VX Underground

21 Ways To Reset A Register

Here are all kinds of ways to reset the registers - from simple to the most sophisticated, but that's what's not there - so it is a complete perversion, such as zeroing one by one bit, auto generated code, etc

PDF Read more

Hooking WinNT/2K/XP API

Our task is to hook some API functions in all existing processes, and in all new processes which may be created, under NT/2K/XP operating systems. Patching existing processes can be done by means of the following:

PDF Read more

21 Ways To Reset A Register

Here are all kinds of ways to reset the registers - from simple to the most sophisticated, but that's what's not there - so it is a complete perversion, such as zeroing one by one bit, auto generated code, etc

PDF Read more

Hooking WinNT/2K/XP API

Our task is to hook some API functions in all existing processes, and in all new processes which may be created, under NT/2K/XP operating systems. Patching existing processes can be done by means of the following:

PDF Read more
z0mbie/29a 21 Ways To Reset A Register
Hooking WinNT/2K/XP API
Code Transformation and Finite Automatons
Automated Reverse Engineering: Mistfall Engine
Disassemblers Within Viruses
DELAYED CODE
VIRUS ENGINES: COMMON RECOMMENDATIONS
Executable Trash Generator (ETG Engine)
HOW TO CREATE YOUR OWN RSA KEY
I.Danilov vs V.Bogdanov (Dr.Web vs AVP): Programmer's Competition [EN]
Injected Evil: (executable files infection) [TEXT FORMAT]
KME-32: Kewl Mutation Engine User's Manual [EN]
LDE32: Length-Disassembler Engine User's Manual [EN]
ADDING LDT ENTRIES IN WIN2K
libtcc can be useful to use tcc as a "backend" for a code generator
SOME IDEAS ABOUT METAMORPHISM
METAMORPHISM AND PERMUTATION: FEEL THE DIFFERENCE
Description of the Win9X INT 2E services (VMM/NTKERN.VxD) [EN]
Opcode Frequency Statistics
TRAITOR OUTLOOK
WRITING INTO KERNEL FROM RING-3: LETS FUCK PAGETABLE [EN]
Permutation conditions
Polymorphic Games
PRCG: Polymorphic Recursive Cycle Generator
PERVERT WORLD WIDE
ABOUT REVERSING
LIMITING DATA TRANSFER SPEED
TCP switch
TRACING UNDER WIN32
ABOUT UNDETECTABLE VIRUSES
DATA ENCODING IN META VIRUSES
VMware has you