1 17 17.

  1. #1
    Junior Member
    15.10.2007
    5
    61

    100% .

    Agnitum Outpost Security Suite Pro 2007(5.0.1252.7915.619).

    (n/a).
    .. , . .
    . - , , . (: n/a: Opera DNS UDP connection Download Master DNS UDP connection).
    TCP,UDP, IPIIP,EGP,SKIP,TMuX, ICMPv6 ( ), ICMP , NetBIOS, IGMP , RAWSOCKET (!) .. SYSTEM.

    , dialer ( ), , , Svchost .. .
    .

    AVZ 4.27, GMER 1.0.13 RootkitUnhooker 3.7.300.509.

    1. AVZ ( ) : F7473000. (.. ), , . 98304 .
    , . , , . , avz.exe .
    2. GMER ( ) : name: (noname) value: ***hidden***
    2944 91776 .
    :
    name: ______ value:
    3. RkU unknown module filename SSDT, Shadow SSDT, (Hooked codes).
    - ( ). 37 . unknown_irp_handler. 512 4064 .

    , , !

    PS: , , : .
    drongo; 15.10.2007 23:33.

  2. !
      VirusInfo

    ? , Anti-Malware.ru:

    Anti-Malware Telegram
     

  3. #2
    Senior Helper
    10.01.2007
    22,817
    1524
    virusinfo_syscure.zip - ( ) ... 3 ....
    ...
    :
    begin
     SearchRootkit(true, true);
     SetAVZGuardStatus(true);
    QuarantineFile('C:\DOCUME~1\098A~1\LOCALS~1\Temp\Rar$EX00.656\pwl\pwlshell.dll','');
    QuarantineFile('\SystemRoot\system32\DRIVERS\sd20_nt.sys','');
    QuarantineFile('C:\WINDOWS\system32\tsseShrd.dll','');     
     BC_ImportQuarantineList;
     BC_Activate;
     RebootWindows(true);
    end.
    3 ...

  4. #3
    VIP
    07.07.2005
    Moscow region
    30,462
    2522
    ?dStringFileInfo@040904E4DCompanyNameTeknum Systems AS\FileDescriptionShared Shell Menu Handler4 FileVersion5.4.0.122"InternalNamev)LegalCopyri ghtCopyright 1994-2001, Teknum Systems AS*LegalTrademarks> OriginalFilenamessmenu.dllTProductNameShared Shell Menu Handler4ProductVersion1.0.0.0VCommentsContext menu handler for Windows Explorer that can be shared by multiply applicationsDVarFileInfo$Translation FE2XES.NET_DLL', Res); end.U16:217,YYPOS1ȬYȬYTroj an.PSW ?YYHYHY<*Y [hIYPYY,P,NYLL
    - . .

    . , . .

    AVZ HijackThis 10-00 18-00

    Windows7, SEP(work)
    WindowsXP KIS(home)

    up

  5. #4
    Junior Member
    15.10.2007
    5
    61

    ()

    ! . - .
    3 .

    , , AVZ .
    Officekey.exe PSWTool.Win32.RAS.a - , .
    Klister Backdoor.Win32.BO2K, windows 2000. ( ).
    KnownExt .
    sskbfd.sys Monitor.Win32.SpySweeper -. .
    Interceptor.dll - . .
    TsseShrd.dll HandyBitsFil Shredder. . .
    sd20_nt.sys - - , , .
    DelDrv - 3 .
    [ , AVZ .]

    . .
    DrWeb. NOD32, . 7, . , ,

    PS:, , ,

    6

    , - http://virusinfo.info/upload_virus.php, . . .
    pca; 16.10.2007 17:43. :

  6. #5
    VIP
    07.07.2005
    Moscow region
    30,462
    2522
    .
    , , .

    2

    , , . ?

    .. . , .
    PavelA; 16.10.2007 17:51. :

    AVZ HijackThis 10-00 18-00

    Windows7, SEP(work)
    WindowsXP KIS(home)

    up

  7. #6
    Junior Member
    15.10.2007
    5
    61
    ? , . , , .
    . , .

    . , .. . . ( ) : - . .
    3 , , windows, .
    , ? ? ?
    BSOD (). , Windows 3.1 Linux, ? , , . system32 . ?

  8. #7
    Senior Member
    21.04.2005
    Perm, Russia
    5,794
    2292
    , ? . , ?
    , , .

  9. #8
    Junior Member
    15.10.2007
    5
    61
    ? ! . .
    "" . , .

  10. #9
    Senior Member
    21.04.2005
    Perm, Russia
    5,794
    2292
    .

    1

    RKU, ?

    2

    , , , . .
    anton_dr; 16.10.2007 22:36. :

  11. #10
    Junior Member
    15.10.2007
    5
    61
    ! Kaspersky Internet Security 7.0.0.124. , IGMP , ! Agnitum Outpost - !
    , . - - .

    8

    RkU 3.7.300.509?
    -, 10 , 30 - -. . , GMER 1.0.13. Outpost ( ), .

    13

    . . ....
    pca; 16.10.2007 23:00. :

  12. #11
    Senior Member
    08.05.2006
    399
    155
    -...

  13. #12
    Senior Member   Muzzle
    07.02.2007
    1,068
    89
    -

  14. #13
    Full Member   [500mhz]
    05.11.2007
    290
    143
    vmode

  15. #14
    Senior Member
    21.04.2005
    Perm, Russia
    5,794
    2292
    [500mhz]
    vmode
    ,

  16. #15
    Full Member   [500mhz]
    05.11.2007
    290
    143
    !
    !

  17. #16

  18. #17
    Full Member   [500mhz]
    05.11.2007
    290
    143
    Paul
    ,
    ,

  1. ?
    ne_kodim !
    : 3
    : 16.06.2011, 11:45
  2. IBM
    ALEX(XX)
    : 1
    : 11.06.2008, 01:56
  3. NOD32:
    SDA
    : 1
    : 24.12.2006, 21:04

/

  •  
Page generated in 0.00634 seconds with 20 queries