2013幎2æãæ°ãã
Avatarã«ãŒããããã«é¢ããæ
å ±ãæ²èŒãããŸãããããã¯æããã«ãã¢ã³ããŒã°ã©ãŠã³ããã©ãŒã©ã ã®1ã€ã«ç±æ¥ããŸãã ç¹ã«ããã®æ©èœã®èª¬æã¯pastebinãµãŒãã¹ã§
å
¬éãããŸããã ãã®ã«ãŒããããã®èª¬æãããæ©èœã¯æ¬åœã«å°è±¡çã ã£ããããæ°ããã«ãŒããããã«é¢ããæ
å ±ã¯ã»ãã¥ãªãã£ã³ãã¥ããã£ã§ç±ãè°è«ãããŸããã ããšãã°ãããŒããã£ã¹ã¯ã䜿çšããã«ãã©ã€ããŒãããŠã³ããŒãããæ©èœãOSããŒããã©ã€ããŒã®ææãæ°ããããããããä¿è·ã¹ããŒã ãªã©ã ãŸããããã€ãã®ã»ãã¥ãªãã£/ AV補åããã³æåãªã«ãŒãããã察çããã€ãã¹ãããšäž»åŒµããŸããã
ãã®ã«ãŒããããã®ãããããŒãèŠã€ãããšãããã«åæãå§ããŸããã
Win32 / Rootkit.AvatarãšããŠããŒã¿ããŒã¹ã«è¿œå ãããšèšããªããã°ãªããŸããã ååã®
ã¢ã³ãã³ã»ãã§ã¬ããããš
ã¢ã¬ã¯ãµã³ããŒã»ããããœãã¯ããã®ã«ãŒããããããã€ããŒããããã³åºæ¬çãªæ©èœã®è©³çްãªåæãè¡ããŸããã

3æãã¢ã³ããŠã€ã«ã¹ã©ãã¯ãç°ãªãCïŒCãµãŒããŒãšå¯Ÿè©±ããã³ã³ãã€ã«æ¥ãç°ãªã2ã€ã®ãããããŒãçºèŠããŸããã


çºè¡šã§è¿°ã¹ãããã«ãWin32 / Rootkit.Avatarã«ã¯ãã©ã€ããŒã€ã³ãã§ã¯ã¿ãŒãå«ãŸããŠããŸãããããã«ãã®ææ³ã2å䜿çšããŸãã1ã€ç®ã¯ãããããŒã§HIPSããã®æ€åºããã€ãã¹ãã2ã€ç®ã¯ãã©ã€ããŒã§åèµ·ååŸãåç¶ããŸãã åè
ã®å ŽåãæšæºOSãã©ã€ããŒã䜿çšããŠã«ãŒãã«ã¢ãŒãããã«ãŒãããããã©ã€ããŒãçŽæ¥èªã¿èŸŒããšããå©ç¹ã䜿çšãããåŸè
ã®å Žåãã«ãŒããããã¯åèµ·ååŸã®èµ·åãä¿èšŒããŸãã ãã¡ããããã®æŠè¡ã«ã¯ããã©ã€ããŒã®ããžã¿ã«çœ²åãæ€èšŒããããšã§ãã¡ã€ã«ã®æŽåæ§ãšæŽåæ§å¶åŸ¡ã«éåãããšããç¹ã§æ¬ ç¹ããããããã«ãŒããããã¯x86ã·ã¹ãã ã§ã®ã¿æ©èœããŸãã
ãããããŒã¢ãã¿ãŒã¯ããã«ãã¬ã€ã€ãŒãããããŒã¢ãããŒãã䜿çšããŸãã 第1ã¬ãã«ã®ãããããŒã¯ã第2ã¬ãã«ã®ãããããŒãšãã©ã€ããŒã«å¯ŸããŠè§£åïŒLZMAïŒãå®è¡ããŸãã å®éãæåã®ãããããŒã¯ã³ãŒãã§äœ¿çšããããã¥ãŒããã¯ã¹ãšã€ãã³ãã®ã©ã³ãã ãªååãçæããåã¢ãžã¥ãŒã«ã®æ¬äœã§ãããã®å€æŽãçŽæ¥å®è¡ããããã第2ã¬ãã«ã®ãããããŒãšãã©ã€ããŒèªäœã¯ãã¢ã³ããã¯ãããã³ã«çæãããäžæã®ãã¡ã€ã«ã§ãã æåã®ãããããŒã¯ããããã°é²æ¢ããŒã«ãšããŠè峿·±ãããªãã¯ã䜿çšããŸããããã¯ãKUSER_SHARED_DATA.InterruptTimeæ§é ïŒKUSER_SHARED_DATAãããŒãžã«ããããŠãŒã¶ãŒã¢ãŒããšã«ãŒãã«ã¢ãŒãã®äž¡æ¹ã§ã¢ã¯ã»ã¹å¯èœïŒããã®æéãæ¯èŒããããšã«åºã¥ããŠããŸãã æªæã®ããã³ãŒãã¯ãå¥ã®
KiUserExceptionDispatcher颿°å
ã®
RtlDispatchException颿°ã®åŒã³åºãã倿ŽããŸãã æ¬¡ã®ã¹ãããã§ã¯ãå
å«ãçæããå¶åŸ¡ãç®çã®äŸå€ãã³ãã©ãŒã«æž¡ããŸãã

