldman, and it used a CRC16 hash.&lt;br /&gt;&lt;br /&gt;Some years later the first collisions (different files having same hash) for CRC16 appeared in virus collections so collectors switched to weeders using CRC32 hashing.&lt;br /&gt;&lt;br /&gt;Around year 2000 some collectors started to use MD5 hash and some stayed with CRC32.&lt;br /&gt;&lt;br /&gt;After 2000 the story repeats and first CRC32 collisions appear in virus collections. As workaround solution for these CRC32 collisions, two weeders (VirWeed and FWeeder) are created, using CRC32 hashing plus file size checking to verify for duplicates.&lt;br /&gt;&lt;br /&gt;At the beginning I thought it was not possible that two different files may have the same CRC32 and file size but this was proved to be wrong. This was the end of the use of CRC32 between virus collectors.&lt;br /&gt;&lt;br /&gt;Actually traders use MD5 weeders or SHA-1. Some months ago I decided to change the hash of my file weeder and initially I considered using MD5 but I was told that generating collisions for MD5 was simple so I decided to go with SHA-256.&lt;br /&gt;&lt;br /&gt;I´m not aware of MD5 collisions in malware collections so I´ld say that at the moment using a weeder that uses  MD5 is safe.&lt;br /&gt;&lt;br /&gt;If you decide to use a MD5 weeder I recommend FAST! File Weeder (FWeeder) by my friend Bumblebee. Right now it´s open source.&lt;br /&gt;&lt;br /&gt;You can get source code &lt;a href="http://kavdefs.net23.net/fweeder/fweeder-ose.zip"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;You can get binary &lt;a href="http://kavdefs.net23.net/fweeder/fweeder.zip"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I will give a brief description of how to use FWeeder.&lt;br /&gt;&lt;br /&gt;FWeeder is a command line tool. Run "fweeder -h" to get the help screen.&lt;br /&gt;&lt;br /&gt;To create a database of our collection run: fweeder -c &lt;path&gt;. Example: fweeder -c c:\virus&lt;br /&gt;&lt;br /&gt;To add new entries to database (new files you got in your collection) run: fweeder -a &lt;path&gt;. Example: fweeder -a c:\newvirus&lt;br /&gt;&lt;br /&gt;To look for duplicate files run: fweeder -v &lt;path&gt;. Example: fweeder -v c:\test&lt;br /&gt;&lt;br /&gt;By default FWeeder will not delete duplicated files. You must add "-k" switch. Examples:&lt;br /&gt;&lt;br /&gt;fweeder -c c:\virus -k&lt;br /&gt;fweeder -a c:\newvirus -k&lt;br /&gt;fweeder -v c:\test -k&lt;br /&gt;&lt;br /&gt;With that information you have the basic information to weed your collection.&lt;br /&gt;&lt;br /&gt;Old weeders were dangerous when used by inexpert hands. Some collectors deleted their collections because they created a database and then looked for duplicates in their own collection!!!&lt;br /&gt;&lt;br /&gt;FWeeder has a "newbie" protection to avoid that situation but anyway it´s always a good idea to make a backup of your collection.&lt;br /&gt;&lt;br /&gt;I will make a post exclusively to talk about backups and how important they are but before I do it... make a backup.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8757966904836155171-4381775591607288146?l=malwarecollecting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwarecollecting.blogspot.com/feeds/4381775591607288146/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/file-weeding-keep-clean-your-collection.html#comment-form' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/4381775591607288146'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/4381775591607288146'/><link rel='alternate' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/file-weeding-keep-clean-your-collection.html' title='File Weeding: Keep clean your collection of duplicate files'/><author><name>VirusBuster</name><uri>http://www.blogger.com/profile/06798218908877392347</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8757966904836155171.post-7305896004815727416</id><published>2009-07-22T10:47:00.001-07:00</published><updated>2009-07-22T11:36:32.117-07:00</updated><title type='text'>VirSort: long life to the king of the virus collecting tools!</title><content type='html'>Hi, malware collectors of the world!&lt;br /&gt;&lt;br /&gt;Today I will dedicate my post to the tool that has been more years around virus collectors: VirSort.&lt;br /&gt;&lt;br /&gt;VirSort was written many years ago and it has been rewritten by different people several times.&lt;br /&gt;&lt;br /&gt;Let´s start with a lesson of history.&lt;br /&gt;&lt;br /&gt;Christian Julius is the father of the virus sorting tool called VirSort. Here we can read the documentation he added to the first package he released:&lt;br /&gt;&lt;blockquote&gt;&lt;/blockquote&gt;V I R S O R T 1.1 beta&lt;br /&gt;&lt;br /&gt;Why you need Virsort?&lt;br /&gt;&lt;p&gt;    You collect virii and the collection growed up to a few thousand     samples and each week you get another few hundred samples?&lt;/p&gt;   &lt;p&gt;    Than you have the problem to analyse and sort them into directories     spending hours while doing do.&lt;/p&gt;   &lt;p&gt;    VIRSORT takes this work away from you. It analyzes a scan list from     the popular anti-virus program F-Prot by Fridrik Skulason and     compares the incoming virii against your own. After doing so it sorts     out the dupes and copies the new virii in separate directories.&lt;/p&gt;   &lt;p&gt;    How to use:&lt;/p&gt;   &lt;p&gt;    1. Make an F-Prot list of your virii and don't forget to add the     /nowrap command line parameter.&lt;/p&gt;   &lt;p&gt;    2. Copy this list in the same directory as virsort.exe&lt;/p&gt;   &lt;p&gt;    3. Type virsort -b &lt;fprot.list&gt; to create a database and you'll     get some few files:&lt;/fprot.list&gt;&lt;/p&gt;   &lt;p&gt;      virsort.dat = The database&lt;/p&gt;   &lt;p&gt;      unsort.log = Suspicious files not identified 100% (sort them     in manually&lt;/p&gt;   &lt;p&gt;      new_vir.log = The new virii&lt;/p&gt;   &lt;p&gt;      trojans.log = Trojan horses&lt;/p&gt;   &lt;p&gt;      variants.log = New or modified virii&lt;/p&gt;   &lt;p&gt;      possible.log = Possibly infected files&lt;/p&gt;   &lt;p&gt;    4. Type in virsort -s &lt;database&gt; &lt;target-directory&gt; &lt;-     no backslash at the end and virsort will create new directories and     copies the viruses into them.