-

  • (45)
  • / (26)
  • (13)
  • (9)
  • (9)

 - e-mail

 

 -

   _

 -

 LiveInternet.ru:
: 28.02.2006
: 182
: 1228
: 1017

:

.


: (9), (45), (9), / (26)
(4)

SMS- , . NOD !!!

, 06 2009 . 15:39 +
Alfizik (_) . SMS- , Windows. ! SMS, 300 .
 (653x551, 89Kb)
, )))

, , , ( ), . Win+L, . , . ))

:
1. C:\Documents and Settings\\Local Settings\Temp\922.exe
2. C:\Documents and Settings\\Local Settings\Temporary Internet Files\Content.IE5\HO9NMBT5\aa[1].exe
3. C:\WINDOWS\mfo.exe
44544 MD5 : E7A247CE628D8F455D5E895DBEF71976

:
AntiVir - TR/LockScreen.E.1
Avast - Win32:Malware-gen
AVG - SHeur2.BPQG
Comodo - Heur.Suspicious
DrWeb - Trojan.Winlock.428
Kaspersky - Trojan-Ransom.Win32.SMSer.rk
Panda - Trj/CI.A
Symantec - Trojan.Ransomlock.C
NOD !!! , !


.
LiveCD . LiveCD USB- ( Alkid Live CD iNFR@ CD). portable Dr.Web - Dr.Web CureIt!, . - http://www.freedrweb.com/cureit/
AVZ ( ), . . - http://www.z-oleg.com/secur/avz/download.php

AVZ ( )

( ).
: 13616. . , . ( ---> - , Regedit) :

HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Internet Explorer \ Desktop \ SafeMode
HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Control \ SafeBoot
HKEY_LOCAL_MACHINE \ System \ ControlSet003 \ Control \ SafeBoot
HKEY_LOCAL_MACHINE \ System \ CurrentControlSet \ Control \ SafeBoot

1 ( ). , , Windows, F8. - " ". .


/

:  
(8)

, 26 2009 . 17:18 +
Alfizik (_) , , . .

, , , , .

1. (Ctrl+Alt+Delete)
 (314x126, 26Kb)
Windows :
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] REG_DWORD DisableTaskMgr 1.

.

* > > : regedit > OK > .

2.
 (405x126, 30Kb)
? ))
Windows :
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] REG_DWORD DisableRegistryTools 1.

.

3. , (explorer-).
, , , ! , , , . Windows ))
explorer Windows :
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe]
Debugger %Windir%\csrss.exe

.

P.S.



))

, .

, > > : gpedit.msc > OK > > > > > > ( ) : > > ( ) > >OK.

. ( , Windows+D), F5 ( , ).

Windows, (,RegOrganazer), [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] REG_DWORD DisableRegistryTools.

explorer, , . , autorun TotalComander ( explorer ) Windows ( Totala regedit), , RegOrganazer Debugger [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe]

:)


/

(0)

QIP ver.8094 Win32/Induc.A

, 19 2009 . 13:29 +
Alfizik (_) Win32/Induc.A ( CodeGear Delphi) Delphi, : QIP, AIMP ( Skype, Total Commander, ).

, Delphi , , SysConst.dcu ( SysConst.bak), Delphi, , Delphi , .


Virus.Win32.Induc.a , Delphi. , .dcu-, Windows .

, Delphi 4.0-7.0. , Virus.Win32.Induc.a Delphi Sysconst.pas , Sysconst.dcu.

Delphi "use SysConst", . , Sysconst.dcu, , , . pas- .

, 8094 QIP ( QIP ). , - Runtime error 3, HKEY_LOCAL_MACHINE\SOFTWARE\Borland\Delphi\x.0 (x 4 7) RootDir ( ).


, . , .
QIP , 8095, :)

(!) ( IE8) ;)

, - QIP, .dcu- Virus.Win32.Induc.a .


