non so se ho fatto la ricerca in modo corretto è la prima volta che uso questo sito, l'ho inserito in Search è il risultato è questo...
User:
RyanMM
Reputation:
3 credits
Comment date:
2010-09-21 19:07:48 (UTC)
#Redbook.sys located in the #system32 / #drivers directory. Detected by TDSSKiller as a #rootkit. From the #TDSSKiller log:
2010/09/21 14:30:43.0484 redbook (43f64dbb7296ce330d300b0ff1dc0cd1) C:\WINDOWS\system32\DRIVERS\redbook.sys
2010/09/21 14:30:43.0484 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\redbook.sys. Real md5: 43f64dbb7296ce330d300b0ff1dc0cd1, Fake md5: b31b4588e4086d8d84adbf9845c2402b
2010/09/21 14:30:50.0125 Backup copy found, using it..
2010/09/21 14:30:50.0125 C:\WINDOWS\system32\DRIVERS\redbook.sys - will be cured after reboot
2010/09/21 14:30:50.0125 Rootkit.Win32.TDSS.tdl3(redbook) - User select action: Cure
2010/09/21 14:30:58.0046 Deinitialize success
Removing this file and this file alone restored the system to proper functionality, so I'm calling this malware.
Tags: Malware, Redbook, system32, drivers, rootkit, TDSSKiller, patched, lookslike
0b45979623b0ac774a9426c428954e7fb604fae0db187c402a f6052906f4099a