&lt;/target-directory&gt;&lt;/database&gt;&lt;/p&gt;   &lt;p&gt;      You can use the -sd switch instead to move the files into the     target directory, othwise they'll be copied.&lt;/p&gt;   &lt;p&gt;      Note: The dupes are not removed. I'll fix this in future     versions of my software.&lt;/p&gt;   &lt;p&gt;    5. You get a new collection?&lt;/p&gt;   &lt;p&gt;      Make a F-Prot file and type&lt;/p&gt;   &lt;p&gt;      virsort -c &lt;new-fprot-log&gt; &lt;output-file&gt;&lt;/output-file&gt;&lt;/new-fprot-log&gt;&lt;/p&gt;   &lt;p&gt;      The output file contains the new virii list in binary format.&lt;/p&gt;   &lt;p&gt;      Go to step 4 to sort them in.&lt;/p&gt;   &lt;p&gt;      Virsort asks you for updating your database now.&lt;/p&gt;   &lt;p&gt;      If you type 'y' the incoming virii are added to your database     and the old database is deleted.&lt;/p&gt;   &lt;p&gt;    I can't garantee that there are no bugs in it, if you recognize some     please let me know.&lt;/p&gt;   &lt;p&gt;    This software is published as Public Domain, so you can spread it to     everybody who wants it, but you are not allowed to take a fee for it.&lt;/p&gt;   &lt;p&gt;    Further and improved versions will be published as Shareware.&lt;/p&gt;   &lt;p&gt;    Please apologize any spelling mistakes.&lt;/p&gt;   &lt;p&gt;    Christian Julius&lt;/p&gt;   &lt;p&gt;    Germany&lt;/p&gt;   &lt;p&gt;    email: chj@ing.ruhr.de&lt;/p&gt;&lt;p&gt;That´s the information the author included in the first release of the package.&lt;/p&gt;&lt;p&gt;It´s not clear if Brian Burdick (Shadow Seeker) continued coding on that version done by Christian Julius or if he started a new version from scratch. Anyway he initiated the second phase of the development. At some point the project went to Jim Fougeron (Poltergeist) hands.&lt;/p&gt;&lt;p&gt;Polt was in charge of the project for some time but around 1997 more or less he left the trading scene. He sent VirSort source code to Spooky but Spooky never continued with the development. This second release of VirSort was coded in C++.&lt;/p&gt;&lt;p&gt;When it was obvious that Spooky was not going to continue working on the tool Brian started a new version of VirSort (third stage in the history of VirSort). This time Brian coded the tool in Pascal and renamed the tool to VirSort 2000 or just VS2000 as it´s better known nowadays.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;After a few releases Brian gave up development, a bit because he had not much time and a bit because he considered the tool already had the required features. This happened in 1998.&lt;/p&gt;&lt;p&gt;I was not satisfied with the features as I wanted more included. I asked him the source code to continue improving it. In that moment I had no idea of Pascal. Brian also sent the source code to Ralph Roth. It was supposed that both Ralph and me would continue with the development but finally I was the only one keeping the updating work And that´s how it has been from 1998 to right now.&lt;/p&gt;&lt;p&gt;In the fourth stage I started improving Brian´s code but at some point I rewritten almost from scratch the tool. Initially the tool was being compiled with Turbo Pascal, after a while with Free Pascal and right now it´s being coded in Delphi.&lt;/p&gt;&lt;p&gt;The amount of features is so big that explaining all them would take lots of space. It´s better if I explain the main features and you learn to use the others as you need them. You can find a manual (a bit outdated but still valid) &lt;a href="http://kavdefs.net23.net/vs2000/vs2000%20manual.rar"&gt;here&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;There are 3 main functions: build a database, compare a log and add new stuff to existing database.&lt;/p&gt;&lt;p&gt;Build a database: -B. Example: VS2000 -B AVP.LOG&lt;/p&gt;&lt;p&gt;Compare a log: -C. Exampe: VS2000 -C OTHER_TRADER.LOG&lt;/p&gt;&lt;p&gt;Add new stuff to your database: -A. Example: VS2000 -A AVP2.LOG&lt;/p&gt;&lt;p&gt;Pretty easy to use.&lt;/p&gt;&lt;p&gt;I didn´t mention it before but VirSort always has been a command line tool.&lt;/p&gt;&lt;p&gt;Many traders I have met in my years in the trading scene prefered GUI tools but I must say that most of the best tools for collecting are usually those ones running at command line.&lt;/p&gt;&lt;p&gt;You can find VS2000 for Win32 &lt;a href="http://kavdefs.net23.net/vs2000/vs2000%20console%20for%20win32.rar"&gt;here&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;I also compiled a version of VS2000 for Linux. You can find it &lt;a href="http://kavdefs.net23.net/vs2000/vs2000%20console%20for%20linux.rar"&gt;here&lt;/a&gt; but Linux version is not supported and it has not been tested deeply.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;VS2000 is so professional that even people from antivirus vendors have used it. Some of them asked for the inclusion of support of the reports generated with their antivirus.&lt;/p&gt;&lt;p&gt;Enough about VS2000! You better go and try it!&lt;br /&gt;&lt;/p&gt;&lt;span style="color:WHITE;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8757966904836155171-7305896004815727416?l=malwarecollecting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwarecollecting.blogspot.com/feeds/7305896004815727416/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/virsort-long-life-to-king-of-virus.html#comment-form' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/7305896004815727416'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/7305896004815727416'/><link rel='alternate' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/virsort-long-life-to-king-of-virus.html' title='VirSort: long life to the king of the virus collecting tools!'