PDA

:



pca
15.10.2007, 22:49
100% .

Agnitum Outpost Security Suite Pro 2007(5.0.1252.7915.619).

(n/a).
.. , . .
. - , , . (: n/a: Opera DNS UDP connection Download Master DNS UDP connection).
TCP,UDP, IPIIP,EGP,SKIP,TMuX, ICMPv6 ( ), ICMP , NetBIOS, IGMP , RAWSOCKET (!) .. SYSTEM.

, dialer ( ), , , Svchost .. .
.

AVZ 4.27, GMER 1.0.13 RootkitUnhooker 3.7.300.509.

1. AVZ ( ) : F7473000. (.. ), , . 98304 .
, . , , . , avz.exe .
2. GMER ( ) : name: (noname) value: ***hidden***
2944 91776 .
:
name: ______ value:
3. RkU unknown module filename SSDT, Shadow SSDT, (Hooked codes).
- ( ). 37 . unknown_irp_handler. 512 4064 .

, , ! :)

PS: , , : .

V_Bond
15.10.2007, 23:11
virusinfo_syscure.zip - ( ) ... 3 ....
...


begin
SearchRootkit(true, true);
SetAVZGuardStatus(true);
QuarantineFile('C:\DOCUME~1\098A~1\LOCALS~1\Temp\R ar$EX00.656\pwl\pwlshell.dll','');
QuarantineFile('\SystemRoot\system32\DRIVERS\sd20_ nt.sys','');
QuarantineFile('C:\WINDOWS\system32\tsseShrd.dll', '');
BC_ImportQuarantineList;
BC_Activate;
RebootWindows(true);
end.

3 ...

PavelA
16.10.2007, 10:16
?dStringFileInfo@040904E4DCompanyNameTeknum Systems AS\FileDescriptionShared Shell Menu Handler4 FileVersion5.4.0.122"InternalNamev)LegalCopyrightCopyright 1994-2001, Teknum Systems AS*LegalTrademarks> OriginalFilenamessmenu.dllTProductNameShared Shell Menu Handler4ProductVersion1.0.0.0VCommentsContext menu handler for Windows Explorer that can be shared by multiply applicationsDVarFileInfo$Translation FE2XES.NET_DLL', Res); end.U16:217,YYPOS1ȬYȬYTroj an.PSW ?YYHYHY<*Y [hIYPYY,P,NYLL
- . .

. , . .

pca
16.10.2007, 17:43
! . - .
3 .

, , AVZ .
Officekey.exe PSWTool.Win32.RAS.a - , .
Klister Backdoor.Win32.BO2K, windows 2000. ( ).
KnownExt .
sskbfd.sys Monitor.Win32.SpySweeper -. .
Interceptor.dll - . .
TsseShrd.dll HandyBitsFil Shredder. . .
sd20_nt.sys - - , , .
DelDrv - 3 .
[ , AVZ .]

. .
DrWeb. NOD32, . 7, . , ,

PS:, , ,

6

, - http://virusinfo.info/upload_virus.php, . . .

PavelA
16.10.2007, 17:51
.
, , .

2

, , . ?

.. . , .

pca
16.10.2007, 22:14
? , . , , ;) .
. , .

. , .. . . ( ) : - . .
3 , , windows, .
, ? ? ?
BSOD (). , Windows 3.1 Linux, ? , , . system32 . ?

anton_dr
16.10.2007, 22:22
, ? . , ?
, , .

pca
16.10.2007, 22:30
? ! . .
"" . , .

anton_dr
16.10.2007, 22:36
.

1

RKU, ?

2

, , , . .

pca
16.10.2007, 23:00
! Kaspersky Internet Security 7.0.0.124. , IGMP , ! Agnitum Outpost - !
, . - - .

8

RkU 3.7.300.509?
-, 10 , 30 - -. . , GMER 1.0.13. Outpost ( ), .

13

. . ....

19.10.2007, 13:11
-...

Muzzle
23.10.2007, 03:24
- :)

[500mhz]
14.11.2007, 12:34
vmode

anton_dr
14.11.2007, 12:43
;150422'] vmode
, :)

[500mhz]
14.11.2007, 12:59
!
!

XP user
14.11.2007, 16:26
;150422'] vmode , . , , , ... http://www.antirootkit.com/blog/category/bios-rootkits/ http://theinvisiblethings.blogspot.com/ Paul

[500mhz]
14.11.2007, 21:13
Paul
,
,