Information pour Coolman et autres
Elite
-
Elite -
Elite -
rundll32.exe shell32.dll,Control_RunDLL appwiz.cpl,,2\1 +composant indésirable
--------------------------------------------------------------------------------------------------------------------------------------
Rundll_As <~~ camoufflage ;)
--------------------------------------------------------------------------------------------------------------------------------------
[NoLoad] --> cpl
--------------------------------------------------------------------------------------------------------------------------------------
/!\ Encryption --> ROT13 <~~ controle tout /!\
--------------------------------------------------------------------------------------------------------------------------------------
Norton fake pwnz
--------------------------------------------------------------------------------------------------------------------------------------
Service executer<--> installer:
Comme par exemple:
--------------------------------------------------------------------------------------------------------------------------------------
Sur écriture //1
-----------------------------------------------------------------------------------------------------------------------------------------
Vérifier MBAMService
Vérifier Firefox
------------------------------------------------------------------------------------------------------------------------------------------
Et y a du ZeroAccess derrière
------------------------------------------------------------------------------------------------------------------------------------------
HHCTRL.OCX +[ui] ; user32.dll, ntdll
/!\ Exploit movie maker / front page /!\
------------------------------------------------------------------------------------------------------------------------------------------
C:\WINDOWS\system32\Setup\iis.dll <--- Boo
------------------------------------------------------------------------------------------------------------------------------------------
Vérification approfondie sur les "printers" & Trojan server Printer
------------------------------------------------------------------------------------------------------------------------------------------
Langue utiliser&version pack installer <--|
^
[rapport avec le framework] WMI overflow
[V2] principalement en cause pour le moment
pas encore finni avec ça
----------------------------------------------------------------------------------------------------------------------------------------
Bonne Recherche pour ton tool :P
--------------------------------------------------------------------------------------------------------------------------------------
Rundll_As <~~ camoufflage ;)
--------------------------------------------------------------------------------------------------------------------------------------
[NoLoad] --> cpl
--------------------------------------------------------------------------------------------------------------------------------------
/!\ Encryption --> ROT13 <~~ controle tout /!\
--------------------------------------------------------------------------------------------------------------------------------------
Norton fake pwnz
--------------------------------------------------------------------------------------------------------------------------------------
Service executer<--> installer:
Comme par exemple:
[SQL Server (32 bits)] Driver=C:\WINDOWS\system32\SQLSRV32.dll Setup=C:\WINDOWS\system32\sqlsrv32.dll 32Bit=1 [ODBC 32 bit Drivers] SQL Server (32 bits)=Installed Microsoft Access Driver (*.mdb) (32 bits)=Installed Microsoft Text Driver (*.txt; *.csv) (32 bits)=Installed Microsoft Excel Driver (*.xls) (32 bits)=Installed Microsoft dBase Driver (*.dbf) (32 bits)=Installed Microsoft Paradox Driver (*.db ) (32 bits)=Installed Microsoft Visual FoxPro Driver (32 bits)=Installed Microsoft FoxPro VFP Driver (*.dbf) (32 bits)=Installed Microsoft dBase VFP Driver (*.dbf) (32 bits)=Installed Microsoft Access-Treiber (*.mdb) (32 bits)=Installed Microsoft Text-Treiber (*.txt; *.csv) (32 bits)=Installed Microsoft Excel-Treiber (*.xls) (32 bits)=Installed Microsoft dBase-Treiber (*.dbf) (32 bits)=Installed Microsoft Paradox-Treiber (*.db ) (32 bits)=Installed Microsoft Visual FoxPro-Treiber (32 bits)=Installed Driver do Microsoft Access (*.mdb) (32 bits)=Installed Driver da Microsoft para arquivos texto (*.txt; *.csv) (32 bits)=Installed Driver do Microsoft Excel(*.xls) (32 bits)=Installed Driver do Microsoft dBase (*.dbf) (32 bits)=Installed Driver do Microsoft Paradox (*.db ) (32 bits)=Installed Driver para o Microsoft Visual FoxPro (32 bits)=Installed Microsoft ODBC for Oracle (32 bits)=Installed [Microsoft Access Driver (*.mdb) (32 bits)] Driver=C:\WINDOWS\system32\odbcjt32.dll Setup=C:\WINDOWS\system32\odbcjt32.dll 32Bit=1 [Microsoft Text Driver (*.txt; *.csv) (32 bits)] Driver=C:\WINDOWS\system32\odbcjt32.dll Setup=C:\WINDOWS\system32\odtext32.dll 32Bit=1 [Microsoft Excel Driver (*.xls) (32 bits)] Driver=C:\WINDOWS\system32\odbcjt32.dll Setup=C:\WINDOWS\system32\odexl32.dll 32Bit=1 [Microsoft dBase Driver (*.dbf) (32 bits)] Driver=C:\WINDOWS\system32\odbcjt32.dll Setup=C:\WINDOWS\system32\oddbse32.dll 32Bit=1 [Microsoft Paradox Driver (*.db ) (32 bits)] Driver=C:\WINDOWS\system32\odbcjt32.dll Setup=C:\WINDOWS\system32\odpdx32.dll 32Bit=1 [Microsoft Visual FoxPro Driver (32 bits)] Driver=C:\WINDOWS\system32\vfpodbc.dll Setup=C:\WINDOWS\system32\vfpodbc.dll 32Bit=1 [Microsoft FoxPro VFP Driver (*.dbf) (32 bits)] Driver=C:\WINDOWS\system32\vfpodbc.dll Setup=C:\WINDOWS\system32\vfpodbc.dll 32Bit=1 [Microsoft dBase VFP Driver (*.dbf) (32 bits)] Driver=C:\WINDOWS\system32\vfpodbc.dll Setup=C:\WINDOWS\system32\vfpodbc.dll 32Bit=1 [Microsoft Access-Treiber (*.mdb) (32 bits)] Driver=C:\WINDOWS\system32\odbcjt32.dll Setup=C:\WINDOWS\system32\odbcjt32.dll 32Bit=1 [Microsoft Text-Treiber (*.txt; *.csv) (32 bits)] Driver=C:\WINDOWS\system32\odbcjt32.dll Setup=C:\WINDOWS\system32\odtext32.dll 32Bit=1 [Microsoft Excel-Treiber (*.xls) (32 bits)] Driver=C:\WINDOWS\system32\odbcjt32.dll Setup=C:\WINDOWS\system32\odexl32.dll 32Bit=1 [Microsoft dBase-Treiber (*.dbf) (32 bits)] Driver=C:\WINDOWS\system32\odbcjt32.dll Setup=C:\WINDOWS\system32\oddbse32.dll 32Bit=1 [Microsoft Paradox-Treiber (*.db ) (32 bits)] Driver=C:\WINDOWS\system32\odbcjt32.dll Setup=C:\WINDOWS\system32\odpdx32.dll 32Bit=1 [Microsoft Visual FoxPro-Treiber (32 bits)] Driver=C:\WINDOWS\system32\vfpodbc.dll Setup=C:\WINDOWS\system32\vfpodbc.dll 32Bit=1 [Driver do Microsoft Access (*.mdb) (32 bits)] Driver=C:\WINDOWS\system32\odbcjt32.dll Setup=C:\WINDOWS\system32\odbcjt32.dll 32Bit=1 [Driver da Microsoft para arquivos texto (*.txt; *.csv) (32 bits)] Driver=C:\WINDOWS\system32\odbcjt32.dll Setup=C:\WINDOWS\system32\odtext32.dll 32Bit=1 [Driver do Microsoft Excel(*.xls) (32 bits)] Driver=C:\WINDOWS\system32\odbcjt32.dll Setup=C:\WINDOWS\system32\odexl32.dll 32Bit=1 [Driver do Microsoft dBase (*.dbf) (32 bits)] Driver=C:\WINDOWS\system32\odbcjt32.dll Setup=C:\WINDOWS\system32\oddbse32.dll 32Bit=1 [Driver do Microsoft Paradox (*.db ) (32 bits)] Driver=C:\WINDOWS\system32\odbcjt32.dll Setup=C:\WINDOWS\system32\odpdx32.dll 32Bit=1 [Driver para o Microsoft Visual FoxPro (32 bits)] Driver=C:\WINDOWS\system32\vfpodbc.dll Setup=C:\WINDOWS\system32\vfpodbc.dll 32Bit=1 [Microsoft ODBC for Oracle (32 bits)] Driver=C:\WINDOWS\system32\msorcl32.dll Setup=C:\WINDOWS\system32\msorcl32.dll 32Bit=1
--------------------------------------------------------------------------------------------------------------------------------------
Sur écriture //1
-----------------------------------------------------------------------------------------------------------------------------------------
Vérifier MBAMService
Vérifier Firefox
------------------------------------------------------------------------------------------------------------------------------------------
Et y a du ZeroAccess derrière
------------------------------------------------------------------------------------------------------------------------------------------
HHCTRL.OCX +[ui] ; user32.dll, ntdll
/!\ Exploit movie maker / front page /!\
------------------------------------------------------------------------------------------------------------------------------------------
C:\WINDOWS\system32\Setup\iis.dll <--- Boo
------------------------------------------------------------------------------------------------------------------------------------------
Vérification approfondie sur les "printers" & Trojan server Printer
------------------------------------------------------------------------------------------------------------------------------------------
Langue utiliser&version pack installer <--|
^
[rapport avec le framework] WMI overflow
[V2] principalement en cause pour le moment
pas encore finni avec ça
----------------------------------------------------------------------------------------------------------------------------------------
Bonne Recherche pour ton tool :P
A voir également:
- Information pour Coolman et autres
- Information d'identification réseau - Guide
- Zhpcleaner nicolas coolman - Télécharger - Informations & Diagnostic
- L'en-tête du document comporte une information qui n’apparaît pas à l'impression car elle est de couleur blanche. de quelle information s'agit-il ? ✓ - Forum LibreOffice / OpenOffice
- En tête qui n'apparaît pas ✓ - Forum Bureautique
- Information pc - Guide