/><author><name>VirusBuster</name><uri>http://www.blogger.com/profile/06798218908877392347</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8757966904836155171.post-262257805892227958</id><published>2009-07-21T00:47:00.001-07:00</published><updated>2009-07-21T01:51:47.434-07:00</updated><title type='text'>KAV 4.5 - The antivirus of the traders</title><content type='html'>Hi, malware collectors of the world!&lt;br /&gt;&lt;br /&gt;This entry in the blog will be dedicated to the antivirus that all malware collectors use to exchange and that you can use to catalog your collection.&lt;br /&gt;&lt;br /&gt;You can download KAV 4.5 &lt;a href="ftp://ftp.kaspersky.ee/products/homeuser/old/kavpersonalpro/4.5/kav4.5.0.104_personalpro_eng.exe"&gt;from this link&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;You launch the installer and the welcome screen appears. Click "Next &gt;".&lt;br /&gt;&lt;br /&gt;Now you must choose a temporal folder where KAV will decompress installation files. Click "Next &gt;" when you are done.&lt;br /&gt;&lt;br /&gt;Another welcome screen appears. Click "Next &gt;" again. Click "Yes" to accept license agreement. Does anyone in the world read that?&lt;br /&gt;&lt;br /&gt;Introduce customer information and click "Next &gt;".&lt;br /&gt;&lt;br /&gt;Choose destination folder for KAV and don´t touch the common files folder. Click "Next &gt;".&lt;br /&gt;&lt;br /&gt;Select program folder. Default will be fine. Click "Next &gt;".&lt;br /&gt;&lt;br /&gt;Choose "Custom" setup type and click "Next &gt;".&lt;br /&gt;&lt;br /&gt;Everything must be disabled except: Kaspersky Anti-Virus Core Components, Kaspersky Anti-Virus Bases, Kaspersky Anti-Virus Scanner and Kaspersky Anti-Virus Updater. Click "Next &gt;". Like this:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_jZ8ITICq63o/SmV3aFOA_zI/AAAAAAAAAAM/VWKG8fKpqsA/s1600-h/kav_screen_01.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 306px;" src="http://4.bp.blogspot.com/_jZ8ITICq63o/SmV3aFOA_zI/AAAAAAAAAAM/VWKG8fKpqsA/s400/kav_screen_01.jpg" alt="" id="BLOGGER_PHOTO_ID_5360822221415710514" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Click "Next &gt;" in the "Start Copying Files" screen.&lt;br /&gt;&lt;br /&gt;You can associate report files (*.REP and *.RPT) to KAV´s Report Viewer utility. This is not really necessary and you can skip the association if you want. You must configure where you want to store report files. Click "Next &gt;" when you are done.&lt;br /&gt;&lt;br /&gt;Add your valid key file and click "Next &gt;".&lt;br /&gt;&lt;br /&gt;Don´t enable the "Launch Kaspersky Anti-Virus Updater" checkbox and click "Finish".&lt;br /&gt;&lt;br /&gt;If you pretend to exchange with malware collectors you should run "Kaspersky Anti-Virus Updater" and configure it properly. For this you must do:&lt;br /&gt;&lt;br /&gt;In the welcome screen of Kaspersky Anti-Virus Updater enable the "Change settings" checkbox. Click "Next &gt;".&lt;br /&gt;&lt;br /&gt;Open "Update Kaspersky Anti-Virus from Internet" tree and click in the "..." button. Select all links and click the "Delete URL" icon. Click in the "Add URL" icon and introduce next link:&lt;br /&gt;&lt;br /&gt;http://66.232.119.78/~largefus/AVP/&lt;br /&gt;&lt;br /&gt;It will look like this:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_jZ8ITICq63o/SmV42qwVDcI/AAAAAAAAAAU/Ah1xyLkS-wM/s1600-h/kav_screen_02.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 296px;" src="http://3.bp.blogspot.com/_jZ8ITICq63o/SmV42qwVDcI/AAAAAAAAAAU/Ah1xyLkS-wM/s400/kav_screen_02.jpg" alt="" id="BLOGGER_PHOTO_ID_5360823812039708098" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Click "Next &gt;" twice and Kaspersky Anti-Virus should start updating databases. If you receive an error message telling the updater can not obtain contents means that Kaspersy Anti-Virus, for some reason I never was able to understand, will not work. In this case you can try using the KAV Updater tool I coded for this situation. You can retrieve it from &lt;a href="http://kavdefs.net23.net/kav%20updater/kav%20updater.rar"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;If you don´t plan exchanging with collectors you can skip the above steps and update KAV defs using default KAV servers.&lt;br /&gt;&lt;br /&gt;You must consider with what periodicity you will update KAV defs. If you use the server used by traders you must know defs are updated one time per week.&lt;br /&gt;&lt;br /&gt;Now launch the Kaspersky Anti-Virus Scanner. It´s time to configure it.&lt;br /&gt;&lt;br /&gt;Click in the "Expert" button at left side. (bottom)&lt;br /&gt;&lt;br /&gt;"Options" should be configured like this:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_jZ8ITICq63o/SmWABGU5Y-I/AAAAAAAAAAc/9PRsQebhwPw/s1600-h/kav_screen_03.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 293px;" src="http://1.bp.blogspot.com/_jZ8ITICq63o/SmWABGU5Y-I/AAAAAAAAAAc/9PRsQebhwPw/s400/kav_screen_03.jpg" alt="" id="BLOGGER_PHOTO_ID_5360831687820927970" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Just change the path of the report file to the one you prefer.&lt;br /&gt;&lt;br /&gt;"Customize" should be configured like this:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_jZ8ITICq63o/SmWAa3HrAEI/AAAAAAAAAAk/xYgI1QuBFBQ/s1600-h/kav_screen_04.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 388px; height: 301px;" src="http://2.bp.blogspot.com/_jZ8ITICq63o/SmWAa3HrAEI/AAAAAAAAAAk/xYgI1QuBFBQ/s400/kav_screen_04.jpg" alt="" id="BLOGGER_PHOTO_ID_5360832130415525954" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Now go the menus and click "File -&gt; Save profile as default". Save the file in the same folder you installed KAV.&lt;br /&gt;&lt;br /&gt;And that´s all. You have KAV ready to be used.