°£¤FKAV 7¯S¦³ªº·s¼W¥\¯à¥~,ÁÙ¥[±jªºPDM¤¶²Ð,¥H¤Î·s¼W¨¾¤õÀ𪺳]©w±Ð¾Ç
¥Dµe±

¨¾¤õÀð

±½ºË

§ó·s
¦pªG§ó·sµo¥Í¿ù»~,¥i¥H«öRollback (¦^ÂÐ)¤§«eªºª¬ºAµM«áÄ~Äò§ó·s

³ø§i
¹w³]30¤Ñ·|¦Û°Ê²M²z¤@¦¸,¦pªGµo²{KISÅܪº¸û¬°½wºC¥i¥H¨Ó²M²z³o¨ÇÀÉ®×§ïµ½³nÅé®Ä²v

°ò¥»³]©w
Potentially dangeroug software³o¶µ¤£«ØÄ³¶}±Ò,¦pªG¶}±Ò¤F·|³ø¤@¨ÇÀb«Èµ{¦¡,¹CÀ¸¥~±¾µ¥

¦bApperance³o¶µªºEvents notification¿ï¾ÜAdvanced¶i¤J¶i¶¥¿ï¶µ
§âHacker attack detection³o¶µ¨ú®ø¤Ä¿ï

§ó·s³]©w:
³]©w¬°¨C¤p®É§ó·s¤@¦¸,µM«á«öConfugure¶i¤J¤U¤@Ó¶±

¦³Å³©óKaspersky§ó·sªA°È¾¹¦³ªº®ÉÔ·|¥X¤@¨Ç°ÝÃD,¦Ó¨Ï±o§ó·sµLªk¦¨¥\
©Ò¥H§Ú±ÀÂ˲Ĥ@¦¸¦w¸Ë®É¥i¥H¨Ï¥Î"¤é¥»"ªA°È¾¹
«Ý§ó·s§¹²¦«á½Ð§ó§ï¬°"Russian Federation"(«Xù´µ)
¦¹ªA°È¾¹¥Ñ©ó¬OÁ`³¡©Ò¥H¯S§Oéw,§ó·s¨B½Õ¤]¤ñ¤é¥»ÁÙn§Ö¤W¤@ÂI

§Y®ÉºÊ±±³]©w
¿ï¾Ü³Ì§C¼h¯Å,¦¹¼h¯Å¤£·|Åý¹q¸£Åܪº¸û®e©ö¤¤¬r!
°Ê§@³]©w¬°ªý¤î¦s¨ú«á¸Ñ¬r,¦pªGµLªk¸Ñ¬r¬J§R°£ÀÉ®×

§Y®ÉºÊ±±:±Òµo°»´ú
¦pªG¨t²Îªº©Ê¯à°÷¦n,¥i¥H¥´¶}±Òµo¦¡½r¬r¤ÞÀº

ºô¶¨¾Å@³]©w:
ª½±µ«ö"¦Ûq",±NLimit fragment buffering time¬í¼Æ§ï¬°"1"¬í
¦p¦¹¥i¥H¥[§Ö¶}ºô¶ªº¤ÏÀ³®É¶¡

µM«á¿ï¾Ü¦Ûq,¤]§â±Òµo¶}¨ì³Ì°ª

¥kÁä±½ºË³]©w:
¿ï¶µ´N°Ñ·Ó¹w³],¤£«ØÄ³¸òºÊ±±¤@¼Ë³]¬°¦Û°Ê³B²z

¥kÁä±½ºË«ØÄ³±Òµoµ¥¯Å¥i¥H¶}¨ì³Ì°ª¯Å

¦pªGµo²{§AªºKIS±½´y³t«×«ÜºCªº¸Ü
¥i¥H¸ÕµÛ§âConcede resources to other application¨ú®ø,¤£n§â¨t²Î¸ê·½¤Àµ¹¨ä¥¦À³¥Îµ{¦¡