Delphi , SysConst.bak, :
1. SysConst.dcu
2. SysConst.bak SysConst.dcu. , , SysConst.bak .

, . Win32/Induc.A : Avast, Kaspersky, NOD32.

/

(5)

Win32.Ntldrbot (aka Rustock.C) , !

, 16 2008 . 10:38 +
Alfizik (_) Rootkit (, . root kit ) , , , .



, . , . , , , . .



, , , . Wikipedia, - (. botnet) , , . , . , , , .

SecureWorks -, . , Rustock, . :
: 150, 000;
: 30 ;
-: .


.

Rustock
Rustock Symantec, , . : Z:\NewProjects\spambot\last\driver\objfre\i386\driver.pdb. spambot Rustock rootkit v 1.2.

(A, B, C). , , , . .

2005 2006 - Rustock.A . : i386.sys, sysbus32. (SSDT) IRP-.

Rustock.A pe386.sys ( 1.0), . , SSDT 0x2E (Windows 2000) MSR_SYSENTER(Windows XP+). ADS (Alternate Data Stream). NTFS. %SystemRoot%\system32:[__].

2006 - Rustock.B (huy32.sys), Rustock.B - lzx32.sys ( 1.2), INT2E/MSR_SYSENTER, ADS (%Windir%\System32:lzx32.sys). , : tcpip.sys, wanarp.sys ndis.sys, -.

, , , .

, TrendMicro, Rustock.C, Rustock.B

Rustock.C
Rustock.C 2006 . , . , , , .

, , , . , - . C- : , / , . !, : Rustock.є, - , .

, Rustock.C . , .

 (600x119, 43Kb)

Rustock. , Rustock.C 2008 . , .

600 , . 2007 . , .

, 2007 , . , . , . , , . , Rustock.C , , , ,
- .


, ;
, ;
, ;
: (DR-); : Syser,SoftIce. WinDbg ;
. :
NtCreateThread
NtDelayExecution
NtDuplicateObject
NtOpenThread
NtProtectVirtualMemory
NtQuerySystemInformation
NtReadVirtualMemory
NtResumeThread
NtTerminateProcess
NtTerminateThread
NtWriteVirtualMemory
, ;
. , ;
, . . , , - .
, FSD- ;
;
, Windows. . DLL .


.

, Dr.Web, Rustock.C. , Dr.Web, . , Dr.Web, Dr.Web CureIt! .

, 90- . Rustock: , .


(4)

" "?

, 28 2007 . 23:23 +
StoneCold (_) , .
, "-"
.
Disk Write Copy "", .
- , ?

/

(13)

(

, 23 2007 . 11:31 +
RainWalker (_) : (( , ? ((( - ((( . , , . )))


(37)

, 19 2007 . 13:13 +
Maranii (_) 1. ?
2. , . , ?


/

(13)

?

, 10 2007 . 13:44 +
Bad_Kpoxa (_) ... ???




/

(2)

, 04 2006 . 21:24 +
cHocO_cHoCo (_) "Buka"?


(0)

Virus.1C.Bonny.a

, 02 2006 . 00:14 +
 (_) , "1:7.7" (. " 1C", http://www.1c.ru). "1: 7.7" ( , ".ERT").

-, - 1C. - 1C -, MS Office. -, . , MS Office, -, -, , .

1C ( -), .

( , -).

, 1: , .

-"":

Trivial.1Cv77 by BKNY0NNX
Companion.1Cv77 by BKNY0NNX
( "Bonny" "BKNY0NNX")

1C-Module.Bonny.a
"Overwriting"-, . -.

- "()" , , . 15 , .ERT- ( 1), .

( 1C:).

1C-Module.Bonny.b
-. - "()". .ERT-, .ERT.ERT ( .ERT, , AUDIT.ERT -> AUDIT.ERT.ERT) .

- (.ERT.ERT-).

, , , "BALANS.ERT.ERT.ERT ... .ERT".


