<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1555473146551121810</id><updated>2012-02-16T09:21:28.308+01:00</updated><category term='Analisis'/><category term='Varias'/><category term='Keygenning'/><category term='Malware'/><category term='Analizadores'/><category term='Herramientas'/><category term='Unpacking'/><category term='Editores'/><category term='Tutoriales'/><category term='Depuradores'/><category term='Ingenieria Inversa'/><category term='Linux'/><category term='Retos'/><category term='Virus'/><category term='Exploits'/><category term='Otros'/><category term='Worms'/><category term='VB'/><category term='Backdoors'/><category term='Spyware'/><category term='Crackmes - Keygenmes'/><category term='.NET'/><category term='Vulnerabilidades y Exploits'/><title type='text'>ClS | AbsshA</title><subtitle type='html'>Seamos realistas, y hagamos lo imposible.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Shaddy</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_lqSqJt4JmcE/STtE5Z8nz9I/AAAAAAAAAAM/jFxXs9F2HWI/s1600-R/1386152joker.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>29</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-4394683923393050407</id><published>2010-11-10T17:22:00.003+01:00</published><updated>2010-11-10T18:01:16.013+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutoriales'/><category scheme='http://www.blogger.com/atom/ns#' term='Ingenieria Inversa'/><category scheme='http://www.blogger.com/atom/ns#' term='Unpacking'/><title type='text'>Unpackme by GUAN (SOLUCION)</title><content type='html'>Bueno, a petición de algunos de la lista y con la única intención de cubrir las inquietudes de la humanidad. Ahí va.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.reversingcode.com/f1l3s/Unpackme.GUAN.rar"&gt;Descarga&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span id="fullpost"&gt;Pass: "crackslatinos"&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-4394683923393050407?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/4394683923393050407/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=4394683923393050407' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/4394683923393050407'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/4394683923393050407'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2010/11/unpackme-by-guan.html' title='Unpackme by GUAN (SOLUCION)'/><author><name>Shaddy</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_lqSqJt4JmcE/STtE5Z8nz9I/AAAAAAAAAAM/jFxXs9F2HWI/s1600-R/1386152joker.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-1660841967752106104</id><published>2010-08-24T22:43:00.002+02:00</published><updated>2010-08-24T22:52:49.715+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutoriales'/><category scheme='http://www.blogger.com/atom/ns#' term='Ingenieria Inversa'/><category scheme='http://www.blogger.com/atom/ns#' term='Linux'/><title type='text'>Reversing Tips para Linux</title><content type='html'>Para que no pase tanto tiempo entre una entrada y la siguiente os dejo un pequeño tutorial para aquellos que no saben que hay más mundos al otro lado de sus ventanas...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://ricardonarvaja.info/WEB/CURSO%20NUEVO/TEORIAS%20NUMERADAS/1201-1300/1273-Reversing%20tips%20para%20Linux.AbsshA.rar"&gt;Descarga&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-1660841967752106104?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/1660841967752106104/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=1660841967752106104' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/1660841967752106104'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/1660841967752106104'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2010/08/reversing-tips-para-linux.html' title='Reversing Tips para Linux'/><author><name>Absolom1</name><uri>http://www.blogger.com/profile/13853111646939752229</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-1664507580865814795</id><published>2010-07-28T13:48:00.001+02:00</published><updated>2010-07-28T13:52:19.445+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutoriales'/><category scheme='http://www.blogger.com/atom/ns#' term='Ingenieria Inversa'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerabilidades y Exploits'/><title type='text'>Exploiting PhotoFiltre Studio 8.x.x</title><content type='html'>Buenas a todos!&lt;br /&gt;&lt;br /&gt;La verdad es que tenía muchas ganas de quitarme  éste tutorial de encima, que por falta constante de tiempo no he podido  escribir prácticamente nada.&lt;span id="fullpost"&gt;&lt;/span&gt;&lt;br /&gt;Espero que disculpéis la brevedad del mismo, algunas "faltas" de explicación sobre detalles que obvio, etc.&lt;br /&gt;&lt;br /&gt;Descarga: &lt;a href="http://www.reversingcode.com/f1l3s/Exploiting_PhotoFiltreStudio.8.x.x.rar"&gt;Exploiting PhotoFiltre Studio 8.x.x&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Password: "&lt;span style="font-weight: bold;"&gt;crackslatinos&lt;/span&gt;"&lt;br /&gt;&lt;br /&gt;Gracias,&lt;br /&gt;&lt;br /&gt;Un saludo.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-1664507580865814795?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/1664507580865814795/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=1664507580865814795' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/1664507580865814795'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/1664507580865814795'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2010/07/exploiting-photofiltre-studio-8xx.html' title='Exploiting PhotoFiltre Studio 8.x.x'/><author><name>Shaddy</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_lqSqJt4JmcE/STtE5Z8nz9I/AAAAAAAAAAM/jFxXs9F2HWI/s1600-R/1386152joker.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-6237964214521960799</id><published>2010-06-07T21:04:00.003+02:00</published><updated>2010-08-26T21:41:16.392+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Backdoors'/><category scheme='http://www.blogger.com/atom/ns#' term='Tutoriales'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerabilidades y Exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploits'/><title type='text'>Exploiting FTP´s</title><content type='html'>Para abrir el apetito os traigo un pequeño tutorial sobre exploiting de dos FTP´s gemelos.&lt;br /&gt;&lt;br /&gt;Espero que os guste e intentaré  no demorarme tanto entre entradas...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.reversingcode.com/f1l3s/AbsshA.Exploiting_FTPs.rar"&gt;Link&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span id="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-6237964214521960799?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/6237964214521960799/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=6237964214521960799' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/6237964214521960799'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/6237964214521960799'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2010/06/exploiting-ftps.html' title='Exploiting FTP´s'/><author><name>Absolom1</name><uri>http://www.blogger.com/profile/13853111646939752229</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-8899225058841808108</id><published>2010-02-06T22:21:00.005+01:00</published><updated>2010-02-08T16:35:21.559+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Ingenieria Inversa'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerabilidades y Exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploits'/><title type='text'>TFTP Exploit - Vulnerability Analysis</title><content type='html'>&lt;span id="fullpost"&gt;Solución al Concurso 1 del 2010 de Crackslatinos.&lt;br /&gt;&lt;br /&gt;Trata de una vulnerabilidad (conocida) sobre TFTP Server v1.4 en Windows.&lt;br /&gt;&lt;br /&gt;Un clásico "stack overflow".&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.reversingcode.com/f1l3s/Concurso%201%20-%20TFTP%20Exploit.rar"&gt;Bajar artículo&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span id="fullpost"&gt;Un saludo!&lt;/span&gt;&lt;br /&gt;&lt;span id="fullpost"&gt;&lt;br /&gt;PASSWORD: "crackslatinos"&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-8899225058841808108?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/8899225058841808108/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=8899225058841808108' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/8899225058841808108'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/8899225058841808108'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2010/02/tftp-expoit-vulnerability-analysis.html' title='TFTP Exploit - Vulnerability Analysis'/><author><name>Shaddy</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_lqSqJt4JmcE/STtE5Z8nz9I/AAAAAAAAAAM/jFxXs9F2HWI/s1600-R/1386152joker.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-8947897628427236621</id><published>2009-06-16T16:01:00.002+02:00</published><updated>2009-06-16T16:06:25.073+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Backdoors'/><category scheme='http://www.blogger.com/atom/ns#' term='Tutoriales'/><category scheme='http://www.blogger.com/atom/ns#' term='Ingenieria Inversa'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><title type='text'>Análisis de Bifrost v1.2 Exahustivo Parte #1</title><content type='html'>&lt;span id="fullpost"&gt;&lt;span class="Apple-style-span" style="font-family: 'Times New Roman'; "&gt;&lt;div style="margin-top: 8px; margin-right: 8px; margin-bottom: 8px; margin-left: 8px; font: normal normal normal small/normal arial; "&gt;&lt;span class="Apple-style-span" style="font-family: 'Times New Roman'; font-size: 16px; "&gt;&lt;div style="margin-top: 8px; margin-right: 8px; margin-bottom: 8px; margin-left: 8px; font: normal normal normal small/normal arial; "&gt;Ya llevaba la idea desde hace tiempo y de momento sale la parte #1... el archivo adjunto contiene.&lt;/div&gt;&lt;div style="margin-top: 8px; margin-right: 8px; margin-bottom: 8px; margin-left: 8px; font: normal normal normal small/normal arial; "&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;"&lt;i&gt;Bifrost_core.dl&lt;/i&gt;l" -&gt; &lt;b&gt;.DLL con cabecera reparada y descomprimida (de UPX), y tabla IAT arreglada que contiene el núcleo del troyano&lt;/b&gt;.&lt;/div&gt;&lt;div&gt;"&lt;i&gt;PE_Header.Bifrost_core.txt&lt;/i&gt;" -&gt; &lt;b&gt;Copia de la Información del PE Header de la librería que se crea en memoria.&lt;/b&gt;&lt;/div&gt;&lt;div&gt;"&lt;i&gt;Server.exe_INFECTED&lt;/i&gt;" -&gt; &lt;b&gt;Servidor que se ha analizado (Infectado, aunque no conecta a ningún lado).&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;En ésta parte se ve solamente hasta lo que es extraer la .dll de la memoria, en la segunda parte haré el análisis Estático con IDA (que tengo casi terminado) y escribiré el funcionamiento sobre como se Instala en el SO, Protocolos de comunicación, Desinstalación y Contra-Ataques que se puedan hacer...&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Si hay alguien que le interese saber como reparé la .dll una vez volcada que me escriba al privado y haré una Parte III o un Anexo.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.savefile.com/files/2130462"&gt;Mirror 1&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://sites.google.com/site/absshacls/Home/Bifrost.v1.2.Analasis.Exahustivo.By.%5BClS%5DAbsshA.rar?attredirects=0"&gt;Mirror 2&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Password: "crackslatinos"&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;AbsshA&lt;/div&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-8947897628427236621?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/8947897628427236621/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=8947897628427236621' title='6 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/8947897628427236621'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/8947897628427236621'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/06/analisis-de-bifrost-v12-exahustivo.html' title='Análisis de Bifrost v1.2 Exahustivo Parte #1'/><author><name>Shaddy</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_lqSqJt4JmcE/STtE5Z8nz9I/AAAAAAAAAAM/jFxXs9F2HWI/s1600-R/1386152joker.jpg'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-8061959003295287046</id><published>2009-05-04T00:55:00.007+02:00</published><updated>2009-05-05T23:35:41.607+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Ingenieria Inversa'/><category scheme='http://www.blogger.com/atom/ns#' term='Retos'/><title type='text'>Panda Security #2 - Solucion</title><content type='html'>&lt;div&gt;&lt;span class="Apple-style-span"  style="font-family:'Times New Roman';"&gt;&lt;div   style="border-width: 0px; margin: 0px; padding: 3px; width: auto; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; text-align: left;font-family:Georgia,serif;font-size:100%;"&gt;&lt;div&gt;Aquí está la solución al reto #2 de &lt;span style="font-weight: bold;"&gt;Panda Security&lt;/span&gt; reto que ha llevado unos días elaborarlo correctamente.&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse;font-family:arial;font-size:13;"  &gt;&lt;div&gt;Para la prueba número 2 de panda, que por lo visto no tenía solución todavía (o al menos no ha sido publicada), resuelta por todos los listeros de Crakslatinos.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;Nos ha costado, ya que había mucho que escribir y está bastante resumido. Si hay cualquier error, duda o lo que sea, decidlo.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.savefile.com/files/2092689" target="_blank" style="color: rgb(87, 151, 176);"&gt;http://www.savefile.com/files/&lt;wbr&gt;2092689&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.mediafire.com/file/owjgedqumdx/Reto_Panda_P2_By.Guan_y_AbsshA.rar" target="_blank" style="color: rgb(87, 151, 176);"&gt;http://www.mediafire.com/file/&lt;wbr&gt;owjgedqumdx/Reto_Panda_P2_By.&lt;wbr&gt;Guan_y_AbsshA.rar&lt;/a&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;AbsshA&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-8061959003295287046?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/8061959003295287046/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=8061959003295287046' title='8 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/8061959003295287046'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/8061959003295287046'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/05/panda-security-2-solucion.html' title='Panda Security #2 - Solucion'/><author><name>Shaddy</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_lqSqJt4JmcE/STtE5Z8nz9I/AAAAAAAAAAM/jFxXs9F2HWI/s1600-R/1386152joker.jpg'/></author><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-396910424920504800</id><published>2009-04-03T10:00:00.003+02:00</published><updated>2009-05-05T23:36:05.042+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Ingenieria Inversa'/><category scheme='http://www.blogger.com/atom/ns#' term='Retos'/><title type='text'>Panda Security #1 - Solucion</title><content type='html'>Aquí tenéis la solución al pasado reto de &lt;span style="font-weight: bold;"&gt;Panda Security&lt;/span&gt; publicado el pasado miércoles, día 1 de Abril.&lt;br /&gt;&lt;span id="fullpost"&gt;&lt;br /&gt;Lo podéis descargar &lt;a href="http://www.megaupload.com/?d=NZKJEIK8"&gt;aquí&lt;/a&gt;.&lt;/span&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;AbsshA.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-396910424920504800?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/396910424920504800/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=396910424920504800' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/396910424920504800'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/396910424920504800'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/05/panda-security-1-solucion.html' title='Panda Security #1 - Solucion'/><author><name>ClS | AbsshA</name><uri>http://www.blogger.com/profile/15497404795417783425</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-3097989316510666178</id><published>2009-03-25T04:09:00.001+01:00</published><updated>2009-05-18T17:03:39.147+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutoriales'/><category scheme='http://www.blogger.com/atom/ns#' term='Ingenieria Inversa'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerabilidades y Exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploits'/><title type='text'>Tiny Identd v2.X- Explotando vulnerabilidad</title><content type='html'>&lt;span id="fullpost"&gt;Tutorial donde se explica el método para explotar la vulnerabilidad, localizar e inyectar una &lt;span style="font-weight: bold;"&gt;&lt;span style="font-style: italic;"&gt;ShellCode&lt;/span&gt;&lt;/span&gt; para obtener acceso al sistema.&lt;br /&gt;&lt;br /&gt;Lo podéis descargar &lt;a href="http://ricardonarvaja.info/WEB/OTROS/EXPLOIT/SOBRE%20PROGRAMAS/TINY%20IDENT/CONCURSO%208%20-%20NIVEL%203%20-%20By%20Absolom1%20&amp;amp;%20Shaddy%20%5bAbsshA%5d.rar"&gt;aquí&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;AbsshA&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-3097989316510666178?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/3097989316510666178/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=3097989316510666178' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/3097989316510666178'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/3097989316510666178'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/05/tiny-identd-v2x-explotando.html' title='Tiny Identd v2.X- Explotando vulnerabilidad'/><author><name>Shaddy</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_lqSqJt4JmcE/STtE5Z8nz9I/AAAAAAAAAAM/jFxXs9F2HWI/s1600-R/1386152joker.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-1328922972211758111</id><published>2009-02-04T04:03:00.001+01:00</published><updated>2009-06-18T00:31:55.099+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutoriales'/><category scheme='http://www.blogger.com/atom/ns#' term='Ingenieria Inversa'/><category scheme='http://www.blogger.com/atom/ns#' term='Analisis'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerabilidades y Exploits'/><title type='text'>01-lizer-sissy-GS Mas SafeSEH</title><content type='html'>Interesante &lt;span style="font-weight: bold;"&gt;&lt;span style="font-style: italic;"&gt;ExploitMe&lt;/span&gt;&lt;/span&gt; con protección &lt;span style="font-style: italic;"&gt;anti-overflows&lt;/span&gt; con &lt;span style="font-weight: bold;"&gt;&lt;span style="font-style: italic;"&gt;SafeSEH&lt;/span&gt;&lt;/span&gt;, se puede ver como hacer un &lt;span style="font-style: italic;"&gt;ByPass&lt;/span&gt; para saltar la protección y conseguir el reto.&lt;br /&gt;&lt;br /&gt;Lo podéis descargar &lt;a href="http://ricardonarvaja.info/WEB/OTROS/EXPLOIT/01-lizer-sissy-GS+SafeSEH.rar"&gt;aquí&lt;/a&gt;.&lt;span id="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-1328922972211758111?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/1328922972211758111/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=1328922972211758111' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/1328922972211758111'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/1328922972211758111'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/05/01-lizer-sissy-gs-mas-safeseh.html' title='01-lizer-sissy-GS Mas SafeSEH'/><author><name>Shaddy</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_lqSqJt4JmcE/STtE5Z8nz9I/AAAAAAAAAAM/jFxXs9F2HWI/s1600-R/1386152joker.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-7162882157451576620</id><published>2009-02-03T02:36:00.000+01:00</published><updated>2009-05-14T02:42:07.352+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutoriales'/><category scheme='http://www.blogger.com/atom/ns#' term='Ingenieria Inversa'/><category scheme='http://www.blogger.com/atom/ns#' term='Retos'/><title type='text'>Crackme Hispasec</title><content type='html'>&lt;span id="fullpost"&gt;Hace bastante tiempo resolví también un &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;CrackMe&lt;/span&gt; que propusieron los de &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Hispasec&lt;/span&gt; como reto, creo que ya se publicaron bastantes soluciones, y ahora mismo no recuerdo como quedó.&lt;/span&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Se publicó el &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;26/11/2008&lt;/span&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;El objetivo es un &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;KeyFile&lt;/span&gt; que se va comprobando mediante unos &lt;span class="Apple-style-span" style="font-style: italic;"&gt;hilos&lt;/span&gt; haciendo el reto bastante interesante. Todo el análisis está realizado con &lt;span class="Apple-style-span" style="font-style: italic;"&gt;IDA Pro Disassembler&lt;/span&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Lo podéis descargar &lt;a href="http://ricardonarvaja.info/WEB/CURSO%20NUEVO/TEORIAS%20NUMERADAS/1001-1100/1077-Crackme%20Hispasec%20%28Sherab%20Giovannini%29.doc.7z"&gt;aquí&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Nota: El archivo viene como &lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;.doc.7z.doc&lt;/span&gt;&lt;/span&gt; debéis renombrarlo a &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;.7z&lt;/span&gt; para descomprimirlo.