:
100% .
Agnitum Outpost Security Suite Pro 2007(5.0.1252.7915.619).
(n/a).
.. , . .
. - , , . (: n/a: Opera DNS UDP connection Download Master DNS UDP connection).
TCP,UDP, IPIIP,EGP,SKIP,TMuX, ICMPv6 ( ), ICMP , NetBIOS, IGMP , RAWSOCKET (!) .. SYSTEM.
, dialer ( ), , , Svchost .. .
.
AVZ 4.27, GMER 1.0.13 RootkitUnhooker 3.7.300.509.
1. AVZ ( ) : F7473000. (.. ), , . 98304 .
, . , , . , avz.exe .
2. GMER ( ) : name: (noname) value: ***hidden***
2944 91776 .
:
name: ______ value:
3. RkU unknown module filename SSDT, Shadow SSDT, (Hooked codes).
- ( ). 37 . unknown_irp_handler. 512 4064 .
, , ! :)
PS: , , : .
virusinfo_syscure.zip - ( ) ... 3 ....
...
begin
SearchRootkit(true, true);
SetAVZGuardStatus(true);
QuarantineFile('C:\DOCUME~1\098A~1\LOCALS~1\Temp\R ar$EX00.656\pwl\pwlshell.dll','');
QuarantineFile('\SystemRoot\system32\DRIVERS\sd20_ nt.sys','');
QuarantineFile('C:\WINDOWS\system32\tsseShrd.dll', '');
BC_ImportQuarantineList;
BC_Activate;
RebootWindows(true);
end.
3 ...
?dStringFileInfo@040904E4DCompanyNameTeknum Systems AS\FileDescriptionShared Shell Menu Handler4 FileVersion5.4.0.122"InternalNamev)LegalCopyrightCopyright 1994-2001, Teknum Systems AS*LegalTrademarks> OriginalFilenamessmenu.dllTProductNameShared Shell Menu Handler4ProductVersion1.0.0.0VCommentsContext menu handler for Windows Explorer that can be shared by multiply applicationsDVarFileInfo$Translation FE2XES.NET_DLL', Res); end.U16:217,YYPOS1ȬYȬYTroj an.PSW ?YYHYHY<*Y [hIYPYY,P,NYLL
- . .
. , . .
! . - .
3 .
, , AVZ .
Officekey.exe PSWTool.Win32.RAS.a - , .
Klister Backdoor.Win32.BO2K, windows 2000. ( ).
KnownExt .
sskbfd.sys Monitor.Win32.SpySweeper -. .
Interceptor.dll - . .
TsseShrd.dll HandyBitsFil Shredder. . .
sd20_nt.sys - - , , .
DelDrv - 3 .
[ , AVZ .]
. .
DrWeb. NOD32, . 7, . , ,
PS:, , ,
6
, - http://virusinfo.info/upload_virus.php, . . .
.
, , .
2
, , . ?
.. . , .
? , . , , ;) .
. , .
. , .. . . ( ) : - . .
3 , , windows, .
, ? ? ?
BSOD (). , Windows 3.1 Linux, ? , , . system32 . ?
anton_dr
16.10.2007, 22:22
, ? . , ?
, , .
anton_dr
16.10.2007, 22:36
.
1
RKU, ?
2
, , , . .
! Kaspersky Internet Security 7.0.0.124. , IGMP , ! Agnitum Outpost - !
, . - - .
8
RkU 3.7.300.509?
-, 10 , 30 - -. . , GMER 1.0.13. Outpost ( ), .
13
. . ....
[500mhz]
14.11.2007, 12:34
vmode
anton_dr
14.11.2007, 12:43
;150422'] vmode
, :)
[500mhz]
14.11.2007, 12:59
!
!
;150422'] vmode , . , , , ... http://www.antirootkit.com/blog/category/bios-rootkits/ http://theinvisiblethings.blogspot.com/ Paul
[500mhz]
14.11.2007, 21:13
Paul
,
,
vBulletin® v4.2.5, Copyright ©2000-2023, Jelsoft Enterprises Ltd. : zCarot