±Ò°Ê±½ºË:
¨ú®ø"At application startup"¥H¼W¶i¶}¾÷«áªºµ¥«Ý®É¶¡

§K¬Ì¨¾Å@³]©w:
¥Ñ¤W¨ì¤U¤À§O¬° "À³¥Îµ{¦¡¦æ¬°¤ÀªR" , "À³¥Îµ{¦¡¦æ¬°±±¨î" , "µù¥Uªí¨¾Å@"

À³¥Îµ{¦¡¦æ¬°¤ÀªR
KISªº¦æ¬°§PÂ_¥\¯àÁöµM¥u¬O¤@ÓªþÄݤlµ{¦¡
¦ý¥\¯à«D±`±j¤j,¤×¨ä¬O°»´úRootkit¥H¤ÎKeyloggesªº¯à¤O«D±`±j®«,«ÜÃø·|³Q¿òº|!

Âù««OÅ@,¤£¯à¥Ñ½r¬r¤ÞÀº°»´úªº³¡¤À¥æ¥ÑPDM¨Ó°»´ú(¹Ï¤ù¨ú¦ÛKAV 7.0
Overview of technologies)


KISªº§K¬Ì¨¾¿m¤¤ªºÀ³¥Îµ{¦¡¦æ¬°±±¨î¥\¯à¹w³]¬O¤£¶}±Òªº
¦]¬°¤@¯ë¤H¤£¤Ó·|¾Þ§@³oÓ¤l¨t²Î,§Ú³o¸Ìµy¬°»¡¤@¤U²³æªº³]©w¸ò±Æ°£¤èªk
º¥ý³oÓ¥\¯àªºì²z«Ü²³æ,¦b¹q¸£¸Ìªº¥ô¦ó¾Þ§@³£·|¨ü¨ìKISªººÊ±±
¤£¦P©ó½r¬r¤ÞÀºªº°»´ú¤è¦¡,¥¦¬Oª½±µ¹ïµ{§Çªº¦æ¬°¶i¦æ¤ÀªR
¥Ø«e¨Ï¥Î³oºØµo¦¡ªº¨¾¬r³nÅé°£¤FKISÁÙ¦³Panda , F-Secureµ¥
¨ä¤¤PandaÁ٥Ψӷí§@¥¦ªº¶i¶¥«¬±Òµo¦¡¤ÞÀº
¦p¦¹¤@¨Ó¹ï©ó¥¼ª¾«Â¯Ùªº¨¾¿m¤ñ°_³Ì±j±Òµo¦¡ªºNOD32ÁÙn±j®«¤£¤Ö
KIS 7ÁöµM¤ñ°_KIS 6¥[¤J¤Fwhiter list,¦ý¨ÌµMÄÝ©ó¤ñ¸û§xÃø¥B¯Ê¥F´¼¼zªº³oºØÃþ«¬
©Ò¥H¤HµM»Ýn¤@ÂI±M·~ª¾ÃÑ,¸ò¦Û¤v±Æ°£¤@¨Ç¤£¬O"«Â¯Ù"ªºµ{¦¡¦æ¬°
¤w¤U¥u¬O«Ü²³æªº¨Ò¤l,¥Ñ©ó¨CÓ¤H¹q¸£¦w¸Ëªº³nÅ餣ºÉ¬Û¦P
©Ò¥H·|¹J¨ìªº±¡ªp¤]¤£¤@¼Ë,n¬O¥X²{°ÝÃD,¨Ì·Ó¤U±ªº¤è¦¡¨Ì¼Ëµe¸¬Äª´N¥i¥H¤F
±Æ°£ªºµ{¦¡:
wuauclt.exe , msiexec.exe , iexplorer.exe
wuauclt.exe ¬°windows¨t²Î¦Û°Ê§ó·sªºµ{¦¡, msiexec.exe «h¬O¥Î¨Ó¦w¸Ë°ÆÀɦW¬°*.msi ªº¦w¸ËÀÉ
¸òiexplorer.exe ¤@¼Ë°õ¦æ®É·|¦³×§ïµù¥Uªíªº¥²n,¥Ñ©ó³o¨Ç³£¬O«H¥ôªºµ{¦¡,©Ò¥H¥i¥H±Æ°£µù¥UªíºÊ±±

¥H¤U¬°¦XªkªºÀ³¥Îµ{¦¡¥H¤Î¨t²Îµ{§Ç
alg.exe , csrss.exe , lsass.exe , smss.exe , winlogon.exe , svchost.exe , services.exe , msnmsgr.exe , msmsgs.exe
alg.exe:¥¦t³d³B²z¨t²Îºô¸ô¥H¤Î¨¾¤õÀ𤧶¡ªºÁpµ²
csrss.exe:¥¦¬Ot³d³B²z¨t²Î¹Ï§Î¬ÛÃöªºªA°È
lsass.exe:t³dOSªº¨t²Î¦w¥þµ¦²¤
smss.exe:·|¸Ü¨t²Î,³B²z¨t²Î·|¸Ü
winlogon.exe:¬°OSµn¤JºÞ²z¾¹,¦pªGµo²{¦³¤£©úµ{¦¡²K¥[±Ò°Ê¶µ¨ì³oÃä½Ðª`·N!
svchost.exe:¥¦·|±`±`½Õ¥Î*.dll ÀÉ®×,¦³®É·|¦³¶Ç°e«Ê¥]µ¥ªº»Ý¨D©Ò¥H³]¬°¤£¨üºô¸ôºÊ±±
services.exe:¬°¨t²ÎªA°ÈºÞ²zì¥ó,¦³®É·|×§ïµù¥Uªí,©Ò¥H³]¬°¤£¨üµù¥UªíºÊ±±
msnmsgr.exe:¸òmsmsgs.exe ±`·|¦³«Ü¦h³sºô°Ê§@,¥Ñ©óMSN¬O«H¥ôµ{¦¡©Ò¥H¤]³]¬°¤£¨üºô¸ôºÊ±±
À³¥Îµ{¦¡¦æ¬°±±¨î½d¨Ò
³o¸Ì±Ð¤j®a¥ÎÀ³¥Îµ{¦¡¦æ¬°±±¨î¨ÓÅý¤p¬õ³Ê§ó·s®É¥Ã»·¤£·|¼u¥X¼s§i
¥[¤Javnotify.exe µM«á§âexecute action (°õ¦æ°Ê§@)³]¬°block,
Content modification (ק鷺®e) ³]¬°block,run as child process (°õ¦æ¤lµ{§Ç) ³]¬°block

§âavnotify.dll ³oÓÀÉ®×¥[¶i¨Ó,³]¬°block
³]¸m§¹¤§«á¤p¬õ³Ê§ó·s´N¦A¤]¤£·|¸õ¥X¼s§i¤F

À³¥Îµ{¦¡¦æ¬°¤ÀªR»¡©ú
®³¤ì°¨¨ÓÁ|¨Ò,°²³]²{¦b¦³¤@°¦¤ì°¨½r¬r¤ÞÀº¥»¨°»´ú¤£¨ì
§Ṵ́õ¦æ¥¦,ÂǥѤ차¥»¨ªº¦æ¬°§i¶D§ÚÌ¥¦n°µªº¬O¤°»ò¨Æ±¡
¥¦¥i¯à·|¶}±Ò¬YÓport ¹ï¥~¶Ç°e«Ê¥],©Î¬O³s¤W¨ä¥¦ºô¯¸¤U¸ü¯f¬r
¦æ¬°¼Ò¦¡´N¬O¤ì°¨½Õ¥Îsvchost.exe¶Ç°e«Ê¥],©Î¬O½Õ¥Îiexplorer.exe¤U¸ü¯f¬r
³o®ÉÔµo²{¤F³o¼Ëªº¦æ¬°,KAV¥¦´N·|´£¥Ü
¥Ü½d:
°»´ú¨ì¦³µ{¦¡·N¹Ï¦s¨úµù¥Uªíªº±Ò°Ê¶µ¥Ø

