PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode...

77

Transcript of PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode...

Page 1: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 2: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 3: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 4: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 5: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 6: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 7: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 8: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 9: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 10: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 11: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 12: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 13: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 14: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 15: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 16: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 17: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 18: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 19: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor

sigcheck -e -u -s c:\

listdlls -u

Page 20: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor

strings <file>

Page 21: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 22: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 23: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 24: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 25: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 26: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 27: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 28: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 29: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 31: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 32: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 33: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 34: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 35: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 36: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor

http://blogs.technet.com/b/markrussinovich/archive/2011/03/14/3412374.aspx

Page 37: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 38: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 39: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 40: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 41: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 42: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor

User Mode

Kernel Mode

File System

Filter Registry Callback

Kernel

Callouts

Process Monitor UI

Process Monitor Driver TCP/IP Driver ETW

events

Page 43: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 44: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 45: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 46: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 47: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 48: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 49: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor

Function 2

Function 1

Function 3

Function 3 Function 2 Function 1

Stack Display

Page 50: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor

Filter Manager

Virus Scanner

Kernel

System Library

System Library

SuperFetch

(root cause)

Kernel Mode

User Mode

Note: user stack capture isn’t supported on 64-bit versions of Windows XP/Server 2003

Page 51: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 52: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor

“Category is Write”

Page 53: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 54: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 55: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 56: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 57: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 58: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor

http://blogs.technet.com/b/markrussinovich/archive/2011/03/08/3392087.aspx

Page 59: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 60: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 61: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 62: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor

http://blogs.technet.com/b/markrussinovich/archive/2011/02/27/3390475.aspx

Page 63: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 64: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 65: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 66: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 67: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 68: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 69: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 70: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 71: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor

http://blogs.technet.com/b/markrussinovich/archive/2011/03/30/3416253.aspx

Page 72: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 73: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 74: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor
Page 75: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor

www.zerodaythebook.com

http://www.youtube.com/watch?v=ucyMBYg9RWU

Page 77: PowerPoint Presentationdownload.sysinternals.com/files/SysinternalsMalwareCleaning.pdf · User Mode Kernel Mode File System Filter Registry Callback Kernel Callouts Process Monitor

http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_stuxnet_dossier.pdf

http://www.wired.com/threatlevel/2011/07/how-digital-detectives-deciphered-stuxnet/

http://www.virusbtn.com/pdf/conference_slides/2010/Johnson-VB2010.pdf