ÀúÀÚ |
RootkitRevealer »ç¿ë±â |
Anonymous (0) ºñȸ¿ø
| °Ô½ÃÀÏ: 2007-01-16 23:51|| RootkitRevealer¸¦ ¹Ù·Î ¹Þ¾Æ¼ »ç¿ëÇغýÀ´Ï´Ù.
È£±â½ÉÀÌ »ý±â¸é ÇÒ Àϵµ ¹Ì·ç°í Çغ¸°í ¸¶´Â ½À¼º¶§¹®¿¡...^^
µÎ °¡Áö¸¦ ½ºÄµÇÏ´Â °Å °°½À´Ï´Ù.
¿ì¼± ·¹Áö½ºÆ®¸® ÇÏÀ̺ê(raw hive data)¸¦ ÅëÇØ,
1. Key name¿¡ ºñÁ¤»óÀûÀÎ ¹®ÀÚ(null µî)°¡ Æ÷ÇԵǾîÀÖ´ÂÁö °Ë»ç
2. Windows API¿¡ ÀÖ´Â ³»¿ë°ú ºñ±³
3. Á¢±ÙÀÌ ±ÝÁöµÈ ·¹Áö½ºÆ®¸® °Ë»ö
ÇÏ°í,
fileÀ» ´ë»óÀ¸·Î,
1. Windows API¸¦ ÅëÇØ Á¢±ÙÀÌ ºÒ°¡´ÉÇÑ file °Ë»ö
2. API¸¦ ÅëÇؼ´Â Á¢±Ù °¡´ÉÇÏÁö¸¸ MFT³ª directory index¿¡¼´Â Á¢±ÙÀÌ ºÒ°¡´ÉÇÑ file °Ë»ö
ÇÑ´Ù´Â °Í Á¤µµ...
ÇÁ·Î±×·¥ÀÇ ¼Ò°³¿¡µµ ³ª¿ÍÀÖÁö¸¸, °Ë»ö°á°ú´Â Á¦°øÇÏÁö¸¸ ÆÇ´ÜÀº "»ç¿ëÀÚ°¡ ¾Ë¾Æ¼..."¶ó´Â °á·ÐÀ̱º¿ä.
ÀÌ ÇÁ·Î±×·¥ÀÇ Èñ¾ÈÇÑ Æ¯Â¡ ÇÑ °¡Áö...
½ºÄµ °á°ú¸¦ "³» ¹®¼"¿¡ ÀúÀåÇϸé "c:\Documents and Settings\LocalService\My Documents"¿¡ ÀúÀåÇÕ´Ï´Ù.
¾î¶µç, ù ½ºÄµÀ» ½ÇÇàÇÑ °á°úÀÔ´Ï´Ù.
----
Path Timestamp Size Description
----
HKLM\SECURITY\Policy\Secrets\SAC* 2005-12-14 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 2005-12-14 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\Installer\Products\32418F9EE1126B64A90E8365B85CFCF6\ProductName
2006-11-02 58 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}\DisplayName 2006-11-02 58 bytes Data mismatch between Windows API and raw hive data.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg 2006-11-02 0 bytes Access is denied.
HKLM\SYSTEM\ControlSet001\Services\vax347s\Config\jdgg40 2006-11-07 0 bytes Hidden from Windows API.
...ÀÌÇÏ»ý·«...
----------
*»ý·«µÈ ºÎºÐÀº cookie ¹× internet Àӽà folder¿¡ »ý±â´Â fileµéÀÔ´Ï´Ù.
³ª¸§´ë·Î ºÐ¼®À» Çغôµ¥,
¼¼¹ø°¿Í ³×¹ø°ÀÇ key´Â Á¤Ã¼¸¦ ¹àÇô³Â½À´Ï´Ù.
32418F9EE1126B64A90E8365B85CFCF6 Alcohol 120% (Trial Version)ÀÇ Product À̸§
E9F81423-211E-46B6-9AE0-38568BC5CF6F Alcohol 120% (Trial Version)ÀÇ Path À̸§
±×·±µ¥ ³ª¸ÓÁö´Â Á¤»óÀûÀÎ »óÅ¿¡¼µµ º¸ÀÌ´Â keyÀÎÁö È®½ÅÀ» ¸øÇÏ°Ú´õ±º¿ä.
1. "HKLM\SECURITY"´Â regedit·Î´Â º¼ ¼ö ¾ø´Â ³»¿ëÀÌ°í,
2. sptd´Â sptd.sys¸¦ ÀǹÌÇÏ°í vax347s´Â vax347s.sys¸¦ ÀǹÌÇÕ´Ï´Ù.
fileÀ» ã¾Æ¼ ºÐ¼®ÇÑ °á°ú,
sptd.sts -> Verisign Time Stamping Service driver
vax347s.sys -> SCSI miniport driver
¶ó´Â °á·Ð!!!