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;AbsshA&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-7162882157451576620?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/7162882157451576620/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=7162882157451576620' title='3 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/7162882157451576620'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/7162882157451576620'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/02/crackme-hispasec.html' title='Crackme Hispasec'/><author><name>Shaddy</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_lqSqJt4JmcE/STtE5Z8nz9I/AAAAAAAAAAM/jFxXs9F2HWI/s1600-R/1386152joker.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-578967112340616631</id><published>2009-02-01T04:17:00.000+01:00</published><updated>2009-05-04T04:38:08.410+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutoriales'/><category scheme='http://www.blogger.com/atom/ns#' term='Ingenieria Inversa'/><title type='text'>Script en Python para desempaquetar un PE</title><content type='html'>El último y final &lt;span class="Apple-style-span" style="font-style: italic;"&gt;Nivel 5&lt;/span&gt; del &lt;span class="Apple-style-span" style="font-style: italic;"&gt;Concurso 1&lt;/span&gt; de &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;CracksLatinos&lt;/span&gt;.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Aquí se nos pedía escribir un script en &lt;span class="Apple-style-span" style="font-style: italic;"&gt;python&lt;/span&gt; que sea capaz de desempacar un &lt;span class="Apple-style-span" style="font-style: italic;"&gt;Aspack&lt;/span&gt; o &lt;span class="Apple-style-span" style="font-style: italic;"&gt;UPX&lt;/span&gt; y además, comprobar que la tabla &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;IAT&lt;/span&gt; (&lt;span class="Apple-style-span" style="font-style: italic;"&gt;Import Table Address&lt;/span&gt;) esté en perfecto estado.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;El fichero incluye el &lt;span class="Apple-style-span" style="font-style: italic;"&gt;script &lt;/span&gt;en &lt;span class="Apple-style-span" style="font-style: italic;"&gt;Python&lt;/span&gt; tanto para la descompresión como el debugger. También incluye el &lt;span class="Apple-style-span" style="font-style: italic;"&gt;Crackme v1.0 de Cruehead&lt;/span&gt; comprimido con &lt;span class="Apple-style-span" style="font-style: italic;"&gt;UPX&lt;/span&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Lo podéis descargar &lt;a href="http://ricardonarvaja.info/WEB/CONCURSOS%202008/CONCURSO%201/NIVEL%205/CONCURSO%201-2008.Nivel%205%20Script%20de%20Python.rar"&gt;aquí&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;AbsshA&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-578967112340616631?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/578967112340616631/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=578967112340616631' title='2 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/578967112340616631'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/578967112340616631'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/05/script-en-python-para-desempaquetar-un.html' title='Script en Python para desempaquetar un PE'/><author><name>Shaddy</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_lqSqJt4JmcE/STtE5Z8nz9I/AAAAAAAAAAM/jFxXs9F2HWI/s1600-R/1386152joker.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-870797475151915082</id><published>2009-02-01T04:11:00.001+01:00</published><updated>2009-05-18T16:56:04.231+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutoriales'/><category scheme='http://www.blogger.com/atom/ns#' term='Ingenieria Inversa'/><category scheme='http://www.blogger.com/atom/ns#' term='Unpacking'/><title type='text'>VideoRedo v2.2.1.445</title><content type='html'>Éste es el &lt;span class="Apple-style-span" style="font-style: italic;"&gt;Nivel 4 &lt;/span&gt;del&lt;span class="Apple-style-span" style="font-style: italic;"&gt; Concurso 1&lt;/span&gt; de &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;CracksLatinos&lt;/span&gt;.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Es un programa comercial y un tutorial escrito con fines única y exclusivamente educativos, el autor no se responsabiliza del uso que se le de. (La historia de siempre, vamos).&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Está protegido con &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Armadillo &lt;/span&gt;con todas sus protecciones habilitadas, para entretenernos.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;El fichero incluye el &lt;span class="Apple-style-span" style="font-style: italic;"&gt;script&lt;/span&gt; para &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;OllyDBG&lt;/span&gt; y la librería &lt;span class="Apple-style-span" style="font-weight: bold; font-style: italic;"&gt;armaccess.dll&lt;/span&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt; &lt;/span&gt;para dejar registrado el programa.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Lo podéis descargar &lt;a href="http://ricardonarvaja.info/WEB/CONCURSOS%202008/CONCURSO%201/NIVEL%204/Nivel%204%20%28AbsshA%29.rar"&gt;aquí&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;AbsshA&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-870797475151915082?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/870797475151915082/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=870797475151915082' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/870797475151915082'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/870797475151915082'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/05/videoredo-v221445.html' title='VideoRedo v2.2.1.445'/><author><name>Shaddy</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_lqSqJt4JmcE/STtE5Z8nz9I/AAAAAAAAAAM/jFxXs9F2HWI/s1600-R/1386152joker.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-6991065003442826696</id><published>2009-02-01T04:05:00.001+01:00</published><updated>2009-05-18T16:56:36.395+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutoriales'/><category scheme='http://www.blogger.com/atom/ns#' term='Ingenieria Inversa'/><category scheme='http://www.blogger.com/atom/ns#' term='Unpacking'/><title type='text'>TrashReg (DotFix)</title><content type='html'>Éste fue el &lt;span class="Apple-style-span" style="font-style: italic;"&gt;Nivel 3&lt;/span&gt; del &lt;span class="Apple-style-span" style="font-style: italic;"&gt;Concurso 1&lt;/span&gt; de &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;CracksLatinos&lt;/span&gt;.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Muestro como desproteger el programa empaquetado con &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;DotFix&lt;/span&gt; y reducir el ejecutable quitando las secciones innecesarias.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;En la parte de teoría muestro dos puntos interesantes.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;- &lt;span class="Apple-style-span" style="font-style: italic;"&gt;Sistemas de ofuscación (Funcionamiento básico).&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;- Sistemas de Redirección por SEH. (Self Estructured Handler).&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;Incluye el &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Plugin&lt;/span&gt; &lt;span class="Apple-style-span" style="font-style: italic;"&gt;DeJunk v0.13&lt;/span&gt; con el &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Junkdb.cfg&lt;/span&gt; modificado y adaptado para éste packer y su sistema de ofuscación. También el ejecutable resultante desempaquetado.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Lo podéis descargar &lt;a href="http://ricardonarvaja.info/WEB/CONCURSOS%202008/CONCURSO%201/NIVEL%203/Nivel%203%20%28DotFix%29%20-%20AbsshA.rar"&gt;aquí&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;AbsshA&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-6991065003442826696?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/6991065003442826696/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=6991065003442826696' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/6991065003442826696'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/6991065003442826696'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/05/trashreg-dotfix.html' title='TrashReg (DotFix)'/><author><name>Shaddy</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_lqSqJt4JmcE/STtE5Z8nz9I/AAAAAAAAAAM/jFxXs9F2HWI/s1600-R/1386152joker.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-2843929439963674749</id><published>2009-02-01T03:57:00.002+01:00</published><updated>2009-05-18T17:03:58.085+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutoriales'/><category scheme='http://www.blogger.com/atom/ns#' term='Ingenieria Inversa'/><category scheme='http://www.blogger.com/atom/ns#' term='Keygenning'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerabilidades y Exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploits'/><title type='text'>Against Crackme</title><content type='html'>Éste es el &lt;span class="Apple-style-span" style="font-style: italic;"&gt;Nivel 2&lt;/span&gt; del &lt;span class="Apple-style-span" style="font-style: italic;"&gt;Concurso 1&lt;/span&gt; de &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;CracksLatinos&lt;/span&gt;.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Éste &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;CrackMe&lt;/span&gt; utiliza un &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Driver&lt;/span&gt; con el cual gestiona la comprobación del número de serie.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Destaco que no utilizo ningún depurador &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Ring0&lt;/span&gt; para resolverlo, sino &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;OllyDBG&lt;/span&gt; para analizar el &lt;span class="Apple-style-span" style="font-style: italic;"&gt;Driver&lt;/span&gt; en ejecución e &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;IDA.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;Tanto el &lt;span class="Apple-style-span" style="font-style: italic;"&gt;Driver&lt;/span&gt; modificado para funcionar en &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;OllyBG&lt;/span&gt; como el &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Keygen &lt;/span&gt;del &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;CrackMe&lt;/span&gt; vienen con el tutorial.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Lo podéis descargar &lt;a href="http://ricardonarvaja.info/WEB/CONCURSOS%202008/CONCURSO%201/NIVEL%202/Nivel%202%20AbsSha.zip"&gt;aquí&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;AbsshA&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-2843929439963674749?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/2843929439963674749/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=2843929439963674749' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/2843929439963674749'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/2843929439963674749'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/05/against-crackme.html' title='Against Crackme'/><author><name>Shaddy</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_lqSqJt4JmcE/STtE5Z8nz9I/AAAAAAAAAAM/jFxXs9F2HWI/s1600-R/1386152joker.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-6891412703346630761</id><published>2009-02-01T03:47:00.003+01:00</published><updated>2009-05-18T17:04:12.091+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutoriales'/><category scheme='http://www.blogger.com/atom/ns#' term='Ingenieria Inversa'/><category scheme='http://www.blogger.com/atom/ns#' term='Keygenning'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerabilidades y Exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploits'/><title type='text'>Jame's Crackme v1.0</title><content type='html'>Éste CrackMe fue publicado en el Concurso 1 de la lista &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;CracksLatinos.&lt;/span&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;Está compilado en &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Dev C++&lt;/span&gt;, y se componía de 3 retos:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;- Obtener un número de serie.&lt;/div&gt;&lt;div&gt;- Realizar un KeyGen.&lt;/div&gt;&lt;div&gt;- Explotar la vulnerabilidad.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;El archivo contiene el tutorial en &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;pdf&lt;/span&gt; y con el &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;KeyGen&lt;/span&gt; del &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;CrackMe.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Lo podéis descargar &lt;a href="http://ricardonarvaja.info/WEB/CONCURSOS%202008/CONCURSO%201/NIVEL%201/Nivel%201%20%28a,%20b%20y%20c%29%20por%20AbsshA.rar"&gt;aquí.&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;AbsshA.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-6891412703346630761?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/6891412703346630761/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=6891412703346630761' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/6891412703346630761'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/6891412703346630761'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/05/james-crackme-v10.html' title='Jame&apos;s Crackme v1.0'/><author><name>Shaddy</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_lqSqJt4JmcE/STtE5Z8nz9I/AAAAAAAAAAM/jFxXs9F2HWI/s1600-R/1386152joker.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-1443606429560886176</id><published>2009-01-01T03:59:00.000+01:00</published><updated>2009-05-04T04:37:17.862+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutoriales'/><category scheme='http://www.blogger.com/atom/ns#' term='Ingenieria Inversa'/><title type='text'>DCrack(FOFF) Crackme v1.0</title><content type='html'>Interesante &lt;span style="font-style: italic;"&gt;&lt;span style="font-weight: bold;"&gt;Crackme&lt;/span&gt;&lt;/span&gt; con un sistema de &lt;span style="font-style: italic;"&gt;ofuscación de código&lt;/span&gt;, y &lt;span style="font-style: italic;"&gt;redirección por SEH&lt;/span&gt; que gestionarán la función que comprueba el &lt;span style="font-style: italic;"&gt;serial. &lt;/span&gt;También se puede ver el uso de herramientas como&lt;span style="font-weight: bold; font-style: italic;"&gt; CrypTool&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Interesante sistema, sin embargo un pobre algoritmo criptográfico.&lt;br /&gt;&lt;br /&gt;Lo podéis descargar &lt;a href="http://ricardonarvaja.info/WEB/CURSO%20NUEVO/TEORIAS%20NUMERADAS/1001-1100/1001-DCrack%28FOFF%29.Crackme.v1.0.By.AbsshA.zip"&gt;aquí&lt;/a&gt;.&lt;span id="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-1443606429560886176?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/1443606429560886176/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=1443606429560886176' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/1443606429560886176'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/1443606429560886176'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/05/dcrackfoff-crackme-v10.html' title='DCrack(FOFF) Crackme v1.0'/><author><name>Shaddy</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_lqSqJt4JmcE/STtE5Z8nz9I/AAAAAAAAAAM/jFxXs9F2HWI/s1600-R/1386152joker.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-3254073814258512081</id><published>2009-01-01T03:50:00.000+01:00</published><updated>2009-05-04T04:37:33.728+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutoriales'/><category scheme='http://www.blogger.com/atom/ns#' term='Ingenieria Inversa'/><title type='text'>Teoría de Mensajes y Eventos</title><content type='html'>A muchos os irá bien, cuando no sabéis como entrarle un programa, cuando no para el &lt;span style="font-weight: bold; font-style: italic;"&gt;punto H&lt;/span&gt;, cuando hay un evento y no sabéis como acceder a él. En resumen, una buena alternativa para ir directamente a la &lt;span style="font-style: italic;"&gt;&lt;span style="font-weight: bold;"&gt;Garlic Zone&lt;/span&gt;&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Espero que os guste.&lt;br /&gt;&lt;br /&gt;Lo podéis descargar &lt;span style="text-decoration: underline;"&gt;&lt;a href="http://ricardonarvaja.info/WEB/CURSO%20NUEVO/TEORIAS%20NUMERADAS/1001-1100/1027-Teor%c3%ada_-_Mensajes_y_Eventos_en_Windows.zip"&gt;aquí&lt;/a&gt;.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-3254073814258512081?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/3254073814258512081/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=3254073814258512081' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/3254073814258512081'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/3254073814258512081'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/05/teoria-de-mensajes-y-eventos.html' title='Teoría de Mensajes y Eventos'/><author><name>Shaddy</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_lqSqJt4JmcE/STtE5Z8nz9I/AAAAAAAAAAM/jFxXs9F2HWI/s1600-R/1386152joker.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-7212283662597619264</id><published>2008-12-07T06:21:00.002+01:00</published><updated>2009-05-18T17:00:10.033+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><title type='text'>Análisis de Malware - Spyware</title><content type='html'>&lt;div style="text-align: left;"&gt;Hola a todos, éste es mi primer artículo de mi nuevo blog. Así que poco a poco iré mejorando la calidad de lo que escribo, ya que al principio todo es más complicado.&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;La idea de éste blog es ir poco a poco mostrando información y métodos que bajo mi punto de vista son interesantes, y como ésto ya se irá viendo, sin más, nos adentramos en el mundo del "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Mal&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;ware&lt;/span&gt;&lt;/span&gt;".&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;La historia comenzó básicamente cuando hoy busqué un programa que utiliza un sistema que salió hace muy poquito, el sistema &lt;span style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;GPU&lt;/span&gt;&lt;/span&gt;, y que fue distribuido por la empresa "&lt;span style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;ElcomSoft&lt;/span&gt;&lt;/span&gt;".&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Éste software en principio mejora la velocidad de procesamiento utilizando la tecnología de &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;Nvidia&lt;/span&gt;&lt;/span&gt; y su innovador sistema &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;CUDA&lt;/span&gt;&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Buscando éste software me encontré con un enlace de una página de &lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;rapidshare&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;, por norma general el software que sale de páginas como "www.&lt;span style="font-style: italic;"&gt;vagos.es&lt;/span&gt;", "www.&lt;span style="font-style: italic;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;taringa&lt;/span&gt;.es&lt;/span&gt;", etc. me da bastante confianza, y pese a lo desconfiado que suelo ser con los ejecutables, me decidí a instalarlo en la máquina que utilizo normalmente, es decir, que no lo abrí dentro de una máquina virtual (&lt;span style="font-style: italic;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;VMware&lt;/span&gt;&lt;/span&gt;).&lt;br /&gt;&lt;br /&gt;La sorpresa fue que al rato de instalarlo apareció un mensaje que ya había visto antes, pero que sinceramente no esperaba volverlo a encontrar ahora. Al principio durante los primeros segundos me mosqueé un poco, estaba haciendo varias cosas y me vi obligado a quitarlo de inmediato. Ya hace días que venía con la idea de hacer un artículo sobre &lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;malware&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;  así que me dije a mi mismo que ésta sería una buena oportunidad.&lt;br /&gt;&lt;br /&gt;Dicho ésto mi objetivo es escribir mis experiencias, para que con ellas poco a poco podáis deshaceros del &lt;span style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;malware&lt;/span&gt;&lt;/span&gt; de vuestros &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;PCs&lt;/span&gt;, y no conformes con ésto, saber que es lo que realmente está pasando.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;Lo primero de lo que uno se da cuenta es que en el escritorio aparece un claro mensaje de que tienes un "&lt;span style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;Adware&lt;/span&gt;&lt;/span&gt;" y que pulses un botón para descargar un &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;antivirus&lt;/span&gt;. Con un precioso mensaje "&lt;span style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;Warning&lt;/span&gt;! &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;Spyware&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;detected&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_16"&gt;on&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_17"&gt;your&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_18"&gt;computer&lt;/span&gt;!