&lt;br /&gt;&lt;br /&gt;KAV can be launched from command line. The proper command line to use  is:&lt;br /&gt;&lt;pre&gt;AVP32 /S /W /Q C:\FOLDER_TO_SCAN&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Georgia,serif;"&gt;If anyone has any doubt just drop a comment.&lt;/span&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8757966904836155171-262257805892227958?l=malwarecollecting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwarecollecting.blogspot.com/feeds/262257805892227958/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/kav-45-antivirus-of-traders.html#comment-form' title='1 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/262257805892227958'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/262257805892227958'/><link rel='alternate' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/kav-45-antivirus-of-traders.html' title='KAV 4.5 - The antivirus of the traders'/><author><name>VirusBuster</name><uri>http://www.blogger.com/profile/06798218908877392347</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_jZ8ITICq63o/SmV3aFOA_zI/AAAAAAAAAAM/VWKG8fKpqsA/s72-c/kav_screen_01.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8757966904836155171.post-8150855743536062202</id><published>2009-07-20T08:57:00.000-07:00</published><updated>2009-07-20T09:21:02.268-07:00</updated><title type='text'>Overview of how to sort a malware collection and the tools involved in the process</title><content type='html'>Hi, malware collectors of the world!&lt;br /&gt;&lt;br /&gt;It´s time to start talking about how to sort your malware collection and presenting the tools you will need in the process.&lt;br /&gt;&lt;br /&gt;The first needed tool is the &lt;span style="font-weight: bold;"&gt;antivirus&lt;/span&gt; you will use to scan your collection. You will use KAV 4.5 as I already commented in a previous post in this blog. Using it we will be able to get a list of the malwares we own. You may use other antivirus but for malware exchanges KAV is the standard.&lt;br /&gt;&lt;br /&gt;The second needed tool is a software that builds databases from KAV logs. This tool is named VirSort 2000, better known as &lt;span style="font-weight: bold;"&gt;VS2000&lt;/span&gt;. The tool will be explained more deeply in a separated post because it has a large list of functions.&lt;br /&gt;&lt;br /&gt;A malware collection is just a bunch of files, so rest of tools involved in managing a malware collection are related to processes related to files.&lt;br /&gt;&lt;br /&gt;In a malware collection we must avoid having duplicated files. For this task a good tool is &lt;span style="font-weight: bold;"&gt;FWeeder&lt;/span&gt; by Bumblebee.&lt;br /&gt;&lt;br /&gt;Malware collectors usually store the files in their collections by a hash. Years ago CRC32 was the most popular. Years later was MD5. Actually collectors still use MD5 and others use SHA-1 or SHA-256. Having the correct extension for every file in the collection, even if it may be dangerous, it should be a good idea. For all the renaming tasks &lt;span style="font-weight: bold;"&gt;RenFiles&lt;/span&gt; is the tool.&lt;br /&gt;&lt;br /&gt;When you trade you must deal with the files the other trader requested. &lt;span style="font-weight: bold;"&gt;StripLog&lt;/span&gt; is the tool for this task.&lt;br /&gt;&lt;br /&gt;The above tools (KAV, VS2000, StripLog, RenFiles and FWeeder) are in the basic collection kit of any trader.&lt;br /&gt;&lt;br /&gt;Other tool of interest could be &lt;span style="font-weight: bold;"&gt;VxUnpacker&lt;/span&gt;, the tool coded by MoRRo to decrypt quarantined/crypted files. And another one would be &lt;span style="font-weight: bold;"&gt;VS2000 GUI&lt;/span&gt; which is like a compendium of VS2000+StripLog+RenFiles and it can be used for other tasks.&lt;br /&gt;&lt;br /&gt;I will dedicate one entry of the blog to every tool.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8757966904836155171-8150855743536062202?l=malwarecollecting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwarecollecting.blogspot.com/feeds/8150855743536062202/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/overview-of-how-to-sort-malware.html#comment-form' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/8150855743536062202'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/8150855743536062202'/><link rel='alternate' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/overview-of-how-to-sort-malware.html' title='Overview of how to sort a malware collection and the tools involved in the process'/><author><name>VirusBuster</name><uri>http://www.blogger.com/profile/06798218908877392347</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8757966904836155171.post-2348399346532539209</id><published>2009-07-19T15:18:00.000-07:00</published><updated>2009-07-20T04:01:17.340-07:00</updated><title type='text'>How malware collectors exchange</title><content type='html'>Hi, malware collectors of the world!&lt;br /&gt;&lt;br /&gt;Today I will explain the basics of how malware collectors exchange, but before I must explain a few things to understand why things are done the way they are done.&lt;br /&gt;&lt;br /&gt;Many years ago someone, I don´t know who had the idea, thought that to exchange viruses the best way was to use logs (reports) created by antivirus products to know exactly what everyone had in his collection. As antivirus usually give an unique identification for every variant of every virus family this was a good method. So collectors picked 3 different antivirus (Dr. Solomon, F-Prot and AVP) and they used the logs created with them to exchange.&lt;br /&gt;&lt;br /&gt;Obviously it was necessary to create tools to process logs: create databases from your own logs containing unique variants, generate reports with the missed stuff from the logs of other traders, .... but that´s stuff for other day.