°Ô½ÃÆÇȨ / ³«¼­Àå / RootkitRevealer »ç¿ë±â»õ±Û¾²±â ´ä±Û¾²±â

ÀúÀÚ RootkitRevealer »ç¿ë±â
Anonymous (0)
ºñȸ¿ø
  °Ô½ÃÀÏ: 2007-01-16 23:51||
RootkitRevealer¸¦ ¹Ù·Î ¹Þ¾Æ¼­ »ç¿ëÇغýÀ´Ï´Ù.
È£±â½ÉÀÌ »ý±â¸é ÇÒ Àϵµ ¹Ì·ç°í Çغ¸°í ¸¶´Â ½À¼º¶§¹®¿¡...^^

µÎ °¡Áö¸¦ ½ºÄµÇÏ´Â °Å °°½À´Ï´Ù.

¿ì¼± ·¹Áö½ºÆ®¸® ÇÏÀ̺ê(raw hive data)¸¦ ÅëÇØ,
1. Key name¿¡ ºñÁ¤»óÀûÀÎ ¹®ÀÚ(null µî)°¡ Æ÷ÇԵǾîÀÖ´ÂÁö °Ë»ç
2. Windows API¿¡ ÀÖ´Â ³»¿ë°ú ºñ±³
3. Á¢±ÙÀÌ ±ÝÁöµÈ ·¹Áö½ºÆ®¸® °Ë»ö
ÇÏ°í,

fileÀ» ´ë»óÀ¸·Î,
1. Windows API¸¦ ÅëÇØ Á¢±ÙÀÌ ºÒ°¡´ÉÇÑ file °Ë»ö
2. API¸¦ ÅëÇؼ­´Â Á¢±Ù °¡´ÉÇÏÁö¸¸ MFT³ª directory index¿¡¼­´Â Á¢±ÙÀÌ ºÒ°¡´ÉÇÑ file °Ë»ö
ÇÑ´Ù´Â °Í Á¤µµ...

ÇÁ·Î±×·¥ÀÇ ¼Ò°³¿¡µµ ³ª¿ÍÀÖÁö¸¸, °Ë»ö°á°ú´Â Á¦°øÇÏÁö¸¸ ÆÇ´ÜÀº "»ç¿ëÀÚ°¡ ¾Ë¾Æ¼­..."¶ó´Â °á·ÐÀ̱º¿ä.
ÀÌ ÇÁ·Î±×·¥ÀÇ Èñ¾ÈÇÑ Æ¯Â¡ ÇÑ °¡Áö...
½ºÄµ °á°ú¸¦ "³» ¹®¼­"¿¡ ÀúÀåÇϸé "c:\Documents and Settings\LocalService\My Documents"¿¡ ÀúÀåÇÕ´Ï´Ù.

¾î¶µç, ù ½ºÄµÀ» ½ÇÇàÇÑ °á°úÀÔ´Ï´Ù.

----
Path Timestamp Size Description
----
HKLM\SECURITY\Policy\Secrets\SAC* 2005-12-14 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 2005-12-14 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\Installer\Products\32418F9EE1126B64A90E8365B85CFCF6\ProductName
2006-11-02 58 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}\DisplayName 2006-11-02 58 bytes Data mismatch between Windows API and raw hive data.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg 2006-11-02 0 bytes Access is denied.
HKLM\SYSTEM\ControlSet001\Services\vax347s\Config\jdgg40 2006-11-07 0 bytes Hidden from Windows API.
...ÀÌÇÏ»ý·«...
----------
*»ý·«µÈ ºÎºÐÀº cookie ¹× internet Àӽà folder¿¡ »ý±â´Â fileµéÀÔ´Ï´Ù.

³ª¸§´ë·Î ºÐ¼®À» Çغôµ¥,
¼¼¹ø°¿Í ³×¹ø°ÀÇ key´Â Á¤Ã¼¸¦ ¹àÇô³Â½À´Ï´Ù.

32418F9EE1126B64A90E8365B85CFCF6 Alcohol 120% (Trial Version)ÀÇ Product À̸§
E9F81423-211E-46B6-9AE0-38568BC5CF6F Alcohol 120% (Trial Version)ÀÇ Path À̸§

±×·±µ¥ ³ª¸ÓÁö´Â Á¤»óÀûÀÎ »óÅ¿¡¼­µµ º¸ÀÌ´Â keyÀÎÁö È®½ÅÀ» ¸øÇÏ°Ú´õ±º¿ä.
1. "HKLM\SECURITY"´Â regedit·Î´Â º¼ ¼ö ¾ø´Â ³»¿ëÀÌ°í,
2. sptd´Â sptd.sys¸¦ ÀǹÌÇÏ°í vax347s´Â vax347s.sys¸¦ ÀǹÌÇÕ´Ï´Ù.
fileÀ» ã¾Æ¼­ ºÐ¼®ÇÑ °á°ú,
sptd.sts -> Verisign Time Stamping Service driver
vax347s.sys -> SCSI miniport driver
¶ó´Â °á·Ð!!!
µû¶ó¼­, Á¦ ÄÄÀº º° ÀÌ»óÀÌ ¾ø°í, ù µÎ °³ÀÇ key(SAC* and SAI*)¸¸ ¹®Á¦µÈ´Ù´Â°Çµ¥,
ÀÌ µÎ keyµµ Á¤»óÀûÀÎ key·Î ÃßûÇÏ°í ±×³É »ç¿ëÇÔÀ¸·Î °áÁ¤! ¤»¤»¤»