ãã®å ŽåãçŸåšã®æž¬å®æéã¯KUSER_SHARED_DATA.InterruptTimeããååŸããããã®åŸã®å®è¡æ®µéã§æ¯èŒãããŸãã ãã®ã¡ã«ããºã ã«ããããããããŒã³ãŒãã®ãšãã¥ã¬ãŒã·ã§ã³ãšãããã°ãæ€åºã§ããŸãã
第2ã¬ãã«ã®ãããããŒã¯ãä»®æ³ãã·ã³ã®ç°å¢ããã§ãã¯ããããã«ã¯ããªãããç¥ããããã§ãã¯ã䜿çšãããŸãã VMã®ãã§ãã¯ãè¡ãã³ãŒããå®è¡ããåã«ããããããŒã¯ããšã¯ã¹ãããŒã©ãŒãããŒã䜿çšããŠããã埩å·åããŸãã

次ã®ã¹ãããã§ããããããŒã¯OSããŒãžã§ã³ãšçŸåšã®ç¹æš©ã確èªããŸãã ãã®å Žåã2ã€ã®ç¹æš©ãšã¹ã«ã¬ãŒã·ã§ã³æ¹æ³ã䜿çšãããŸãã
ã·ã¹ãã ã«ãããããŒãææãããããã»ã¹ãäžã®å³ã«ç€ºããŸãã

MS11-080è匱æ§ã®ãšã¯ã¹ããã€ãã§ã¯ã
Metasploit Frameworkã®ãšã¯ã¹ããã€ãã³ãŒãã«äŒŒãã³ãŒãã䜿çšããŸãããè¥å¹²ã®å€æŽãå ããããŠããŸãã afd.sysãã©ã€ããŒã®ããŒãžã§ã³ã確èªããåŸããããããŒã¯æ¬¡ã®ã³ãŒãã䜿çšããŠæäœããŸãã

次ã®ã¹ã¯ãªãŒã³ã·ã§ããã¯ãIOCTL 0x000120BBã䜿çšããŠ
afdïŒAFDJoinLeaf颿°ãåŒã³åºãã
HalDispatchTableã®ãã€ã³ã¿ãŒãç®çã®ã«ãŒãããã颿°ã«æžãæããã³ãŒãã瀺ããŠããŸãã

æäœãæåããå¶åŸ¡ãã·ã§ã«ã³ãŒãã«ç§»è¡ããåŸãã«ãŒãããããã©ã€ããŒã®ããŠã³ããŒããéå§ãããŸãã

å®éãã«ãŒãããããã©ã€ããŒã¯ãã£ã¹ã¯äžã«åå¥ã®ãã¡ã€ã«ãšããŠä¿åãããã®ã§ã¯ãªããã¡ã¢ãªãããã¡ãŒããããŒããããŸãã 以äžã¯ããã©ã€ããŒãããŒããã颿°ã®åŒã³åºãã°ã©ãã§ãã

