<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: My Virus lab part 1: downloading a malicious file</title>
	<atom:link href="http://blog.didierstevens.com/2006/12/15/my-virus-lab-part-1-downloading-a-malicious-file/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2006/12/15/my-virus-lab-part-1-downloading-a-malicious-file/</link>
	<description>(blog \'DidierStevens)</description>
	<lastBuildDate>Thu, 23 May 2013 18:25:36 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/12/15/my-virus-lab-part-1-downloading-a-malicious-file/#comment-21113</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Wed, 28 Nov 2007 22:44:54 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2006/12/15/my-virus-lab-part-1-downloading-a-malicious-file/#comment-21113</guid>
		<description><![CDATA[I don&#039;t want to install malware on my computer.]]></description>
		<content:encoded><![CDATA[<p>I don&#8217;t want to install malware on my computer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: freebsd</title>
		<link>http://blog.didierstevens.com/2006/12/15/my-virus-lab-part-1-downloading-a-malicious-file/#comment-20790</link>
		<dc:creator><![CDATA[freebsd]]></dc:creator>
		<pubDate>Mon, 26 Nov 2007 20:44:44 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2006/12/15/my-virus-lab-part-1-downloading-a-malicious-file/#comment-20790</guid>
		<description><![CDATA[Why exactly would you wan&#039;t to install malware on your computer ?]]></description>
		<content:encoded><![CDATA[<p>Why exactly would you wan&#8217;t to install malware on your computer ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: insecure</title>
		<link>http://blog.didierstevens.com/2006/12/15/my-virus-lab-part-1-downloading-a-malicious-file/#comment-518</link>
		<dc:creator><![CDATA[insecure]]></dc:creator>
		<pubDate>Tue, 30 Jan 2007 14:57:14 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2006/12/15/my-virus-lab-part-1-downloading-a-malicious-file/#comment-518</guid>
		<description><![CDATA[sysinternals&#039; procmon also monitors windoze activity very well

yet another honeypot tool is honeynet 
http://www.honeynet.org/

hope this helps]]></description>
		<content:encoded><![CDATA[<p>sysinternals&#8217; procmon also monitors windoze activity very well</p>
<p>yet another honeypot tool is honeynet<br />
<a href="http://www.honeynet.org/" rel="nofollow">http://www.honeynet.org/</a></p>
<p>hope this helps</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Luke</title>
		<link>http://blog.didierstevens.com/2006/12/15/my-virus-lab-part-1-downloading-a-malicious-file/#comment-459</link>
		<dc:creator><![CDATA[Luke]]></dc:creator>
		<pubDate>Tue, 23 Jan 2007 16:02:33 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2006/12/15/my-virus-lab-part-1-downloading-a-malicious-file/#comment-459</guid>
		<description><![CDATA[Thanks for the tip - afik and regshot sound extremely useful.]]></description>
		<content:encoded><![CDATA[<p>Thanks for the tip &#8211; afik and regshot sound extremely useful.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jim</title>
		<link>http://blog.didierstevens.com/2006/12/15/my-virus-lab-part-1-downloading-a-malicious-file/#comment-361</link>
		<dc:creator><![CDATA[jim]]></dc:creator>
		<pubDate>Thu, 04 Jan 2007 21:36:44 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2006/12/15/my-virus-lab-part-1-downloading-a-malicious-file/#comment-361</guid>
		<description><![CDATA[regshot &amp; afick huh? cool i&#039;ll have to check that out! thanks for the info! i&#039;ll be checking back for your blog
thanks!,
jim b]]></description>
		<content:encoded><![CDATA[<p>regshot &amp; afick huh? cool i&#8217;ll have to check that out! thanks for the info! i&#8217;ll be checking back for your blog<br />
thanks!,<br />
jim b</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/12/15/my-virus-lab-part-1-downloading-a-malicious-file/#comment-342</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Thu, 28 Dec 2006 13:41:52 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2006/12/15/my-virus-lab-part-1-downloading-a-malicious-file/#comment-342</guid>
		<description><![CDATA[I will blog about this, but in a nutshell:
- use Rootkitrevealer by Sysinternals (now MS) to detect rootkits
- you can export the registry before installation and after, and then check for differences
- a tool to automate this is regshot
- afick allows you to detect changes to the filesystem
- and then you have process monitor (also by Sysinternals)]]></description>
		<content:encoded><![CDATA[<p>I will blog about this, but in a nutshell:<br />
- use Rootkitrevealer by Sysinternals (now MS) to detect rootkits<br />
- you can export the registry before installation and after, and then check for differences<br />
- a tool to automate this is regshot<br />
- afick allows you to detect changes to the filesystem<br />
- and then you have process monitor (also by Sysinternals)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jim</title>
		<link>http://blog.didierstevens.com/2006/12/15/my-virus-lab-part-1-downloading-a-malicious-file/#comment-340</link>
		<dc:creator><![CDATA[jim]]></dc:creator>
		<pubDate>Wed, 27 Dec 2006 15:15:20 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2006/12/15/my-virus-lab-part-1-downloading-a-malicious-file/#comment-340</guid>
		<description><![CDATA[hi didier,
i&#039;ve been curious about how some of the malware works (and it was going to do to my system) that was sent to me by means of spam so i&#039;ve created a testing lab as well. i&#039;m interested so read how you set up your testing environment; here&#039;s what i&#039;ve been using:
i&#039;m running vmware on my linux box and have multiple instances of windoze set up so that they can communicate &amp; wreck havok on each other, but not reach the outside network nor the parent OS. then i can simply copy &amp; paste a new instance of the OS when it&#039;s been wrecked. 
what i haven&#039;t found is a program that can monitor for all changes on the win OS and report what registry changes have been made, root kit installed, etc.. have you found anything of this sort?
thank, 
jim]]></description>
		<content:encoded><![CDATA[<p>hi didier,<br />
i&#8217;ve been curious about how some of the malware works (and it was going to do to my system) that was sent to me by means of spam so i&#8217;ve created a testing lab as well. i&#8217;m interested so read how you set up your testing environment; here&#8217;s what i&#8217;ve been using:<br />
i&#8217;m running vmware on my linux box and have multiple instances of windoze set up so that they can communicate &amp; wreck havok on each other, but not reach the outside network nor the parent OS. then i can simply copy &amp; paste a new instance of the OS when it&#8217;s been wrecked.<br />
what i haven&#8217;t found is a program that can monitor for all changes on the win OS and report what registry changes have been made, root kit installed, etc.. have you found anything of this sort?<br />
thank,<br />
jim</p>
]]></content:encoded>
	</item>
</channel>
</rss>