&lt;/span&gt;".&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_lqSqJt4JmcE/STtK5-CyBNI/AAAAAAAAAAo/VbqUktR-dAs/s1600-h/Splash.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 202px;" src="http://3.bp.blogspot.com/_lqSqJt4JmcE/STtK5-CyBNI/AAAAAAAAAAo/VbqUktR-dAs/s320/Splash.bmp" alt="" id="BLOGGER_PHOTO_ID_5276893748162331858" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Si intentamos arrancar el &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Administrador de Tareas &lt;/span&gt; nos dirá que está deshabilitado. Por lo tanto ya deducimos que ha modificado alguna parte del sistema para evitar que los usuarios inexpertos accedan a cerrar un proceso.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="http://1.bp.blogspot.com/_lqSqJt4JmcE/STuJ3OP7cdI/AAAAAAAAAAw/-3dlbvDxrjM/s320/Imagen4.jpg" alt="" id="BLOGGER_PHOTO_ID_5276962970205385170" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 98px;" border="0" /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Nosotros no disponemos de él, el método para solucionar ésto es sencillo, simplemente se cambia un valor de ésta clave.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;"Software\Microsoft\&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_19"&gt;Windows&lt;/span&gt;\&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_20"&gt;CurrentVersion&lt;/span&gt;\&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_21"&gt;Policies&lt;/span&gt;\&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_22"&gt;System&lt;/span&gt;"&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Donde &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_23"&gt;veréis&lt;/span&gt; rápidamente que es lo que se debe modificar. Aun así el sistema está comprobando periódicamente el valor de la clave y modificándolo constantemente (lo veremos al &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_24"&gt;desensamblarlo&lt;/span&gt;).&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Sin embargo &lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_25"&gt;Windows&lt;/span&gt;&lt;/span&gt; nos da algunas herramientas para salir del paso, entre otras utilizaremos "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_26"&gt;Tasklist&lt;/span&gt;&lt;/span&gt;" y "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_27"&gt;Taskkill&lt;/span&gt;&lt;/span&gt;". La primera para listar los procesos y la segunda para cerrarlos.&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_lqSqJt4JmcE/STuK9Rpd9gI/AAAAAAAAABI/t2dZ9eggQ7k/s1600-h/Imagen1.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/_lqSqJt4JmcE/STuK9Rpd9gI/AAAAAAAAABI/t2dZ9eggQ7k/s400/Imagen1.jpg" alt="" id="BLOGGER_PHOTO_ID_5276964173708654082" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 201px;" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Aunque no se aprecie bien la imagen, ahí vemos directamente un "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;.&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_28"&gt;exe&lt;/span&gt;&lt;/span&gt;" que si no es el encargado de todo ésto al menos eso quieren que creamos. Su nombre es "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_29"&gt;lphc&lt;/span&gt;37&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_30"&gt;kj&lt;/span&gt;0e98k.&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_31"&gt;exe&lt;/span&gt;&lt;/span&gt;" que en un principio puede parecer que es el culpable pero nunca hay que dar por hecho nada. &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_32"&gt;Acordaros&lt;/span&gt; que solamente vemos lo que quieren que veamos.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Para analizar el sistema, y saber que es lo que tenemos dentro yo recomiendo un programa esencial. Y su nombre es "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_33"&gt;ProcessMonitor&lt;/span&gt;&lt;/span&gt;" es de la casa de "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;S&lt;/span&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_34"&gt;ysInternals&lt;/span&gt;&lt;/span&gt;" y es un programa fantástico, ya que con él puedes averiguar mucha información sobre cualquier ejecutable que esté corriendo y las operaciones que hace.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Lo podéis bajar &lt;a href="http://download.sysinternals.com/Files/ProcessMonitor.zip"&gt;aquí&lt;/a&gt;. &lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Nosotros podemos prescindir de ésta herramienta si no queda otra, pero si podemos utilizarla es obvio que vamos a hacerlo. Así que lo primero de todo es abrir y ver cuales son los procesos que tenemos abiertos y la información que podemos obtener. Para abrir el "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_35"&gt;Arbol&lt;/span&gt; de &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_36"&gt;Processos&lt;/span&gt;&lt;/span&gt;" o bien pulsamos "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_37"&gt;CTRL&lt;/span&gt; + T"&lt;/span&gt; o bien lo ejecutamos desde el menú &lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_38"&gt;Tools&lt;/span&gt;&lt;/span&gt;.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: rgb(0, 0, 238);"&gt;&lt;img src="http://4.bp.blogspot.com/_lqSqJt4JmcE/STub5LPK3MI/AAAAAAAAABQ/-y3QOIBGUQw/s320/07-12-2008+10-45-27.jpg" alt="" id="BLOGGER_PHOTO_ID_5276982794965933250" style="margin: 0px 10px 10px 0px; text-align: center; float: left; cursor: pointer; width: 183px; height: 168px;" border="0" /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Si os fijáis aquí tenemos de nuevo el archivo, con su &lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_39"&gt;PID&lt;/span&gt;&lt;/span&gt; (&lt;span class="Apple-style-span" style="font-style: italic;"&gt;Identificador&lt;/span&gt;), sin embargo vamos a hacer una captura de cual es el ejecutable que anda detrás de los mensajitos, para ello existe un botón en el mismo &lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_40"&gt;ProcessMonitor&lt;/span&gt;&lt;/span&gt; con el cual marcando cualquier ventana automáticamente &lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_41"&gt;Sniffea&lt;/span&gt;&lt;/span&gt; todos los datos de ficheros, registro e Internet.&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Por ello una vez sale cualquier mensaje tipo bocadillo recordando que tenéis un virus, y un gran etc. lo mejor es localizarlo con ésta función.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;En el caso de encontrarnos con un mensaje así.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_lqSqJt4JmcE/STudMiqsnvI/AAAAAAAAABg/c-F_jOnJy8M/s1600-h/Imagen2.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/_lqSqJt4JmcE/STudMiqsnvI/AAAAAAAAABg/c-F_jOnJy8M/s320/Imagen2.jpg" alt="" id="BLOGGER_PHOTO_ID_5276984227184549618" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 239px;" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Ya haríamos uso del botón que activa en su filtro la opción de &lt;span class="Apple-style-span" style="font-style: italic;"&gt;Incluir&lt;/span&gt; &lt;span class="Apple-style-span" style="font-style: italic;"&gt;el Proceso &lt;/span&gt;indicándole la ventana.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_lqSqJt4JmcE/STurfJ5kbdI/AAAAAAAAABo/zsYe_1nAKQI/s1600-h/Imagen5.jpg"&gt;&lt;img src="http://2.bp.blogspot.com/_lqSqJt4JmcE/STurfJ5kbdI/AAAAAAAAABo/zsYe_1nAKQI/s400/Imagen5.jpg" alt="" id="BLOGGER_PHOTO_ID_5276999940116344274" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 89px;" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;De éste modo rápidamente nos hará un listado no solo con el proceso involucrado, sino que además sabremos básicamente lo que está haciendo.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_lqSqJt4JmcE/STuw8Y5Yn9I/AAAAAAAAABw/uLC4zi8yxxE/s1600-h/07-12-2008+12-14-09.jpg"&gt;&lt;img src="http://3.bp.blogspot.com/_lqSqJt4JmcE/STuw8Y5Yn9I/AAAAAAAAABw/uLC4zi8yxxE/s400/07-12-2008+12-14-09.jpg" alt="" id="BLOGGER_PHOTO_ID_5277005939916447698" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 59px;" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Si os fijáis ya tenemos más candidatos al premio, solamente con ésta imagen ya veis primero, quien está constantemente deshabilitando el &lt;span class="Apple-style-span" style="font-style: italic;"&gt;Administrador de Tareas. &lt;/span&gt;Además por el icono ya deducimos fácilmente que se trata de un &lt;span class="Apple-style-span" style="font-style: italic;"&gt;Visual &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_42"&gt;Basic&lt;/span&gt;.&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Por el momento tenemos dos ejecutables, uno con un nombre irrepetible, y el otro que parece ser que está dando guerra. Copio ambos ejecutables para el análisis posterior, y voy eliminando los procesos a ver como responden.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;En más de una ocasión encontraréis procesos que os deniegan el acceso a la hora de cerrarlos, con ese famoso mensaje de "&lt;span class="Apple-style-span" style="font-style: italic;"&gt;Acceso Denegado&lt;/span&gt;".&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Cuando ésto pase tendréis que hacer uso simplemente de "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_44"&gt;Taskkill&lt;/span&gt;&lt;/span&gt;", para cerrar un proceso normalmente podemos hacerlo de varias formas.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;- &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_45"&gt;Taskkill&lt;/span&gt; /&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_46"&gt;IM&lt;/span&gt; proceso.&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_47"&gt;exe&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;- &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_48"&gt;Taskkill&lt;/span&gt; /&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_49"&gt;PID&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Por una parte, tenemos la opción de seleccionarlo con el nombre y por otra por el &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_50"&gt;handle&lt;/span&gt; del proceso. Sin embargo si el proceso se resiste, hay que forzarlo, y ésto se hace con la opción "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;/F&lt;/span&gt;". &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_51"&gt;Ej&lt;/span&gt;.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;- &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_52"&gt;Taskkill&lt;/span&gt; /&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_53"&gt;IM&lt;/span&gt; "proceso.