ç¹æš©ã®ææ Œã«æåããåŸãæªæã®ããã³ãŒãã¯ãïŒ
WINDIRïŒ
\ system32 \ driversãã£ã¬ã¯ããªã§ææã«é©ãããã©ã€ããŒãæ€çŽ¢ããŸãã ææãå®äºãããšããã©ã€ããŒãšã³ããªãã€ã³ãïŒ
GsDriverEntry ïŒã倿Žãããæªæã®ããã³ãŒãïŒã¹ã¿ãïŒãå®è¡ãããŸãã 倿Žããããšã³ããªãã€ã³ãã¯æ¬¡ã®ãšããã§ãã

ãã®ã¹ã¿ãã®äž»ãªã¿ã¹ã¯ã®1ã€ã¯ã第2ã¬ãã«ã®ãããããŒã®å®è¡ããã»ã¹ã«æ¥ç¶ããã«ãŒãããããã©ã€ããŒã®æ¬äœãã¡ã¢ãªã«èªã¿èŸŒãããšã§ãã ã¹ã¿ãã³ãŒããæ¬¡ã®å³ã«ç€ºããŸãã

ææã«æåãããšã倿Žããããã©ã€ããŒã¯ïŒ
TEMPïŒ
ãã£ã¬ã¯ããªã«èªåèªèº«ãã³ããŒããæšæºã®OSã¡ã«ããºã ã䜿çšããŠïŒãµãŒãã¹ã³ã³ãããŒã«ãããŒãžã£ãŒçµç±ãŸãã¯
ZwLoadDriverããçŽæ¥ïŒèªåèªèº«ãããŒãããããšããŸãã

ãããã£ãŠãAvatarã«ãŒãããããã©ã€ããŒãã¡ã€ã«ã¯å®éã«ã¯ããŒããã©ã€ãã«ä¿åãããŸããããMS11-080ã䜿çšããŠåŒã³åºãããã³ãŒãã§èªã¿èŸŒãŸããŸãã ã·ã¹ãã ãã©ã€ããŒã®ææã䜿çšãããã®ã«ãŒããããããŠã³ããŒãæ¹æ³ã¯ãHIPSãåé¿ãã广çãªæ¹æ³ã§ãããä¿¡é Œã§ããã·ã¹ãã ãã©ã€ããŒããå¥ã®ã«ãŒãã«ã¢ãŒãã¢ãžã¥ãŒã«ãèªã¿èŸŒãããšãã§ããŸãã
é転æãã©ã€ããŒãã¡ã¢ãªã«æ£åžžã«èªã¿èŸŒãŸããåŸãæªæã®ããã³ãŒããã·ã¹ãã ãã©ã€ããŒã«ææããåèµ·ååŸã®çåã確ä¿ããŸãã ç¹å¥ãªã¢ã«ãŽãªãºã ã䜿çšããŠãç®çã®ãã©ã€ããŒãéžæããŸãã åæã«ãã¢ãã¿ãŒã¯ãã©ã€ããŒãã©ã³ãã ã«éžæãããã®ååãOSã®ç°ãªãããŒãžã§ã³ã«åºæã®ãã©ãã¯ãªã¹ããšç
§åããŸãã

ææãããã©ã€ããŒã³ãŒãã®å®è¡ãããŒã¯ã次ã®ã·ããªãªã«åŸã£ãŠçºçããŸãã
1.ãšã³ããªãã€ã³ãã§ã¹ã¿ããå®è¡ãããŸãã