ÂI¿ï©Úµ´

«öRollback¨Ó«ì´_¨t²Î

µù¥Uªí¨¾Å@«ØÄ³¥[¤J³W«h:
¥[¤J´X±ø³W«h¨Ó¥[±jKISªº¨¾Å@¯à¤O
¨ä¤¤¤@±ø¥i¥H¨¾¦í¬y¦æ©ÊUSB¯f¬r
¿ï¾Ü¥[¤J(Add)©Î¬O¦b²{¦³ªº±ø¥Ø¤W·s«Ø

¥[¤J¥H¤U¤T±ø³W«h:
QUOTE:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2

¹ê»Ú¹B¦æUSBÀH¨ºÐ¯f¬r:
¹ê»Ú´ú¸ÕUSB¯f¬rª½±µ¹B¦æntdelect.com«á¥X²{ĵ§iµøµ¡,½Ð«ö¤UDetails¬Ý¸Ô²Ó±¡§Î

³q±`¨S¦³Åã¥Ü¤½¥q¥H¤Î©Ê½è´yzªº½Ð¦h¦hª`·N¤@¤U,·íµM¦³¨Ç«H¥ôµ{¦¡¤]·|¨S¦³(¨Ò¦pNV ForceWare),¦ý«Ü¤Ö

¹Á¸Õק諸µù¥Uªí
QUOTE:
ModifyRegValue \REGISTRY\USER\S-1-5-21-448539723-651377827-725345543-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Personal²×¤î¹B¦æ«á,¯f¬r¹B¦æÅã¥Ü¥X²{¿ù»~
ModifyRegValue \REGISTRY\USER\S-1-5-21-448539723-651377827-725345543-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\AppData

¨S¦³´ú¸ÕRD³W«h,¨º¹D³W«h¬O°²¦p¦³¤HÀH¨ºÐ¤¤¤F¬r
¨Ã§âÀH¨ºÐ´¡¨ì§Aªº¹q¸£¤Wªº®ÉÔ¤~·|¦³§@¥Î
¨¾¤õÀð³]¸m:
KIS¨¾¤õÀð¹w³]¬°Low Level,¤]´N¬O¶Â¦W³æ¼Ò¦¡©ÎºÙ¬°¦wÀR¼Ò¦¡,¹w³]¤U¸òOS¨¾¤õÀð¤@¼Ë¤£·|²z·|¥Ñ¤º¨ì¥~ªº³s½u
¦pªG±N¨¾Å@µ¥¯Å³]¬°Training mode(¾Ç²ß¼Ò¦¡),³o¬OKIS³Ì±jªº¼Ò¦¡,¤]ºÙ¬°¥Õ¦W³æ¼Ò¦¡,§Ú«ØÄ³end user¨Ï¥Î¦¹¼Ò¦¡
¦b¾Ç²ß¼Ò¦¡¤U©Ò¦³ªº·s³s½u¬Ò¶·¥Ñ¨Ï¥ÎªÌ¨M©w¬O§_©ñ¦æ,¦b¦¹¼Ò¦¡¤UKIS¦bLeakTest¤W¤À¼Æ¥i¥H¶W¶VZoonAlarm

ºô°ì³]©w:
Stealth mode¬°Áô§Î¼Ò¦¡,¤@¯ë¹w³]¬°¶}±Ò
¦pªGºô¹J¤WÁÙ¦³¨ä¥Lªº¹q¸£»Ýn¶i¦æ·¾³q
½Ð±NStatus¥ÑIntelnet§ó§ï¬°Local network,¨Ã¨ú®øÁô§Î¼Ò¦¡

À³¥Îµ{¦¡³W«h:
KIS 7¥[¤J¤F¤ñKIS 6§ó¦hªºÀ³¥Îµ{¦¡³W«h
¤@¯ë±`¥Îªºµ{¦¡´X¥G³£¥i¥H¥¿±`ªº¹B§@
¤£¹L¤º«ØªºP2P³nÅé³W«h´N¤Ö,©Ò¥H¦¹¶µ¥Ø¥HBitComet¥H¤ÎeMule§@¥Ü½d
BitComet
º¥ý¥Î°O¨Æ¥»¥´¶}iniÀÉ®×
QUOTE:
App=D:\BitComet64\BitComet.exe§â"D:\BitComet64\BitComet.exe" §ï¦¨§A¦Û¤vBitComet ªº¥Ø¿ý
µM«á¥´¶}¦Û¤vªºBitComet ¦b¿ï¶µ>ºô¸ô³s±µ>ºÊ±±³s±µªú
³oÃä¬Ý§A¦Û¤vªº¬OþÓPORT
µM«á¦biniÀɸ̷j´M"8854"
§â"8854"§ï¦¨§ABitComet ©ÒºÊ±±ªº³s±µªú
§ï¦n«áÀx¦s
µM«á§â¸Óini³W«hÀÉ©ñ¦b«D¤¤¤å¸ô®|ªº¥Ø¿ý©³¤U
µM«á¶i¤JÀb«È¨¾Å@µ{¦¡(AntiHacker) ªº³]©w¶±
¦b¤U¹Ïªº¥k¤U¨¤«ö¶×¤J(°O±o¥ý§R°£¤§«e¦Ûqªº³W«h!)

§¹¦¨«á«ö½T©w¨Ã®M¥Î³W«h!
¤§«á§A¨Ï¥ÎBTªº®ÉÔ¤£¦ý¤U¸ü³t«×¤£·|°§C
¦Ó¥B¤]¤£¥Î¾á¤ß¦w¥þ©Ê¤è±ªº°ÝÃD!
eMule
³W«h¸òBTªº¤@¼Ën×§ï¤@¨Ç¦a¤è
º¥ý¤@¼Ën¨Ç§ïµ{¦¡¸ô®|
QUOTE:
App=D:\eMule0.47a-EastShare_v11-bin\eMule.exe§â"D:\eMule0.47a-EastShare_v11-bin\eMule.exe"
§ï¦¨§A¦Û¤veMuel ªº¥Ø¿ý
¦A¨Ó¥´¶}¦Û¤veMule ¨Ã¶i¤J>¿ï¶µ>³s½u>«È¤áºÝ³s±µªú
¬Ý¤@¤U§A¦Û¤vªºTCP/UDP ¦U¬Oþ¤@ÓPORT
µM«á¦biniÀɤº®e¤¤·j´M"4661",§â©Ò¦³ªº"4661"§ï¦¨§A¦Û¤vªºTCP³s±µªú
§ï¦n«á¦A·j´M"4672",¥þ³¡§ï¦¨§A¦Û¤vªºUDP³s±µªú
×§ï¦n«áÀx¦sini ÀÉ®×
¨Ã©ñ¸m¦b«D¤¤¤å¸ô®|ªº¥Ø¿ý¸ÌÀY
¤@¼Ë¦b³oÓ¦a¤è¶×¤J(¦pì¥ý¤w³]¦³eMule ³W«h½Ð§R°£«á¦A¶×¤J!)
[ ¥»©«³Ì«á¥Ñ £«¤@ ©ó 2007-8-25 15:54 ½s¿è ]
BT_³W«h.rar
(2007-08-23 21:52:20, Size: 349 B , Downloads: 72)
emule_³W«h.rar
(2007-08-23 21:52:20, Size: 377 B , Downloads: 28)

§Ú¤]¨Ó»¡¨â¥y ¬d¬Ý¥þ³¡µû½× ¬ÛÃöµû½×