&lt;br /&gt;&lt;br /&gt;A few years later Dr. Solomon became very slow scanning and after a time it was dropped by collectors as common used antivirus for the exchange. F-Prot was also dropped because its ability to detect unique variants decreased. So AVP remained as the only one commonly used antivirus to exchange.&lt;br /&gt;&lt;br /&gt;Even if AVP is the best antivirus detecting known viruses and malwares, collect using only one antivirus was not a good idea so for a while collectors used from time to time other antivirus to exchange: Nod32, BitDefender, AVG, McAfee, ...&lt;br /&gt;&lt;br /&gt;Two years ago, more or less, the amount of detected malware started to increase exponentially. Since then using several antivirus to exchange became a very difficult task for collectors having big collections. Lots of scanning hours would be required to generate logs. That´s why usually only AVP is used to exchange between big collectors.&lt;br /&gt;&lt;br /&gt;As anecdote I should comment that never ever a woman became a known virus collector and there were only a few virus writers, being probably the best known one Gigabyte.&lt;br /&gt;&lt;br /&gt;Every collector may have his own rules to exchange, but everybody use  KAV 4.5 Personal Pro in english to generate the log of  his collection. You can find it &lt;a href="ftp://ftp.kaspersky.ee/products/homeuser/old/kavpersonalpro/4.5/kav4.5.0.104_personalpro_eng.exe"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Most collectors update KAV definition databases from &lt;a href="http://66.232.119.78/%7Elargefus/AVP/"&gt;here&lt;/a&gt;. This is done because identification names change often. Two collectors using different KAV defs may request stuff they already have. The solution to avoid this situation is using same defs.&lt;br /&gt;&lt;br /&gt;Years ago collectors may generate new logs every day. Actually that´s not possible because the time required to scan must be up to 48 hours if not more depending of the hardware resources. That´s why nowadays collectors generate one log per week so exchanges are done once in a week.&lt;br /&gt;&lt;br /&gt;Between big collectors the exchange ratio is 1:1. It means that for every file you send, you receive other. Many years ago the used ratio with small collectors may be 3:1 or a different one depending of the trader.&lt;br /&gt;&lt;br /&gt;Other golden rule is that the most veteran trader receives his request before sending the request of the other trader.&lt;br /&gt;&lt;br /&gt;Personally I have next rule: I exchange viruses/worms for other viruses/worms and malware for malware.&lt;br /&gt;&lt;br /&gt;And that´s basically how collectors exchange.&lt;br /&gt;&lt;br /&gt;Resuming:&lt;br /&gt;&lt;br /&gt;1) Update KAV defs.&lt;br /&gt;&lt;br /&gt;2) Generate log with KAV 4.5&lt;br /&gt;&lt;br /&gt;3) Create database from log.&lt;br /&gt;&lt;br /&gt;Then you are ready to get a log from other trader and verify if you need anything from him. If you do,  you  send your log to the other trader so he can check if he misses something from you.&lt;br /&gt;&lt;br /&gt;Pretty simple but effective.&lt;br /&gt;&lt;br /&gt;It´s good idea that before starting to transfer files both traders are sure they are using same defs.&lt;br /&gt;&lt;br /&gt;Next blog entries will be dedicated to present the tools commonly used to collect and keep the collection in good shape.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8757966904836155171-2348399346532539209?l=malwarecollecting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwarecollecting.blogspot.com/feeds/2348399346532539209/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/how-malware-collectors-exchange.html#comment-form' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/2348399346532539209'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/2348399346532539209'/><link rel='alternate' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/how-malware-collectors-exchange.html' title='How malware collectors exchange'/><author><name>VirusBuster</name><uri>http://www.blogger.com/profile/06798218908877392347</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8757966904836155171.post-1609031517990717162</id><published>2009-07-17T06:28:00.000-07:00</published><updated>2009-07-17T07:31:06.550-07:00</updated><title type='text'>Presenting other traders</title><content type='html'>Hi, malware collectors of the world!&lt;br /&gt;&lt;br /&gt;Today I will present other traders. The few active remaining ones.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;br /&gt;Baptist&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;You can reach him visiting his web site at: &lt;a href="http://66.232.119.78/%7Elargefus/"&gt;http://66.232.119.78/~largefus/&lt;/a&gt;&lt;span style="color: rgb(51, 102, 153);font-family:verdana,arial;font-size:130%;"  &gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;He has been collecting for a few years but his collection is very large.&lt;br /&gt;&lt;br /&gt;He has contributed to the virus exchange community providing web space to allocate other collector logs.&lt;br /&gt;&lt;br /&gt;Status: Active trader&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;br /&gt;Morro&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;He has been in the trading scene for long time, not as much as me, I´m kinda  a dinosaur, but really a lot.&lt;br /&gt;&lt;br /&gt;His major contribution to the collectors has been VxUnpacker, a tool coded in .NET used to decrypt quarantined/crypted samples. It´s the best tool in its genre so far. (and the only one)&lt;br /&gt;&lt;br /&gt;You can reach him writing a mail to morrovx@gmail.com&lt;br /&gt;&lt;br /&gt;Status: Active trader&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;MasterRat&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;He is the owner of &lt;a href="http://www.blogger.com/www.megasecurity.org"&gt;www.megasecurity.org&lt;/a&gt;, a very famouse trojan repository.&lt;br /&gt;&lt;br /&gt;You can contact him at masterrat666@yahoo.com&lt;br /&gt;&lt;br /&gt;Status: Active trader&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Vir Albb&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Trader from China.&lt;br /&gt;&lt;br /&gt;You can reach him at viralbb@yahoo.com.cn&lt;br /&gt;&lt;br /&gt;Status: Probably still active&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;VirusTrader&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Other trader from China.&lt;br /&gt;&lt;br /&gt;Contact him at virustrader@126.com&lt;br /&gt;&lt;br /&gt;Status: Active trader&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;SnakeMan&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;He is an australian collector.&lt;br /&gt;&lt;br /&gt;You can reach him at snakeman@netspace.net.au&lt;br /&gt;&lt;br /&gt;Status: Probably still active&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Trney&lt;/span&gt;&lt;span class="postbody"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;He has been collecting for long time. He comes from Japan.&lt;br /&gt;&lt;br /&gt;You can take a look at his website here: &lt;a href="http://www5c.biglobe.ne.jp/%7ETRNEY/"&gt;http://www5c.biglobe.ne.jp/~TRNEY/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Mail of contact: yk442311@kjb.biglobe.ne.jp&lt;br /&gt;&lt;br /&gt;Status: Probably still active&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;White Master&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;You can visit his web here: &lt;a href="http://whitemaster.pisem.net/"&gt;http://whitemaster.pisem.net/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Mail of contact: whitemst@yahoo.com&lt;br /&gt;&lt;br /&gt;Status: Probably still active&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Seak&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Visit his web site here: &lt;a href="http://www.numentec.com/aver/seak/"&gt;http://www.numentec.com/aver/seak/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Mail: seak@numentec.com&lt;br /&gt;&lt;br /&gt;Status: Probably still active&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;A few months ago there were other active traders but lately I didn´t hear about them so I don´t know what´s their status. A list of them follows:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Senna Spy&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Brazilian virus collector.&lt;br /&gt;&lt;br /&gt;Mail of contact: sennaspy@uol.com.br&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Germano&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Italian virus collector.&lt;br /&gt;&lt;br /&gt;Mail of contact: gdalessandro@gmail.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Virax&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Mail of contact: virax@gmx.co.uk&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Apoc&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Mail of contact: aappoocc@walla.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;VirusP&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Collector from Greece. Owner of the site: &lt;a href="http://www.virus.gr/portal/en/"&gt;http://www.virus.gr/portal/en/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Mail of contact: collecting@virus.gr&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Zordhak&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Mail of contact: zordhak.vx@gmail.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;And here it goes a list of other traders from the past. If any of them reads this he probably will be happy knowing there are still someone that remembers him.&lt;br /&gt;&lt;br /&gt;Poltergeist, Shadow Seeker, Jack the Ripper, omega666, Galar, Danielle Fogazzi, Sokrates, Malware, Perikles, Newton, Zulu, Phage, Tally, HomeSlice, SlageHammer, Roadkil, Stramonium, GG-Nome, Raenius, Algol, NFission, Staggle, Specter, Quilb, BasketCase, ByteSurgeon, BaidareW, Nexus Crusader, Panoix, CyberWarrior, BlackCat, Szule, Vein (the craziest collector ever! ;), C-urtis, Toxic, Van Blue Fish, Zelgadis, SnowBlaze, Nemesizz, Dr. Rave, sphinx, Asad, Brian_Perl, Vortex, m0n30 (espero volver a saber de ti algún día ;), BuddyMusic, mr-virus, Akap, VirusJoe and CTDummy.&lt;br /&gt;&lt;br /&gt;Sorry if I forgot someone but my memory is not what it used to be. O;-)&lt;br /&gt;&lt;br /&gt;There are others but as we say in spanish: valgo más por lo que callo que por lo que digo. They know who they are. };-&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8757966904836155171-1609031517990717162?l=malwarecollecting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwarecollecting.blogspot.com/feeds/1609031517990717162/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/presenting-other-traders.html#comment-form' title='1 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/1609031517990717162'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/1609031517990717162'/><link rel='alternate' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/presenting-other-traders.html' title='Presenting other traders'/><author><name>VirusBuster</name><uri>http://www.blogger.com/profile/06798218908877392347</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8757966904836155171.post-4904771107924994841</id><published>2009-07-14T01:18:00.000-07:00</published><updated>2009-07-14T02:09:53.170-07:00</updated><title type='text'>Presenting myself (Part II) - Objective of this blog</title><content type='html'>Hi, malware collectors of the world!&lt;br /&gt;&lt;br /&gt;I will start this blog entry replying the pendant question from previous post: Why is not possible nowadays to become a traditional collector?&lt;br /&gt;&lt;br /&gt;The main reason that makes it not possible is because malware collectors have very large collections, containing over 400k and 500k unique samples, therefore someone that starts collecting can not join the trading game.&lt;br /&gt;&lt;br /&gt;Obviously anyone can collect malware but not at the level that traditional collectors reached.