2.次ã«ãPnp Notifyã³ãŒã«ããã¯é¢æ°ãGUID_DEVINTERFACE_DISKã¯ã©ã¹çšã«ã€ã³ã¹ããŒã«ãããŸãããã®ã¯ã©ã¹ã§ã¯ããã©ã€ããŒããã£ãé衚瀺ã®ã«ãŒãããããã¡ã€ã«ã·ã¹ãã ããããŒããããŸãã
TDL3 ã
TDL4ãããã³OlmascoïŒMaxSS / SSTïŒã§ãåæ§ã®ææ³ã芳å¯ãã
ãŸãã ã

3.ãšã³ããªãã€ã³ãã®ãœãŒã¹ãã€ãã埩å
ãããŸãã

ã«ãŒãããããã©ã€ããŒã¯ãå
ã®ãã¡ã€ã«ã®å
ã®ãµã€ãºã倿Žããã«ãããã€ãã®ã·ã¹ãã ãã©ã€ããŒã«ææããå¯èœæ§ããããŸãã
ã¢ãã¿ãŒã¯è峿·±ãããªãã¯ã䜿çšããŠãä»®æ³ãã·ã³ç°å¢ãçºèŠããŸãã
ntïŒMmMapIoSpace颿°ãåŒã³åºããŠã
0xF0000ã§ BIOSããŒã¿ãèªã¿åããæ¬¡ã®è¡ããã§ãã¯ããŸãã
- ParallelsãœãããŠã§ã¢
- ä»®æ³ãã·ã³
- Virtualbox
- QEMU BIOS
- VMware
- ããã¯ã¹
ãŸããã³ãŒãã«ã¯ãCPUIDåœä»€ã®æ¢ç¥ã®ããªãã¯ã䜿çšããKVMããã³Hyper-Vã®è¿œå ãã§ãã¯ããããŸãã
é衚瀺ã®FSã¯ããŠãŒã¶ãŒã¢ãŒãã®ãã€ããŒããšè£å©ãã¡ã€ã«ãæ ŒçŽããããã«äœ¿çšãããŸãã ãã¹ãŠã®ãã¡ã€ã«ã¯å¯Ÿç§°ã¢ã«ãŽãªãºã ã䜿çšããŠæå·åãããŸãã 以äžã¯ãé衚瀺ã®FSã§æ©èœãã颿°ã®åŒã³åºãã°ã©ãã§ãã

é衚瀺ã®FSã«ä¿åãããŠãããã¡ã€ã«ã«ã¯ç¹å¥ãªå±æ§ããããŸãã

æªæã®ããã³ãŒãã«ããããããã¯ãŒã¯ããããŠã³ããŒããããŠãŒã¶ãŒã¢ãŒãããã³ã«ãŒãã«ã¢ãŒãã¢ãžã¥ãŒã«ã®åœ¢ã§è¿œå ã®ãã€ããŒããããã«å®è¡ã§ããŸãã ãã®ãã€ããŒãã¯ãé衚瀺ã®FSã«ãä¿åãããŸãã Win32 / Rootkit.Avatarã¯ãææããã·ã¹ãã ãã©ã€ããŒãé€ãããã®ã³ã³ããŒãã³ããNTFSããªã¥ãŒã ã«ä¿åããŸããã é ãããæå·åãããFSãšææããã·ã¹ãã ãã©ã€ããŒã®ãã®çµã¿åããã«ãããåŸæ¥ã®ãã©ã¬ã³ãžãã¯ãã¯ããã¯ã䜿çšããŠã¢ãã¿ãŒã®ææã調æ»ããããšãããå°é£ã«ãªããŸãã
ãŠãŒã¶ãŒã¢ãŒããã€ããŒããå®è£
ããã«ã¯ã
KeInitializeApc颿°ã
䜿çšããŠAPCãªããžã§ã¯ããåæåããŸãããã®åŸãAPCãªããžã§ã¯ãã䜿çšããŠå¿
èŠãªã«ãŒãããã颿°ãå®è¡ããŸãã
ãã€ããŒãç ç©¶äžã®ã¢ãã¿ãŒã«ãŒããããã®å€æŽã®ãã€ããŒãã¯ãªãªãžãã«ã§ã¯ãããŸããã äž»ãªæ©èœïŒ
- ããŒã CïŒCãšã®çžäºäœçšã
- æ§ææ
å ±ã®è§£æã
- é衚瀺ã®FSã䜿çšããŸãã
- ã«ãŒãããããã©ã€ããŒãšã®çžäºäœçšã
- ãã€ããŒããã·ã¹ãã ã«ã€ã³ã¹ããŒã«ããŸãã
ã«ãŒããããã®ãã®å€æŽã調ã¹ãŠãããšãã«ãavcmd.dllã®åœ¢åŒã®ãã€ããŒããsvchost.exeã·ã¹ãã ããã»ã¹ã«å°å
¥ãããŠããããšãããããŸããã ãã®ã¢ãžã¥ãŒã«ã¯ãIPã¢ãã¬ã¹ãæ§æãã¡ã€ã«ã«ä¿åãããŠããCïŒCãæäœããŸãã ãã®ãã¡ã€ã«ã®æ§é ã¯æ¬¡ã®ãšããã§ãã
- ããããããã®èå¥åïŒååïŒã
- CïŒCããŒã ãµãŒããŒã®URLã
- æå·åã¢ã«ãŽãªãºã çšã®1024ãããããŒã
- RSA-1024ã®å
¬éããŒã
- ãã€ããŒããå®è£
ããããã»ã¹ã®ååã
2ã€ã®ç°ãªããããããŒãã埩å·åãããæ§ææ
å ±ã®äŸã以äžã«ç€ºããŸãã
èå¥åBTN1ã®ããããããã®å Žåã

