427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet97/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   93   94   95   96   97   98   99   100   ...   387
Bog'liq
Botnets - The killer web applications

www.syngress.com
Common Botnets • Chapter 4
113
427_Bot_ch04.qxt 1/9/07 3:03 PM Page 113


the HKEY_Local_Machine\Software\Microsoft\Windows\
CurrentVersion\Run key in the registry.
Agobot will sometimes add a registry entry aimed at the Windows 95,
Windows 98, or Windows ME operating systems. By referencing the dropped
malicious file using the HKEY_Local_Machine\Software\Microsoft\
Windows\CurrentVersion\RunServices registry key, the bot software will
execute, but the service will not be displayed on the Close Program dialog
box, making it effectively invisible to the user.
Terminated Processes
Agobot contains arguably the most comprehensive listing of programs and
services to target for termination. Agobot seeks out processes associated with
antivirus or other security software, as well as processes associated with com-
peting malware, and shuts them down.
Modify Hosts File
Above and beyond terminating the processes associated with antivirus and
security software, variants of Agobot also modify the hosts file of the infected
machine to redirect attempts to reach the Web sites of antivirus and security
vendors.
The Hosts file, typically found at %System%\drivers\etc\hosts, is
appended with entries for Web sites such as Symantec’s LiveUpdate site or
McAfee’s download site, among others.The entries direct any attempts to
connect with these sites to the loopback address, 127.0.0.1, preventing the
connection and blocking the machine from communicating with those sites.
Theft of Information
Another aspect of Agobot that sets it apart from some of the other major bot
families is the theft of information. Specifically, Agobot will seek out and steal
the CD keys for a variety of popular games (see Table 4.7).
www.syngress.com

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   93   94   95   96   97   98   99   100   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish