[ Last edited by Legend on 2007-1-23 at 14:09 ]作者: Legend 时间: 2007-1-23 14:08 请勿在论坛发病毒样本的下载链接,避免其它网友误点。
下次您可以直接发到virus@micropoint.com.cn我们会具体测试分析,原链接已做屏蔽处理。作者: 360SuperKill 时间: 2007-1-23 14:09 该病毒样本没有任何危害,并提供了直接卸载功能作者: shaka47 时间: 2007-1-24 22:28 标题: 俄windows内核专家回复mj0011
这是俄windows内核专家回复mj0011,否定mj0011的研究成果:
EP_X0FF
Senior Member
Joined: 08 March 2006
Location: Russian Federation
Online Status: Offline
Posts: 3708 Posted: 21 January 2007 at 7:40am | IP Logged Some remarks. For mj0011 and others:
RkDetection it is not when you started few forensic tools and searched for known place where hidden object are located. And it is not cleaning FS filters, because this is a very likely will lead to BSOD (for example if you have EFS filters).
So what is the RkDetection?
1. It is when I started RkDetector on different computers, not only mine, and not got stupid BSOD on start.
2. It is when RkDetector can locate rootkits even if it is do not knows where rootkits are located.
3. It is when I do not worry about BSOD's only because somebody wanna cleanup fs-filter queue =))))
4. It is when I can locate these hidden objects not from the ass of the world (command line prompt with mount, unmount commands, forensic tools etc) From Normal GUI application with few pretty buttons (not f**ken labels or comboboxes) where one of them is named "SCAN" or "Scan for rk".
I see Nothing from this here right now, so further discussion have no sense.作者: 360SuperKill 时间: 2007-1-25 01:33
Quote:
Originally posted by shaka47 at 2007-1-24 22:28:
这是俄windows内核专家回复mj0011,否定mj0011的研究成果:
EP_X0FF
Senior Member
Joined: 08 March 2006
Location: Russian Federation
Online Status: Offline
Posts: 3708 Posted: 21 January 2007 ...