èå¥åãNET1ã®ããããããçšã

CïŒCãšã®çžäºäœçšãä¿è·ããããã«ãã¢ãã¿ãŒã¯ç¬èªã®base64æå·åã¢ã«ãŽãªãºã ã䜿çšããŸãã åæã«ããŠãŒã¶ãŒã¢ãŒãã§ã®ãã¹ãŠã®ãããã¯ãŒã¯å¯Ÿè©±ã¯ãéåžžã®WinInet API颿°ã䜿çšããŠå®è¡ãããŸãã
ã¢ãã¿ãŒã«ã¯ãä»ã®æ¹æ³ã䜿çšããŠåé¡ãçºçããå Žåã«CïŒCãšéä¿¡ãã远å ã®æ¹æ³ããããŸãã 圌ã¯ãç¹å¥ãªãã©ã¡ãŒã¿ãŒã䜿çšããŠYahooã°ã«ãŒãã®ã¡ãã»ãŒãžãæ€çŽ¢ããããšããŸãã


ã·ãŒã±ã³ã¹ã¯ã次ã®ãã©ã¡ãŒã¿ãŒã«åºã¥ããŠæ€çŽ¢ãããŸãïŒãã®å Žåããããã¯17BTN1ãš17NET1ã§ãïŒã

ãããã®åç·ãæ¥ç¶ãããåŸãåä¿¡ãããã€ãã·ãŒã±ã³ã¹ã¯ãæ§æãã¡ã€ã«ã®1024ãããããŒã䜿çšããç¬èªã®ã¢ã«ãŽãªãºã ã䜿çšããŠæå·åãããŸãã
BTN1ããŒ=
6mQ98EXP3v7TKMdk704uOUzGqvikuoHt98n8IPp4K19
a3qyZ96LoOc54sb3g9eJVyAs7VmPxQjkkM9R960ev275K24PQ550K1
9fNk8305jRDUTb4cEut4579Zg9i32qUNET1ããŒ=
E623J5XKJ9NF4bseM5J2nkwhs1K2766DUOMUDSee3c
7xu06Q9QayV61U4fm5H89ppuNgLt9M5D2XTCLcd0aS3m9CO1aZg9h9
o2zb2EIC437IU3X1P3ec07481E0j2Tdræå·ååŸãåä¿¡ããã·ãŒã±ã³ã¹ã«base64ãé©çšãããæåã倧æåã«å€æãããäžéšã®æåãé€å€ãããŸãã èå¥åBTN1ã®ããããããã®äŸã以äžã«ç€ºããŸãã
SymFilterïŒUpperCaseïŒBase64ïŒæå·åïŒ17BTN1ïŒïŒïŒïŒ= EZTFDHWPæååEZTFDHWPã¯ãYahooã°ã«ãŒããåŸã§æ€çŽ¢ããããã«äœ¿çšãããŸãã ãã®ãããªèŠæ±ãæåããå Žåãæ¬¡ã®ã¹ãããã¯ãèŠã€ãã£ãã°ã«ãŒãã®çªå·ã確èªãããã®èª¬æããŒã¿ãèªã¿åãããšã§ãã