&lt;br /&gt;&lt;br /&gt;Continuing with my presentation...&lt;br /&gt;&lt;br /&gt;Between 1994 and 1996 I was related to BBS, specially Dark Node, the BBS where I was SysOp, and Internet. In 1996 Dark Node closed and since then I have been related to the virus/trading scene through Internet.&lt;br /&gt;&lt;br /&gt;Since 1994 I exchanged viruses with other collectors at Internet. I also got new viruses directly from virus coders. Being a 29A member helped me greatly to get new stuff.&lt;br /&gt;&lt;br /&gt;Around 1998 I created a website dedicated to the virus exchange and the virus scene in general. I named it "Virus Trading Center".&lt;br /&gt;&lt;br /&gt;Not much time later I thought it would be a good idea to create a small group formed by the best collectors, so I explained my idea to ShadSeek, Slage Hammer and Tally. They agreeded and we formed a group we named "Virus Trading Group". Some time later Cicatrix also joined to the group.&lt;br /&gt;&lt;br /&gt;As IRC was the meeting point for virus collectors, around the same dates, in 1998, I decided to create my own IRC channel. I named it "vx-vtc" in reference to virus trading center.&lt;br /&gt;&lt;br /&gt;For long time most of the collectors of the world joined there to meet and arrange exchanges.&lt;br /&gt;&lt;br /&gt;But things don´t last forever and after two years, more or less, internal problems inside Virus Trading Group leaded to split up the group. Some collectors also decided to leave vx-vtc IRC channel and create their own channel.&lt;br /&gt;&lt;br /&gt;Anyway the period between year 2000 and 2006 was a good one for exchange. As I commented in previous post, collectors came and collectors left. Some of them were good friends and we had a nice time trading together. Spending time at IRC chatting about anything was the real fun of collecting.&lt;br /&gt;&lt;br /&gt;From 2006 until today the number of collectors have been decreasing. Old collectors like VirusP left the trading scene and nobody came to replace the empty places.&lt;br /&gt;&lt;br /&gt;2008 was the year when collectors definetively left IRC as meeting point.&lt;br /&gt;&lt;br /&gt;A few years ago I closed Virus Trading Center website and decided to create a forum for malware collectors. I named it "Malware Collecting Forum". The forum was probably created a bit late. It appeared when only a few collectors were remaining. The participation in the forum was so low that I decided to close it to the public.&lt;br /&gt;&lt;br /&gt;I always liked to be connected in some manner to other collectors and share with them my experiences, my tools, ... First I did it through my web site. At the same time I created an IRC channel. After my site closed I created a forum for collectors.&lt;br /&gt;&lt;br /&gt;Right now IRC channel still exist but nobody joins there. Website is gone and forum too. So I decided to give a try with a blog.&lt;br /&gt;&lt;br /&gt;What´s the objective of this blog?&lt;br /&gt;&lt;br /&gt;I will bring here the malware collecting procedures I consider the right ones. I also will comment the tools (third part or my own ones) to do collecting tasks.&lt;br /&gt;&lt;br /&gt;That´s more or less what you can expect from this blog. Anyway I´m open to critics, suggestions, whatever. So don´t hesitate to contact me and send your comments.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8757966904836155171-4904771107924994841?l=malwarecollecting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwarecollecting.blogspot.com/feeds/4904771107924994841/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/presenting-myself-part-ii-objective-of.html#comment-form' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/4904771107924994841'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/4904771107924994841'/><link rel='alternate' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/presenting-myself-part-ii-objective-of.html' title='Presenting myself (Part II) - Objective of this blog'/><author><name>VirusBuster</name><uri>http://www.blogger.com/profile/06798218908877392347</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8757966904836155171.post-7554212173447956495</id><published>2009-07-09T14:34:00.000-07:00</published><updated>2009-07-15T02:22:38.661-07:00</updated><title type='text'>Opening the blog. Presenting myself (Part I)</title><content type='html'>Hi, malware collectors of the world!&lt;br /&gt;&lt;br /&gt;I will present myself in this first post of the blog.&lt;br /&gt;&lt;br /&gt;I´m VirusBuster, a malware collector. I used to define myself as virus collector, but nowadays viruses are so rare (almost everything are malwares) that some time ago I decided it would be fair to change the "label" from virus collector to malware collector.&lt;br /&gt;&lt;br /&gt;I´m from Spain and I have been collecting viruses and malware since 1992. It was in that year when I met someone that introduced me to virus collecting. He had a small collection of viruses, and after the initial shock (who could be so insane to keep them?), I was truely interested about them.&lt;br /&gt;&lt;br /&gt;At the beginning I used to get new specimens from pirated software, but after a time always the same viruses were showing up. Then, how to get new viruses?&lt;br /&gt;&lt;br /&gt;In that year, in Spain, BBS (Bulletin Board System) were the most used way for communications. Internet was something reserved to universities yet, so I started my quest for new viruses in the spanish BBS. After a time I located a BBS with several new viruses and something that was like the grial, the Virus Creation Laboratory (VCL). I sent my viruses and just in a few days I got access to all the viruses. Chiba City rules!