Most of these skiddies get ahold of FUD malware nowadays no thanks to sites like hackhound, unkn0wn, etc.
@Dj, fuck, you should sniff anything that looks slightly suspicious, most of these kiddie coders add what they call "anti-sniffer" code that only actually kill wireshark if it's run, so if...