(0)

Stoned.a

, 02 2006 . 23:06 +
 (_) . INT 13h : - MBR . (INT 13h, AH=02), - DOS . . , : - MBR , - , . , "Stoned.a" 360K . : - 1/0/3 (//), - 0/0/7. , ( - FAT , - FAT). , :

"Stoned.Angelina": Greetings for ANGELINA !!!/by Garfield/Zielona Gora
"Stoned.Antigame": Antigame from The Rat
"Stoned.Archub": ARC HUB 8A
"Stoned.Arcv.a": [HiDos] By Apache
"Stoned.Arcv.b": [SCYTHE2] by Apache
"Stoned.Arcv.c": [X-3a] ICE-9
"Stoned.Bite": I'm made in B I T E Soft. !
"Stoned.BlackWorm": BLACK WORM
"Stoned.Bunny": BUNNY
"Stoned.Canadian": Canadian
"Stoned.Dallas": Msfl perc mlva DALLAS !
"Stoned.Damcdoom": DAMCDOOM
"Stoned.Daniela": EU TE AMO DANIELA
"Stoned.Diablo": DIABLO
"Stoned.Digital93": ^DIGITAL'93
"Stoned.Intruder": Intruder
"Stoned.J&M": J&M
"Stoned.Jugador": MARADONA
ESTE ES EL VIRUS DEL MEJOR JUGADOR DEL MUNDO
SALUDA A UD. MUY ATTE. DIEGO ARMANDO MARADONA
"Stoned.Kenya": KENYA
"Stoned.Lera": IF YOU WANT TO FUCK CALL 575-52-94 LERA!!!!
"Stoned.Magic": Magic
"Stoned.Micola.a": Mikola
"Stoned.Mikola.b": MIKOLA V15 GHOST
"Stoned.Military": EXPERIMENTAL MILITARY VIRUS Do not distribuite
whitout Pentagon S21 office permission!
"Stoned.Neardark.a": MARIJUANA++
"Stoned.Ok": o.k.
"Stoned.Vaucher": "VAUCHER" BY DARK DOC
"Stoned.Scrlock.a": ScrLock Protection
"Stoned.Scrlock.b": (C)91 Scroll Lock Protects the HDD
"Stoned.Sepultura": -=>SpLr<=-
"Stoned.Service": "Service-1" presents
bootER 1991

made in Russig

"Stoned.Spirit": SPIRIT (c) MW
"Stoned.Survivor": Survivor2
"Stoned.Zoboot": BOOT

Stoned
- 1/8 "Your PC is now Stoned!". , "LEGALISE MARIJUANA!". "Stoned.c" MBR (Disk Partition Table), -. "Stoned.d" 1 .

Stoned.Alive
F0h- (INT 13h) "A AM ALIVE" . - MBR .

Stoned.AntiExe
EXE-, -.

Stoned.Antigame
INT 1, 3 IRET. .

Stoned.Aragon
.

Stoned.Bloody.a,b
: "Bloody! Jun. 4, 1989".

Stoned.Canadian
MBR MBR-.

Stoned.Cancer
: "This computer is dying of cancer!".

Stoned.COMx
25 - COM1 COM2.

Stoned.Copy77
77- "Copy 77 in job ...".

Stoned.Daniela
5 .

Stoned.Dinamo
boot- . , :

Dinamo(Kiev)-champion !!!

Stoned.DiskWasher
:

From DiskWasher with love

Stoned.Donald
:

Donald Duck is a lie!!!

Stoned.Elythnia
1/8 :

Aaronexus of Elythnia!

Stoned.Face
FAT , FACEh.

Stoned.GKCHP
-. : "". 90- .

Stoned.Gozar
11 :

Gozar lives !

Stoned.Hysteria
19 :

Turbo Hysteria

Stoned.IntFF
. INT 21h INT FFh.

Stoned.Intruder
INT 1Ch .

Stoned.Lavot
: "LAVOT NO ENSEA".

Stoned.Lch15
-. : "Lch15", "For pirates". 90- CMOS ( , BIOS'), C:.

Stoned.Leo
2 :

Happy birthday to Leo!

Stoned.Leszop
:

leszoptad!

Stoned.Light
:

(c)Light General
THE LAST TEMPTATION

Stoned.Love
("Love.b" 1/8):

Your PC is now ST NED in L VE with AT

"Love.a" :

From U of A with L VE

Stoned.LovChild
. "LoveChild b3 in reward for software stealing.". -.

Stoned.Lucky
: "I wish you a lucky"

Stoned.March6 (Michelangelo)
1M. 6 , . 360K , . "March6.Tocoto" :

"March6.Tocoto.a": MBF virus *MENEM TOCOTO* B.B.
"March6.Tocoto.b": MENEM TOCOTO virus 2"00

Stoned.March29
29 .

Stoned.May21
"Stoned.March6", . 21 : "ANTI March6 Karpachev Dmitr.".

Stoned.Micola
"Mikola.b" .

Stoned.Military
.

Stoned.Million
boot- . MBR "Non-System disk". OEM : "1000000".

Stoned.Near.a,b
1/16 "Near Dark", MBR. -.

Stoned.Nichols
: "[Nichols] by Apache".

Stoned.Nov7
(01h ASCII), 7 MBR.

Stoned.PC-AT
. " PC AT ".

Stoned.Rostov
--. "Stoned". . - 1/32 .

Stoned.Scrlock
"Scrlock" , ScrollLock.

Stoned.Scroll
, NumLock ScrollLock.

Stoned.Sex.a,b
(INT 13h, AH=2,3). (boot- - MBR ) 1/0/3 (//) 0/0/8 ( 0/0/7 ) . - 1/8 :

"Stoned.Sex.a": EXPORT OF SEX REVOLUTION ver. 1.1
"Stoned.Sex.b": EXPORT OF SEX REVOLUTION ver. 2.0

Stoned.Spook
"Spook 1.0", "LIM". MBR , .

Stoned.Swedish
: "The Swedish Disaster".

Stoned.Torm
1/8 :

Repent for ye shall be tormented...
Tormentor B - RABID Int'nl Dev. Corp. '91

Stoned.TurboManiac
19 :

The Turbo Maniac was here..

Stoned.WXYC
( MBR). : "JAM WXYC" "WXYC rules this roost!". .

Stoned.YMP
: "HAVE A NICE DAY (c)YMP".

Stoned.Zappa
4 :

Dedicated to ZAPPA...

Stoned.Zapped
:

ZAPPED YOU!

Stoned.Loa
"Stoned". -- .

Stone.MidNigh
"Stoned". :

IT'S MID NIGH

Stoned.Satria
"Stoned". MBR .

Stoned.Scale
"Stoned". Boot- MBR 0/0/9. .


(0)

Nexiv_Der.3888

, 02 2006 . 22:43 +
 (_) - -. COM-, boot- C: boot- . - , boot-. boot- C: DOS. Boot- C: . - INT 13h, DOS, INT 21h boot- COM- . COM-: 20h ( , EXE), INT 3, INT 13h ( INT 13h) INT 21h. ( INT 13h 20h ) CCh ( INT 3). , INT 3, , , INT 1 () . 256 , JMP CALL . . , . , , . boot- C: , 21. , :

Nexiv_Der takes on your files


(0)

Pur'Cyst

, 02 2006 . 22:40 +
 (_) -. INT 13h MBR C:. :

PUR'CYST

ExeBug , . : "Pur'Cyst" CMOS, disk A: 360K ( 1,2Mb) 720K ( 1.4Mb). , A: 1,2Mb 1.4Mb , BIOS Setup A, , A: . . BIOS, .



 : [1]