&lt;br /&gt;&lt;br /&gt;I joined (in 1993???) Fidonet just to get access to VIRUS.R34. I met there other people interested in viruses, in writing and collecting them. After a time some people complained because they considered that publishing virus codes was not politically correct and after some argues exchanged the moderator decided to ban that kind of stuff. In that moment I and the person who introduced me to virus collecting, decided we should create our own BBS dedicated to anything related to viruses: coding, collecting, ... That´s how Dark Node BBS was born.&lt;br /&gt;&lt;br /&gt;Very talented virus writers joined the BBS, most of them coming from VIRUS.R34. It was a common project so they helped economically to buy the required hardware.&lt;br /&gt;&lt;br /&gt;After a time, using stuff (articles, virus source codes, ...) published in the BBS, a virus magazine, in the style of Immortal Riot and Vlad, was created. It was called 29A #1 and a virus group, formed by members of the BBS, named as the magazine was created too. What happened with 29A... is other story.&lt;br /&gt;&lt;br /&gt;From Dark Node times I keep nice memories, specially about the meetings we did.&lt;br /&gt;&lt;br /&gt;In 1994 I got internet connection at home. A common friend of a friend got us internet access using a modem installed in the university as bridge. I still wonder how the hell he did that.&lt;br /&gt;&lt;br /&gt;I don´t remember where I heard about IRC but the question is that I joined #virus at Effnet and met there most of the greatest collectors of that time. Poltergeist, Shadow Seeker, jtr, omega666, Danielle Fogazzi, ...&lt;br /&gt;&lt;br /&gt;They teached me their procedures for virus exchange and shared the tools used in the process.&lt;br /&gt;&lt;br /&gt;My collection compared to the collections they had was a joke but I decided I would be patient and constant. Keeping that in mind it was not a surprise that with the years my collection grew a lot. I also learned that being honest and loyal, keeping promises (and also secrets) and being a nice person, was the key to be a better collector.&lt;br /&gt;&lt;br /&gt;With the years collectors came and collectors left.&lt;br /&gt;&lt;br /&gt;I can say with the heart on the hand that the best thing from all these years of collector has been meeting and knowing other collectors. The list of collectors to greet would be too large so I´ll just say: Kind regards for Perikles and the rest of collectors I appreciate.&lt;br /&gt;&lt;br /&gt;As a person who likes to question things, there was a moment I asked myself: What´s the meaning of being a virus collector? Is all about a file exchange? Send and receive?&lt;br /&gt;&lt;br /&gt;I didn´t think so. For me virus collecting was teaching how to collect and helping to new collectors, as previously other people teached me, specially Poltergeist, who I consider my "father" in virus collecting. Poltergeist was the model I used as mirror. He was the kind of collector I wanted to be when I joined internet and met other international collectors.&lt;br /&gt;&lt;br /&gt;Therefore apart of trading files, for me collecting was helping other traders, guiding them in their first steps as traders. But there was other important thing...&lt;br /&gt;&lt;br /&gt;From very old times, collectors used antivirus to make reports and use those reports to know what they had and what they missed from other collections. A few tools were created with the purpose of exchanging viruses but the most famouse was VirSort by Jim Fougeron (Poltergeist), originally created by ShadSeek.&lt;br /&gt;&lt;br /&gt;When Poltergeist left the scene he sent VirSort source code to Spooky but he never released a new version. Then ShadSeek created a new virus collecting tool named VS2000 (VirSort 2000). After a time he also stopped development of his tool and that was a shock because I was used to use other people tools. Who would continue developing the tool and adding new features?&lt;br /&gt;&lt;br /&gt;I wanted to add new functions I considered important for collecting so I asked ShadSeek a copy of VS2000 source code so I could continue developing it.  I had to learn Pascal for this.&lt;br /&gt;&lt;br /&gt;That´s how I discovered another important aspect of being a virus/malware collector: the tools for collecting. With the appropiate tools collecting is easier.&lt;br /&gt;&lt;br /&gt;Actually if someone asks me "what makes of someone a real virus/malware collector?" I know the answer. My answer.&lt;br /&gt;&lt;br /&gt;For me a true virus/malware collector, in the traditional sense, has next characteristics:&lt;br /&gt;&lt;br /&gt;* Someone who is able to get many new samples in a constant basis.&lt;br /&gt;&lt;br /&gt;* Someone that has the knowledge to help other collectors.&lt;br /&gt;&lt;br /&gt;* Someone that rarely infects the system because stablished controls to avoid that.&lt;br /&gt;&lt;br /&gt;* Someone able to code the required tools for the tasks involved in collecting.&lt;br /&gt;&lt;br /&gt;Becoming a true collector is something that takes time and effort.&lt;br /&gt;&lt;br /&gt;I consider that nowadays becoming a traditional collector is not possible anymore. The reasons for that is something I will comment in next post.&lt;br /&gt;&lt;br /&gt;End of presentation. Part I.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8757966904836155171-7554212173447956495?l=malwarecollecting.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://malwarecollecting.blogspot.com/feeds/7554212173447956495/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/opening-blog-presenting-myself-part-i.html#comment-form' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/7554212173447956495'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8757966904836155171/posts/default/7554212173447956495'/><link rel='alternate' type='text/html' href='http://malwarecollecting.blogspot.com/2009/07/opening-blog-presenting-myself-part-i.html' title='Opening the blog. Presenting myself (Part I)'/><author><name>VirusBuster</name><uri>http://www.blogger.com/profile/06798218908877392347</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