µû¶ó¼, Á¦ ÄÄÀº º° ÀÌ»óÀÌ ¾ø°í, ù µÎ °³ÀÇ key(SAC* and SAI*)¸¸ ¹®Á¦µÈ´Ù´Â°Çµ¥,
ÀÌ µÎ keyµµ Á¤»óÀûÀÎ key·Î ÃßûÇÏ°í ±×³É »ç¿ëÇÔÀ¸·Î °áÁ¤! ¤»¤»¤»
[ ¸Þ½ÃÁö¼öÁ¤: ymister ÀϽÃ: 2007-01-16 23:53 ] |
|
Anonymous (0) ºñȸ¿ø
| °Ô½ÃÀÏ: 2007-01-17 00:20||
ÀÎ¿ë µû¶ó¼, Á¦ ÄÄÀº º° ÀÌ»óÀÌ ¾ø°í, ù µÎ °³ÀÇ key(SAC* and SAI*)¸¸ ¹®Á¦µÈ´Ù´Â°Çµ¥,
ÀÌ µÎ keyµµ Á¤»óÀûÀÎ key·Î ÃßûÇÏ°í ±×³É »ç¿ëÇÔÀ¸·Î °áÁ¤! ¤»¤»¤»
Á¦ ÄÄ¿¡¼µµ ¹ß°ßÇß½À´Ï´Ù.
¼ÇÎÇÏ´Ùº¸´Ï °ü·Ã ³»¿ëµéÀÌ ¸¹ÀÌ ÀÖ´õ±º¿ä..
±×·¯³ª º° ¹®Á¦´Â ¾øÀ» °Í °°±âµµ ÇÕ´Ï´Ù. ¤¾
http://forum.sysinternals.com/forum_posts.asp?TID=8881&PN=1
[ ¸Þ½ÃÁö¼öÁ¤: axine ÀϽÃ: 2007-01-17 00:21 ] |
Anonymous (0) ºñȸ¿ø
| °Ô½ÃÀÏ: 2007-01-17 01:31||
ÀÌ·¸°Ô ³ª¿À´Âµ¥ ¹«½¼ ÀǹÌÀÎÁö ¾Ë ¼ö´Â ¾ø´Ù´Â...
°Ë»öÀ» Çغ¸´Ï ´Ù¸¥ À̵鵵 Àú¿Í µ¿ÀÏÇÏ°Ô ³ª¿À´Â °ÍÀ¸·Î ºÁ¼ ½Å°æ ¾È ½áµµ µÉ °Í °°³×¿ä. |
Anonymous (0) ºñȸ¿ø
| °Ô½ÃÀÏ: 2007-01-17 16:41|| sysinternal ¿¡¼ ´Ù¿î¹Þ¾Æ ÀüºÎÅÍ »ç¿ëÇØ ºÃ½À´Ï´Ù
½ÇÇà½ÃÅ°¸é Ä«½ºÆÛ½ºÅ° ¹é½ÅÀÌ ²Ð²Ð°Å¸³´Ï´Ù
ÀÚ½Ä~º°°Íµµ ¾Æ´Ñ°Å °¡Áö°í ³î¶ó±â´Â...action-deny½ÃÅ°°í
½ÇÇàÇϴµ¥ Àü ²À 3°³¸¸ °ËÃâÀÌ µÇ´øµ¥¿ä?
HKLM\SECURITY\Policy\Secrets\SAC*
HKLM\SECURITY\Policy\Secrets\SAI*
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP6\PdmHist\xxxxxxx.
±Ùµ¥ regedit·Î µé¾î°¡º¸¸é ±×·± registry°¡ ¾ø´õ¶ó±¸¿ä?
Àü¿¡´Â ¹«Áö ¸¹ÀÌ °ËÃ⠵Ǿù½À´Ï´Ù
찿Àº °Ç ´Ù »èÁ¦ Çعö¸®±¸¿ä.
sysinternal¿¡¼ ¶Ç dllarchive¶ó°í »ç¿ëÇØ ºÃ´Âµ¥
¹¹ »ç¿ë¾Ê´Â dllÆÄÀÏ Á¤¸®ÇØ Áشٰí Çؼ »ç¿ëÇØ ºÃ½À´Ï´Ù
Á÷Àå ÄÄÅÍ´Â ÀÌ»ó ¾ø´Âµ¥ Áý ÄÄÅÍ´Â ½ÃÀÛ°ú Á¾·áȸéÀÌ ÀÌ»óÇÏ°Ô ¹Ù²î¾î ¹ö·Á¼
Æ÷¸ËÇß´ø ±â¾ïÀÌ ÀÖ½À´Ï´Ù,
ÀÌ°Ç Á¶½ÉÇؼ »ç¿ëÇϼ¼¿ä.ÄÄÅ͸¶´Ù Á¶±Ý¾¿ Ʋ¸°°Å °°¾Æ¿ä
(¹°·Ð ¹é¾÷ÇسõÀº°É·Î ´Ù½Ã dllÀçÀÚ¸®¿¡ µ¹·Á ³õÀ¸¸é µÇÁö¸¸
±ò²ûÇÑ°É ÁÁ¾ÆÇؼ ¹é¾÷ÇÑ°É ´Ù »èÁ¦ÇØ ¹ö·Á¼,,,,¤Ì¤Ì) |
|
| |