&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_54"&gt;exe&lt;/span&gt;" /F&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;De éste modo obligamos al cierre del proceso y podemos eliminar el archivo sin problemas.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Volviendo a la lista de antes localizamos los dos procesos.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_lqSqJt4JmcE/STxk174OTxI/AAAAAAAAACQ/nZYLmz1KidU/s1600-h/Image7.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/_lqSqJt4JmcE/STxk174OTxI/AAAAAAAAACQ/nZYLmz1KidU/s400/Image7.jpg" alt="" id="BLOGGER_PHOTO_ID_5277203741140733714" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 53px;" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Y una vez los hemos localizado ya podemos forzar el cierre con los parámetros necesarios.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_lqSqJt4JmcE/STxknJ7AtwI/AAAAAAAAACI/nQOxPJWqJHQ/s1600-h/Imagen+6.jpg"&gt;&lt;img src="http://3.bp.blogspot.com/_lqSqJt4JmcE/STxknJ7AtwI/AAAAAAAAACI/nQOxPJWqJHQ/s400/Imagen+6.jpg" alt="" id="BLOGGER_PHOTO_ID_5277203487212484354" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 53px;" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Ahora que hemos eliminado para poder continuar, vamos a ver las opciones que trae &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_55"&gt;taskmgr&lt;/span&gt;&lt;/span&gt; (&lt;span class="Apple-style-span" style="font-style: italic;"&gt;Administrador de Tareas&lt;/span&gt;) para habilitarlo, yo por ejemplo utilice el mensaje que nos muestra.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_lqSqJt4JmcE/STxhNj_AnoI/AAAAAAAAACA/NWpqzTPG1bY/s1600-h/Imagen4.jpg"&gt;&lt;img src="http://1.bp.blogspot.com/_lqSqJt4JmcE/STxhNj_AnoI/AAAAAAAAACA/NWpqzTPG1bY/s400/Imagen4.jpg" alt="" id="BLOGGER_PHOTO_ID_5277199748997095042" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 122px;" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Y ya una vez vemos el mensaje lo buscamos en &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_56"&gt;OllyDBG&lt;/span&gt;&lt;/span&gt; para poder localizar el problema.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_lqSqJt4JmcE/STxnoPQ6pAI/AAAAAAAAACY/i14nnaXHEiw/s1600-h/Imagen+7.jpg"&gt;&lt;img src="http://1.bp.blogspot.com/_lqSqJt4JmcE/STxnoPQ6pAI/AAAAAAAAACY/i14nnaXHEiw/s400/Imagen+7.jpg" alt="" id="BLOGGER_PHOTO_ID_5277206804361290754" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 188px;" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;y a partir de ahí ya se puede analizar para ver donde está el problema. Una vez hemos entrado en él ya podemos llegar a la zona del código, para ello tenemos que seleccionar el hilo principal.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Cuando hacemos "&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_57"&gt;attach&lt;/span&gt;" sobre un programa lo que hacemos es situarnos en modo depuración sobre él y creando un nuevo hilo y haciendo uso de la función "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_58"&gt;DbgUiRemoteBreakin&lt;/span&gt;&lt;/span&gt;" como función de comienzo del hilo de entrada, y luego para el proceso con "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_59"&gt;DbgBreakPoint&lt;/span&gt;&lt;/span&gt;" para situarnos precisamente en lo que es el "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_60"&gt;RETN&lt;/span&gt;&lt;/span&gt;" donde nos quedamos parados.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Así que si pulsamos "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_61"&gt;ALT&lt;/span&gt; + T&lt;/span&gt;" (&lt;span class="Apple-style-span" style="font-style: italic;"&gt;Threads&lt;/span&gt;) podemos ver el hilo de depuración y el hilo principal. &lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_lqSqJt4JmcE/STyNUCzAwAI/AAAAAAAAAEo/e5jE9ba3Yso/s1600-h/Imagen+8.jpg"&gt;&lt;img src="http://3.bp.blogspot.com/_lqSqJt4JmcE/STyNUCzAwAI/AAAAAAAAAEo/e5jE9ba3Yso/s400/Imagen+8.jpg" alt="" id="BLOGGER_PHOTO_ID_5277248238859108354" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 71px;" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Cuando entremos sabremos fácilmente que estamos en el hilo correcto.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_lqSqJt4JmcE/STxsq1lV6MI/AAAAAAAAACo/qepLlq6oLAQ/s1600-h/Imagen+9.jpg"&gt;&lt;img src="http://3.bp.blogspot.com/_lqSqJt4JmcE/STxsq1lV6MI/AAAAAAAAACo/qepLlq6oLAQ/s400/Imagen+9.jpg" alt="" id="BLOGGER_PHOTO_ID_5277212346565388482" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 110px;" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Entonces ya sabiendo cual es el principal, lo podemos seleccionar para ver la &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_62"&gt;Stack&lt;/span&gt;&lt;/span&gt; (&lt;span class="Apple-style-span" style="font-style: italic;"&gt;Pila&lt;/span&gt;) y localizar la función del mensaje. Ésto se hace con "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;ALT + K&lt;/span&gt;" (&lt;span class="Apple-style-span" style="font-style: italic;"&gt;Call Stack&lt;/span&gt;).&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_lqSqJt4JmcE/STxt1Jv528I/AAAAAAAAACw/mMVFY9lJLEc/s1600-h/Imagen+10.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/_lqSqJt4JmcE/STxt1Jv528I/AAAAAAAAACw/mMVFY9lJLEc/s400/Imagen+10.jpg" alt="" id="BLOGGER_PHOTO_ID_5277213623288716226" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 185px;" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Ya localizamos el mensaje vemos inmediatamente debajo la función que lo llamó.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_lqSqJt4JmcE/STxuc7ltUSI/AAAAAAAAAC4/aryh5wvXGnQ/s1600-h/Imagen+11.jpg"&gt;&lt;img src="http://3.bp.blogspot.com/_lqSqJt4JmcE/STxuc7ltUSI/AAAAAAAAAC4/aryh5wvXGnQ/s400/Imagen+11.jpg" alt="" id="BLOGGER_PHOTO_ID_5277214306682622242" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 66px;" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Ahí fácilmente se puede localizar donde tenemos que actuar.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_lqSqJt4JmcE/STxvPPhAQLI/AAAAAAAAADA/YeGzdIeGNgc/s1600-h/Imagen+12.jpg"&gt;&lt;img src="http://3.bp.blogspot.com/_lqSqJt4JmcE/STxvPPhAQLI/AAAAAAAAADA/YeGzdIeGNgc/s400/Imagen+12.jpg" alt="" id="BLOGGER_PHOTO_ID_5277215171025060018" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 72px;" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Vemos que comprueba el valor de la variable en el registro "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;DisableTaskMgr&lt;/span&gt;" y la clave la abre un poco antes.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: rgb(0, 0, 238);"&gt;&lt;img src="http://3.bp.blogspot.com/_lqSqJt4JmcE/STxv5R5jC5I/AAAAAAAAADI/dBxGGEp7gqg/s400/Imagen+13.jpg" alt="" id="BLOGGER_PHOTO_ID_5277215893219380114" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 34px;" border="0" /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Con la clave.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;- &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Subkey&lt;/span&gt; = "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Software\Microsoft\Windows\CurrentVersion\Policies\System&lt;/span&gt;"&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Según el valor de la variable que es comparado aquí.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: rgb(0, 0, 0);"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_lqSqJt4JmcE/STxyVLOipjI/AAAAAAAAADY/2aYoh6iScpE/s1600-h/Imagen+14.jpg" style="text-decoration: none;"&gt;&lt;span class="Apple-style-span" style="color: rgb(0, 0, 0);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;img src="http://1.bp.blogspot.com/_lqSqJt4JmcE/STxyVLOipjI/AAAAAAAAADY/2aYoh6iScpE/s400/Imagen+14.jpg" alt="" id="BLOGGER_PHOTO_ID_5277218571487979058" style="margin: 0px auto 10px; text-decoration: underline; display: block; text-align: center; cursor: pointer; width: 400px; height: 55px;" border="0" /&gt;&lt;/a&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Si el &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Buffer&lt;/span&gt; es &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;0x0000000&lt;/span&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;1&lt;/span&gt; el Administrador de tareas no se llega a ejecutar. Por eso hay que cambiar el valor en el regedit.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_lqSqJt4JmcE/STx5eqORxDI/AAAAAAAAADg/o_DX8xgThag/s1600-h/Imagen+15.jpg"&gt;&lt;img src="http://2.bp.blogspot.com/_lqSqJt4JmcE/STx5eqORxDI/AAAAAAAAADg/o_DX8xgThag/s400/Imagen+15.jpg" alt="" id="BLOGGER_PHOTO_ID_5277226431008588850" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 60px;" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Así que para habilitarlo ha de quedar a &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;0&lt;/span&gt;. Ahora queda otra, una vez cerramos los procesos y eliminamos los archivos, hay que restaurar el escritorio. Ya que todavía tenemos la imagen de fondo que nos modificaron, y si damos a propiedades del escritorio nos deshabilitaron precisamente las opciones para modificarlo.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_lqSqJt4JmcE/STx7lmjHqsI/AAAAAAAAADo/cDxF_vdtFZs/s1600-h/Imagen+16.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/_lqSqJt4JmcE/STx7lmjHqsI/AAAAAAAAADo/cDxF_vdtFZs/s400/Imagen+16.jpg" alt="" id="BLOGGER_PHOTO_ID_5277228749304605378" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 147px;" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Son una captura de un pc normal y como quedó despues de ejecutar el spyware. Se ve claramente como faltan, tano el fondo de pantalla como el salvapantallas. Y siguiendo con el método anterior utilizaremos el &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;ProcessMonitor&lt;/span&gt; para capturar el proceso que se encarga de ello.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: rgb(0, 0, 238);"&gt;&lt;img src="http://3.bp.blogspot.com/_lqSqJt4JmcE/STx9aks-wfI/AAAAAAAAADw/IoKY2Iy3IQo/s400/Imagen+17.jpg" alt="" id="BLOGGER_PHOTO_ID_5277230758853788146" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 57px;" border="0" /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Si abrimos en la función de inicio en la ventana veremos la información necesaria.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_lqSqJt4JmcE/STx-Fnyb1BI/AAAAAAAAAD4/-opqTyW7lKY/s1600-h/Imagen+18.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/_lqSqJt4JmcE/STx-Fnyb1BI/AAAAAAAAAD4/-opqTyW7lKY/s400/Imagen+18.jpg" alt="" id="BLOGGER_PHOTO_ID_5277231498416346130" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 219px;" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Una vez tenemos la línea de ejecución la analizamos para ver donde tenemos las opciones importantes.