[ ¸Þ½ÃÁö¼öÁ¤: ymister ÀϽÃ: 2007-01-16 23:53 ]
Anonymous (0)
ºñȸ¿ø
  °Ô½ÃÀÏ: 2007-01-17 00:20||
Àοë
µû¶ó¼­, Á¦ ÄÄÀº º° ÀÌ»óÀÌ ¾ø°í, ù µÎ °³ÀÇ key(SAC* and SAI*)¸¸ ¹®Á¦µÈ´Ù´Â°Çµ¥,
ÀÌ µÎ keyµµ Á¤»óÀûÀÎ key·Î ÃßûÇÏ°í ±×³É »ç¿ëÇÔÀ¸·Î °áÁ¤! ¤»¤»¤»


Á¦ ÄÄ¿¡¼­µµ ¹ß°ßÇß½À´Ï´Ù.

¼­ÇÎÇÏ´Ùº¸´Ï °ü·Ã ³»¿ëµéÀÌ ¸¹ÀÌ ÀÖ´õ±º¿ä..
±×·¯³ª º° ¹®Á¦´Â ¾øÀ» °Í °°±âµµ ÇÕ´Ï´Ù. ¤¾

http://forum.sysinternals.com/forum_posts.asp?TID=8881&PN=1

[ ¸Þ½ÃÁö¼öÁ¤: axine ÀϽÃ: 2007-01-17 00:21 ]
Anonymous (0)
ºñȸ¿ø
  °Ô½ÃÀÏ: 2007-01-17 01:31||


ÀÌ·¸°Ô ³ª¿À´Âµ¥ ¹«½¼ ÀǹÌÀÎÁö ¾Ë ¼ö´Â ¾ø´Ù´Â...

°Ë»öÀ» Çغ¸´Ï ´Ù¸¥ À̵鵵 Àú¿Í µ¿ÀÏÇÏ°Ô ³ª¿À´Â °ÍÀ¸·Î ºÁ¼­ ½Å°æ ¾È ½áµµ µÉ °Í °°³×¿ä.
Anonymous (0)
ºñȸ¿ø
  °Ô½ÃÀÏ: 2007-01-17 16:41||
sysinternal ¿¡¼­ ´Ù¿î¹Þ¾Æ ÀüºÎÅÍ »ç¿ëÇØ ºÃ½À´Ï´Ù
½ÇÇà½ÃÅ°¸é Ä«½ºÆÛ½ºÅ° ¹é½ÅÀÌ ²Ð²Ð°Å¸³´Ï´Ù
ÀÚ½Ä~º°°Íµµ ¾Æ´Ñ°Å °¡Áö°í ³î¶ó±â´Â...action-deny½ÃÅ°°í
½ÇÇàÇϴµ¥ Àü ²À 3°³¸¸ °ËÃâÀÌ µÇ´øµ¥¿ä?

HKLM\SECURITY\Policy\Secrets\SAC*
HKLM\SECURITY\Policy\Secrets\SAI*
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP6\PdmHist\xxxxxxx.

±Ùµ¥ regedit·Î µé¾î°¡º¸¸é ±×·± registry°¡ ¾ø´õ¶ó±¸¿ä?
Àü¿¡´Â ¹«Áö ¸¹ÀÌ °ËÃ⠵Ǿù½À´Ï´Ù
찿Àº °Ç ´Ù »èÁ¦ Çعö¸®±¸¿ä.

sysinternal¿¡¼­ ¶Ç dllarchive¶ó°í »ç¿ëÇØ ºÃ´Âµ¥
¹¹ »ç¿ë¾Ê´Â dllÆÄÀÏ Á¤¸®ÇØ Áشٰí Çؼ­ »ç¿ëÇØ ºÃ½À´Ï´Ù
Á÷Àå ÄÄÅÍ´Â ÀÌ»ó ¾ø´Âµ¥ Áý ÄÄÅÍ´Â ½ÃÀÛ°ú Á¾·áÈ­¸éÀÌ ÀÌ»óÇÏ°Ô ¹Ù²î¾î ¹ö·Á¼­
Æ÷¸ËÇß´ø ±â¾ïÀÌ ÀÖ½À´Ï´Ù,
ÀÌ°Ç Á¶½ÉÇؼ­ »ç¿ëÇϼ¼¿ä.ÄÄÅ͸¶´Ù Á¶±Ý¾¿ Ʋ¸°°Å °°¾Æ¿ä
(¹°·Ð ¹é¾÷ÇسõÀº°É·Î ´Ù½Ã dllÀçÀÚ¸®¿¡ µ¹·Á ³õÀ¸¸é µÇÁö¸¸
±ò²ûÇÑ°É ÁÁ¾ÆÇؼ­ ¹é¾÷ÇÑ°É ´Ù »èÁ¦ÇØ ¹ö·Á¼­,,,,¤Ì¤Ì)
´ÙÀ½±Û: °áÈ¥ ÇÕ´Ï´Ù. (4)9529moonloveyou2019-11-06
ÀÌÀü±Û: adlogger°¡ ¾ÈµÇ¿ä~ (0)3697hacom14242006-10-24

»õ±Û¾²±â ´ä±Û¾²±â
À̵¿:

¼¼»ó»ç´Â À̾߱â



RSS ±¸µ¶ (À͸í | ȸ¿ø | °­Á | Æ÷·³)
(C) 1996 ~ 2017 QAOS.com All rights reserved.