ã°ã«ãŒãã®èª¬æã¯ãRSAãš1024ãããã®ç§å¯ããŒã䜿çšããŠæå·åãããŸãã ãã®ãããªããŒã¿ã¯ãæ§æãã¡ã€ã«ã«ä¿åãããŠããå
¬éããŒãç¥ãããšã§è§£èªã§ããŸãã ãã®æ
å ±ã¯ãã¢ã¯ãã£ããªCïŒCãµãŒããŒããªãå Žåã«ããããããã«å¶åŸ¡ãè¿ãããã«äœ¿çšãããæå·åãããã¡ãã»ãŒãžã«å«ãŸããŠãããšèããŠããŸãã
ãã®é¢æ°ãèŠã€ããåŸãã€ããŒã°ã«ãŒãã§ãã®ãããªã¡ãã»ãŒãžã®å¯èœæ§ããã§ãã¯ããŸããã æå®ããããã©ã¡ãŒã¿ãŒïŒ11BTN1 = EFS9KHRFïŒã«äžèŽããã°ã«ãŒãã1ã€èŠã€ãããŸããã æ€çŽ¢ã¯ãšãªã¯æ¬¡ã®ããã«ãªããŸãã
hxxpïŒ//groups.yahoo.com/searchïŒquery = EFS9KHRFïŒsort = relevance