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;- "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;C:\WINDOWS\system32\rundll32.exe" /d C:\WINDOWS\system32\shell32.dll,Control_RunDLL &lt;span class="Apple-style-span" style="color: rgb(0, 153, 0);"&gt;desk.cp&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span" style="color: rgb(0, 153, 0);"&gt;l&lt;/span&gt;.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Tenemos el módulo encargado de gestionar las propiedades de la pantalla, y es "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;desk.cpl&lt;/span&gt;" así que ya sabemos donde tenemos que actuar cuando actuemos con &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;OllyDBG&lt;/span&gt;.&lt;/div&gt;&lt;div style="text-align: left;"&gt;Abrimos el proceso  con "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Attach&lt;/span&gt;".&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_lqSqJt4JmcE/STx_T9e-uLI/AAAAAAAAAEA/C8QF6JYevZo/s1600-h/Imagen+19.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/_lqSqJt4JmcE/STx_T9e-uLI/AAAAAAAAAEA/C8QF6JYevZo/s400/Imagen+19.jpg" alt="" id="BLOGGER_PHOTO_ID_5277232844270123186" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 189px;" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Ahora asignamos los argumentos con el comando que nos dió el &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;ProcMon&lt;/span&gt;. En "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Debug &lt;/span&gt;&lt;span class="Apple-style-span"&gt;-&lt;/span&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt; Arguments&lt;/span&gt;&lt;span class="Apple-style-span"&gt;"&lt;/span&gt;.&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_lqSqJt4JmcE/STyCADO6UFI/AAAAAAAAAEQ/NFznzXMmlPQ/s1600-h/Imagen+21.jpg"&gt;&lt;img src="http://1.bp.blogspot.com/_lqSqJt4JmcE/STyCADO6UFI/AAAAAAAAAEQ/NFznzXMmlPQ/s400/Imagen+21.jpg" alt="" id="BLOGGER_PHOTO_ID_5277235800750837842" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 319px; height: 134px;" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Ahora reiniciamos el programa para cargar los argumentos "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;CTRL + F2&lt;/span&gt;" (&lt;span class="Apple-style-span" style="font-style: italic;"&gt;Restart&lt;/span&gt;) .&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Seguramente lo más probable es que haya modificado la configuración del sistema, y como es normal ésto se suele hacer mediante archivos "&lt;span class="Apple-style-span" style="font-style: italic;"&gt;.ini&lt;/span&gt;" o en el &lt;span class="Apple-style-span" style="font-style: italic;"&gt;registro. &lt;/span&gt;Si logeamos las funciones que acceden al registro mediante &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;RegQueryValueExA&lt;/span&gt; y &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;RegQueryValueExW &lt;/span&gt;tendremos quizás la solución al problema.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Para ir a la función hay que pulsar "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;CTRL + G&lt;/span&gt;" (&lt;span class="Apple-style-span" style="font-style: italic;"&gt;Go to - Expression&lt;/span&gt;) y le indicamos la función que queremos.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_lqSqJt4JmcE/STyD192iheI/AAAAAAAAAEY/In1R2jErCF4/s1600-h/Imagen+22.jpg"&gt;&lt;img src="http://4.bp.blogspot.com/_lqSqJt4JmcE/STyD192iheI/AAAAAAAAAEY/In1R2jErCF4/s400/Imagen+22.jpg" alt="" id="BLOGGER_PHOTO_ID_5277237826531001826" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 332px; height: 118px;" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Y una vez ahí ya podemos meter un &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Conditional BreakPoint.&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_lqSqJt4JmcE/STyExIIQGfI/AAAAAAAAAEg/kkR4WTctnMU/s1600-h/Imagen+23.jpg"&gt;&lt;img src="http://3.bp.blogspot.com/_lqSqJt4JmcE/STyExIIQGfI/AAAAAAAAAEg/kkR4WTctnMU/s400/Imagen+23.jpg" alt="" id="BLOGGER_PHOTO_ID_5277238842901928434" style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 248px;" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Con &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;RegQueryValueExW &lt;/span&gt;repito el procedimiento y ejecutándolo en el &lt;span class="Apple-style-span" style="font-style: italic;"&gt;log &lt;/span&gt;veremos los resultados. Yo lo guarde todo en un archivo para hacer búsquedas más deprisa (&lt;span class="Apple-style-span" style="font-style: italic;"&gt;Boton derecho Open Log File&lt;/span&gt;). Y lo que encontré es una estructura.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;div style="text-align: left;"&gt;77DA6FEF  CALL to RegQueryValueExW from SHLWAPI.77F442B1&lt;/div&gt;&lt;div style="text-align: left;"&gt;            hKey = A0&lt;/div&gt;&lt;div style="text-align: left;"&gt;            ValueName = "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;NoDispCPL&lt;/span&gt;"&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;div style="text-align: left;"&gt;77DA6FEF  CALL to RegQueryValueExW from SHLWAPI.77F442B1&lt;/div&gt;&lt;div style="text-align: left;"&gt;            hKey = 124&lt;/div&gt;&lt;div style="text-align: left;"&gt;            ValueName = "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;NoDispAppearancePage&lt;/span&gt;"&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;div style="text-align: left;"&gt;&lt;div style="text-align: left;"&gt;77DA6FEF  CALL to RegQueryValueExW from SHLWAPI.77F442B1&lt;/div&gt;&lt;div style="text-align: left;"&gt;            hKey = 124&lt;/div&gt;&lt;div style="text-align: left;"&gt;            ValueName = "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span" style="color: rgb(0, 102, 0);"&gt;NoDispBackgroundPage&lt;/span&gt;&lt;/span&gt;"&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;div style="text-align: left;"&gt;77DA6FEF  CALL to RegQueryValueExW from SHLWAPI.77F442B1&lt;/div&gt;&lt;div style="text-align: left;"&gt;            hKey = 124&lt;/div&gt;&lt;div style="text-align: left;"&gt;            ValueName = "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span" style="color: rgb(0, 102, 0);"&gt;NoDispScrSavPage&lt;/span&gt;&lt;/span&gt;"&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;div style="text-align: left;"&gt;77DA6FEF  CALL to RegQueryValueExW from SHLWAPI.77F442B1&lt;/div&gt;&lt;div style="text-align: left;"&gt;            hKey = 124&lt;/div&gt;&lt;div style="text-align: left;"&gt;            ValueName = "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;NoDispSettingsPage&lt;/span&gt;"&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Se puede dar uno cuenta rápidamente que son los valores que indican si se muestra o no la sección de la pestaña especificada. Añadiendo las funciones &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;RegOpenKeyExA&lt;/span&gt; y &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;RegOpenKeyExW&lt;/span&gt; con el mismo procedimiento anterior obtengo la clave.&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;div style="text-align: left;"&gt;77DA6A9F  CALL to RegOpenKeyExW from SHLWAPI.77F44126&lt;/div&gt;&lt;div style="text-align: left;"&gt;            hKey = HKEY_LOCAL_MACHINE&lt;/div&gt;&lt;div style="text-align: left;"&gt;            Subkey = "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Software\Microsoft\Windows\CurrentVersion\Policies\System&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;"&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;            Reserved = 0&lt;/div&gt;&lt;div style="text-align: left;"&gt;            Access = KEY_QUERY_VALUE&lt;/div&gt;&lt;div style="text-align: left;"&gt;            pHandle = 0007E8D4&lt;/div&gt;&lt;div style="text-align: left;"&gt;77DA6FEF  COND: &lt;/div&gt;&lt;div style="text-align: left;"&gt;77DA6FEF  CALL to RegQueryValueExW from SHLWAPI.77F442B1&lt;/div&gt;&lt;div style="text-align: left;"&gt;            hKey = 124&lt;/div&gt;&lt;div style="text-align: left;"&gt;            ValueName = "&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;NoDispAppearancePage&lt;/span&gt;"&lt;/div&gt;&lt;div style="text-align: left;"&gt;            Reserved = NULL&lt;/div&gt;&lt;div style="text-align: left;"&gt;            pValueType = 0007E77C&lt;/div&gt;&lt;div style="text-align: left;"&gt;            Buffer = 0007EA30&lt;/div&gt;&lt;div style="text-align: left;"&gt;            pBufSize = 0007EA2C&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Ahora debemos ir a.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;"&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;HKEY_LOCAL_MACHINE&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;\&lt;/span&gt;So&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;ftware\Microsoft\Windows\CurrentVersion\Policies\System&lt;/span&gt;&lt;span class="Apple-style-span" style=""&gt;"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;"&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;NoDispScrSavPage&lt;/span&gt;" (&lt;span class="Apple-style-span" style="font-style: italic;"&gt;Eliminar o poner a 0)&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: rgb(0, 102, 0); font-weight: bold;"&gt;&lt;span class="Apple-style-span" style="color: rgb(0, 0, 0);"&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;"&lt;/span&gt;NoDispBackgroundPage&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;" (&lt;span class="Apple-style-span" style="font-style: italic;"&gt;Eliminar o poner a 0&lt;/span&gt;)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Sin casi esfuerzo y haciendo uso de herramientas potentes en poco rato averiguamos el problema y lo solucionamos en el regedit, de ésta manera aparentemente está todo correcto. Pero falta el análisis de los dos ejecutables que copiamos y los posibles rastros (Imágenes, *.scr, .dll, etc.) que veréis en la segunda parte.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Un saludo, y hasta la siguiente entrega.&lt;/div&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-7212283662597619264?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/7212283662597619264/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=7212283662597619264' title='10 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/7212283662597619264'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/7212283662597619264'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2008/11/anlisis-de-malware-bypass-themida.html' title='Análisis de Malware - Spyware'/><author><name>Shaddy</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_lqSqJt4JmcE/STtE5Z8nz9I/AAAAAAAAAAM/jFxXs9F2HWI/s1600-R/1386152joker.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_lqSqJt4JmcE/STtK5-CyBNI/AAAAAAAAAAo/VbqUktR-dAs/s72-c/Splash.bmp' height='72' width='72'/><thr:total>10</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-324075433600412821</id><published>2008-12-06T02:11:00.000+01:00</published><updated>2009-05-04T04:39:48.055+02:00</updated><title type='text'>Comienzo de éste Blog</title><content type='html'>Bueno a partir de ahora comenzaremos con el nuevo &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Blog&lt;/span&gt; escribiendo las cosas más interesantes del mundo de la &lt;span class="Apple-style-span" style="font-style: italic; font-weight: bold;"&gt;Seguridad Informática&lt;/span&gt;.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Un saludo a todos.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-324075433600412821?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/324075433600412821/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=324075433600412821' title='1 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/324075433600412821'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/324075433600412821'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2008/12/inicio.html' title='Comienzo de éste Blog'/><author><name>Shaddy</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_lqSqJt4JmcE/STtE5Z8nz9I/AAAAAAAAAAM/jFxXs9F2HWI/s1600-R/1386152joker.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-4917738342947646779</id><published>2007-05-05T23:24:00.001+02:00</published><updated>2009-05-05T23:40:33.108+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Crackmes - Keygenmes'/><category scheme='http://www.blogger.com/atom/ns#' term='VB'/><title type='text'>VB</title><content type='html'>Aqui una entrada de VB&lt;span id="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-4917738342947646779?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/4917738342947646779/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=4917738342947646779' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/4917738342947646779'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/4917738342947646779'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/05/vb.html' title='VB'/><author><name>Amerikano</name><uri>http://www.blogger.com/profile/12633023812736391713</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_UUAPhcG-yh0/SUkdd9-SAGI/AAAAAAAAAA4/2bBLcSormNU/S220/America.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-8034540665586100826</id><published>2007-05-05T23:24:00.000+02:00</published><updated>2009-05-05T23:39:57.329+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Crackmes - Keygenmes'/><category scheme='http://www.blogger.com/atom/ns#' term='Otros'/><title type='text'>Otros</title><content type='html'>Aqui una entrada de otros&lt;span id="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-8034540665586100826?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/8034540665586100826/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=8034540665586100826' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/8034540665586100826'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/8034540665586100826'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/05/otros.html' title='Otros'/><author><name>Amerikano</name><uri>http://www.blogger.com/profile/12633023812736391713</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_UUAPhcG-yh0/SUkdd9-SAGI/AAAAAAAAAA4/2bBLcSormNU/S220/America.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-8287775198817627093</id><published>2007-05-05T23:23:00.000+02:00</published><updated>2009-05-05T23:40:52.900+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Crackmes - Keygenmes'/><category scheme='http://www.blogger.com/atom/ns#' term='.NET'/><title type='text'>.NET</title><content type='html'>Aqui una entrada de .Net&lt;span id="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-8287775198817627093?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/8287775198817627093/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=8287775198817627093' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/8287775198817627093'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/8287775198817627093'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/05/net.html' title='.NET'/><author><name>Amerikano</name><uri>http://www.blogger.com/profile/12633023812736391713</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_UUAPhcG-yh0/SUkdd9-SAGI/AAAAAAAAAA4/2bBLcSormNU/S220/America.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-450289466876460903</id><published>2007-05-05T23:22:00.000+02:00</published><updated>2009-05-05T23:41:12.937+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Varias'/><title type='text'>Herramientas Varias</title><content type='html'>Aqui una entrada de varias&lt;span id="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-450289466876460903?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/450289466876460903/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=450289466876460903' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/450289466876460903'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/450289466876460903'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/05/herramientas-varias.html' title='Herramientas Varias'/><author><name>Amerikano</name><uri>http://www.blogger.com/profile/12633023812736391713</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_UUAPhcG-yh0/SUkdd9-SAGI/AAAAAAAAAA4/2bBLcSormNU/S220/America.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-8721244894005799504</id><published>2007-05-05T23:21:00.001+02:00</published><updated>2009-05-05T23:42:13.578+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Analizadores'/><title type='text'>Analizadores</title><content type='html'>Aqui una entrada de analizadores&lt;span id="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-8721244894005799504?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/8721244894005799504/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=8721244894005799504' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/8721244894005799504'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/8721244894005799504'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/05/analizadores.html' title='Analizadores'/><author><name>Amerikano</name><uri>http://www.blogger.com/profile/12633023812736391713</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_UUAPhcG-yh0/SUkdd9-SAGI/AAAAAAAAAA4/2bBLcSormNU/S220/America.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-7912324272579563650</id><published>2007-05-05T23:21:00.000+02:00</published><updated>2009-05-05T23:41:46.887+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Editores'/><title type='text'>Editores</title><content type='html'>Aqui una entrada de editores&lt;span id="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-7912324272579563650?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/7912324272579563650/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=7912324272579563650' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/7912324272579563650'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/7912324272579563650'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/05/editores.html' title='Editores'/><author><name>Amerikano</name><uri>http://www.blogger.com/profile/12633023812736391713</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_UUAPhcG-yh0/SUkdd9-SAGI/AAAAAAAAAA4/2bBLcSormNU/S220/America.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-1167036227541128318</id><published>2007-05-05T23:19:00.000+02:00</published><updated>2009-05-05T23:42:35.872+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Herramientas'/><category scheme='http://www.blogger.com/atom/ns#' term='Depuradores'/><title type='text'>Depuradores</title><content type='html'>Aqui una entrada de depuradores&lt;span id="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-1167036227541128318?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/1167036227541128318/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=1167036227541128318' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/1167036227541128318'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/1167036227541128318'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/05/depuradores.html' title='Depuradores'/><author><name>Amerikano</name><uri>http://www.blogger.com/profile/12633023812736391713</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_UUAPhcG-yh0/SUkdd9-SAGI/AAAAAAAAAA4/2bBLcSormNU/S220/America.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-5756368978384751133</id><published>2007-05-05T23:17:00.000+02:00</published><updated>2009-05-05T23:43:36.051+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Worms'/><title type='text'>Worms</title><content type='html'>Aqui una entrada de worms&lt;span id="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-5756368978384751133?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/5756368978384751133/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=5756368978384751133' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/5756368978384751133'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/5756368978384751133'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/05/worms.html' title='Worms'/><author><name>Amerikano</name><uri>http://www.blogger.com/profile/12633023812736391713</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_UUAPhcG-yh0/SUkdd9-SAGI/AAAAAAAAAA4/2bBLcSormNU/S220/America.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1555473146551121810.post-4917802507585384812</id><published>2007-05-05T23:16:00.002+02:00</published><updated>2009-05-05T23:44:38.898+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus'/><title type='text'>Virus 1</title><content type='html'>Aqui una entrada de Virus&lt;span id="fullpost"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1555473146551121810-4917802507585384812?l=abssha.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abssha.blogspot.com/feeds/4917802507585384812/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1555473146551121810&amp;postID=4917802507585384812' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/4917802507585384812'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1555473146551121810/posts/default/4917802507585384812'/><link rel='alternate' type='text/html' href='http://abssha.blogspot.com/2009/05/virus-1.html' title='Virus 1'/><author><name>Amerikano</name><uri>http://www.blogger.com/profile/12633023812736391713</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://1.bp.blogspot.com/_UUAPhcG-yh0/SUkdd9-SAGI/AAAAAAAAAA4/2bBLcSormNU/S220/America.jpg'/></author><thr:total>0</thr:total></entry></feed>