æå·åãããã¡ãã»ãŒãžããã®ã°ã«ãŒãã®èª¬æã«ååšããããšãããããŸãã

æ§æãã¡ã€ã«ã®1ã€ã«ããRSA-1024ããŒã䜿çšããŠããã®ã¡ãã»ãŒãžãè§£èªããŸããã ããããããèå¥åBTN1ãæã€æ§æãã¡ã€ã«ã®ããŒã䜿çšãããŸããã
dZ8FsJ4z0 :: httpïŒ//www.avatarbut.info www.avatarsbut.infoãã®æ
å ±ã¯ãBTN1æ§æãã¡ã€ã«èªäœã§èŠãCïŒCã®URLã®1ã€ã«äŒŒãŠããŸãã ãã®ã°ã«ãŒãã¯ãæ§æãã¡ã€ã«èªäœããã®æ
å ±ãå«ãŸããŠããããããµã€ããŒç¯çœªè
ããã®å¯Ÿè©±ã¢ãŒããåé¿ããããã«äœ¿çšããããã§ãã
CïŒCãµãŒããŒã®ãã¡ã€ã³æ
å ±ã¯é察称RSAããŒã¹ã®æå·åã¢ã«ãŽãªãºã ã䜿çšããŠæå·åããããããYahooã°ã«ãŒãã®ã¡ãã»ãŒãžã䜿çšãããã®ãããªãããããããµããŒãã¹ããŒã ã¯ãããããããã®åæè©Šè¡ã«å¯Ÿããåªããä¿è·ãæäŸããŸãã 調æ»ããã»ã¹äžãè©æ¬ºåž«ã¯ã¡ãã»ãŒãžãè§£èªããããã®å
¬éããŒã®ã¿ãæœåºã§ããŸããããã®ããŒã䜿çšããŠæ°ããã¡ãã»ãŒãžãæå·åãããããŒã°ã«ãŒããäœæããããšã¯ã§ããŸããã
ã¢ãã¿ãŒã©ã³ã¿ã€ã ã©ã€ãã©ãªæªæã®ããã³ãŒãWin32 / Rootkit.Avatarã«ã¯ãè£å©ã³ã³ããŒãã³ããéçºããããã®ç¹å¥ãªAPIããããŸãã ãã®APIã®äœ¿çšã¯ãã¢ãã¿ãŒã©ã³ã¿ã€ã ã©ã€ãã©ãªãšã远å ã®ãŠãŒã¶ãŒã¢ãŒãã¢ãžã¥ãŒã«ã®éçºãèšè¿°ããç¹å¥ãªSDKã«åºã¥ããŠããŸãã ãããã®ã¢ãžã¥ãŒã«ã¯ãã«ãŒãããããã©ã€ããŒãšã察話ã§ããŸãã ã¢ãã¿ãŒã©ã³ã¿ã€ã ã©ã€ãã©ãªã«ã¯ã次ã®APIãå«ãŸããŠããŸãã
- aTakeProcessToken-ããã»ã¹éã§ã¢ã¯ã»ã¹ããŒã¯ã³ãå²ãåœãŠãŸãã
- aExecute-ãªã¢ãŒãããã»ã¹ã®ã³ã³ããã¹ãã§ã¢ãžã¥ãŒã«ãå®è¡ããŸãã
- aLoadDriver-é衚瀺ã®FSã®å Žæãããã©ã€ããŒãããŒãããŸãã
- aLoadFileFromAvatarDisk-é衚瀺ã®FSãããã¡ã€ã«ãèªã¿åããŸãã
- aSaveFileOrAttrToAvatarDisk-ãã¡ã€ã«ãé衚瀺ã®FSã«æžã蟌ã¿ãŸãã
- aSendReport-æ
å ±ããªã¢ãŒãCïŒCã«éä¿¡ããŸãã
ããã»ã¹ã«åã蟌ãŸãããã€ããŒãã¹ãã¬ãŒãžæ§é ã¯æ¬¡ã®ããã«ãªããŸãã

Avatar SDKãåæããçµæããã®ãããžã§ã¯ãã¯ããªãè³æ Œã®ããéçºè
ã«ãã£ãŠéçºããããšçµè«ä»ããŸããã æããã«ãæªæã®ããã³ãŒãã®éçºè
ã¯ãåºæ¬æ©èœããã¹ãããã«ãŒãã«ã¢ãŒãã³ã³ããŒãã³ãã®å¿
èŠãªå®å®æ§ã確èªããããã«ãå°ãªããšã6ãæéã«ãŒããããã³ãŒãã«åãçµãã§ããŸãã
ãããã«Win32 / Rootkit.Avatarã«ãŒãããããã¡ããªã«ã¯ãAV補åã®èгç¹ããæ€åºããã€ãã¹ããè峿·±ãææ³ãå«ãŸããŠããŸãã ã¢ãã¿ãŒã«ãŒãããããšGapzããŒããããã䜿çšããŠãã·ã¹ãã ã®é·æçãªææãæäŸã§ããŸãã ã¢ãã¿ãŒã¯éåžžã®ããªã¥ãŒã ã«ãã¡ã€ã«ãä¿åããŸãããããã®ããã«ç¬èªã®é ãFSã䜿çšããŸã;ããã«ãæšæºãã©ã€ããŒã«ææããæè¡ã䜿çšããŸãã
ãã®è
åšã«ã¯ãã³ãã³ãCïŒCãµãŒããŒãå©çšã§ããªãå Žåã«ããããããã®å¶åŸ¡ãç¶æãã远å ã®æ¹æ³ããããŸãã ææããã·ã¹ãã ãå®å
šã«é§é€ããã«ã¯ããŸããã«ãŒãããããã©ã€ããŒãšãã®ãŠãŒã¶ãŒã¢ãŒããã€ããŒããéã¢ã¯ãã£ãåããŠãããææããã·ã¹ãã ãã©ã€ããŒã埩å
ããå¿
èŠããããŸãã