<?xml version="1.0" encoding="windows-1251"?>
<rss version="2.0">
	<channel>
		<title>Форум esetnod32.ru [тема: Hidden File System Reader]</title>
		<link>http://forum.esetnod32.ru</link>
		<description>Новое в теме Hidden File System Reader форума  на сайте Форум esetnod32.ru [forum.esetnod32.ru]</description>
		<language>ru</language>
		<docs>http://backend.userland.com/rss2</docs>
		<pubDate>Sat, 02 May 2026 13:16:49 +0300</pubDate>
		<item>
			<title>Hidden File System Reader</title>
			<description><![CDATA[<b><a href="http://forum.esetnod32.ru/messages/forum8/topic7187/message54017/">Hidden File System Reader</a></b> <i>Hidden File System Reader tool for TDSS, Cidox,ZeroAccess, etc.</i> в форуме <a href="http://forum.esetnod32.ru/forum8/">Полезные программы</a>. <br />
			<B>Hidden File System Reader tool</B><br /><br />Implementing hidden storage makes forensic analysis more difficult since:<br /><br /> &nbsp; &nbsp;Malicious files are not stored in the file system (difficult to extract)<br /> &nbsp; &nbsp;Hidden storage cannot be decrypted without malware analysis<br /> &nbsp; &nbsp;Typical forensic tools do not work out of the box<br /><br />To tackle the problem of retrieving the contents of the hidden storage areas one needs to perform malware analysis and reconstruct algorithms used to handle the data stored inside it. In the course of our research into complex threats we have developed a tool intended to recover the contents of hidden storage used by such complex threats as:<br /><br /> &nbsp; &nbsp;TDL3 and modifications<br /> &nbsp; &nbsp;TDL4 and modifications<br /> &nbsp; &nbsp;Olmasco<br /> &nbsp; &nbsp;Rovnix.A<br /> &nbsp; &nbsp;Rovnix.B<br /> &nbsp; &nbsp;Sirefef (ZeroAccess)<br /> &nbsp; &nbsp;Goblin (XPAJ)<br /> &nbsp; &nbsp;Flame (dump decrypted resource section)<br /><br />The tool is very useful in incident response and threat analysis and monitoring. It is able to dump the malware’s hidden storage, as well as to dump any desired range of sectors of the hard drive. In the next figure a screenshot of the tool’s output is presented:<br /><br /><noindex><a href="http://blog.eset.com/2012/10/11/defeating-anti-forensics-in-contemporary-complex-threats" target="_blank" rel="nofollow">http://blog.eset.com/2012/10/11/defeating-anti-forensics-in-contemporary-complex-threats</a></noindex> <br />
			<i>14.10.2012 11:09:59, santy.</i>]]></description>
			<link>http://forum.esetnod32.ru/messages/forum8/topic7187/message54017/</link>
			<guid>http://forum.esetnod32.ru/messages/forum8/topic7187/message54017/</guid>
			<pubDate>Sun, 14 Oct 2012 11:09:59 +0400</pubDate>
			<category>Полезные программы</category>
		</item>
		<item>
			<title>Hidden File System Reader</title>
			<description><![CDATA[<b><a href="http://forum.esetnod32.ru/messages/forum8/topic7187/message53635/">Hidden File System Reader</a></b> <i>Hidden File System Reader tool for TDSS, Cidox,ZeroAccess, etc.</i> в форуме <a href="http://forum.esetnod32.ru/forum8/">Полезные программы</a>. <br />
			Это наверное, Матросова утилита. вроде как против tdss заточена. скрытые файловые системы ищет.<br /> <br /><br /> ° ESET Hidden File System Reader °<br /><br /> ° 1.0.2.2 beta (Sep 20 2012 13:07:27) °<br /><br /> ° Copyright &#169; 1992-2012 ESET, spol. s r.o. All rights reserved. °<br /><br /> ° HfsReader.exe &#91;params&#93; &#91;export_path&#93; °<br /> ° Params: °<br /> ° /help or /? &nbsp; &nbsp;- print help message °<br /> ° /no-output &nbsp; &nbsp; - no output to command line °<br /> ° /no-export &nbsp; &nbsp; - do not export files from file system(s) °<br /> ° /export-txt &nbsp; &nbsp;- export file list from file system(s) to text file °<br /> ° /mbr	 &nbsp; &nbsp; - make mbr dump °<br /> ° /vbr	 &nbsp; &nbsp; - make active drive vbr dump °<br /> ° /dump=&lt;o&gt;,&lt;s&gt; &nbsp;- make hard drive dump °<br /> °			&lt;o&gt; - offset from beginning or "end" °<br /> °			&lt;s&gt; - size °<br /> °			Examples: °<br /> °				 &nbsp; &nbsp;/dump=515,1024 °<br /> °				 &nbsp; &nbsp;/dump=end,4096 ° <br />
			<i>08.10.2012 18:02:27, santy.</i>]]></description>
			<link>http://forum.esetnod32.ru/messages/forum8/topic7187/message53635/</link>
			<guid>http://forum.esetnod32.ru/messages/forum8/topic7187/message53635/</guid>
			<pubDate>Mon, 08 Oct 2012 18:02:27 +0400</pubDate>
			<category>Полезные программы</category>
		</item>
		<item>
			<title>Hidden File System Reader</title>
			<description><![CDATA[<b><a href="http://forum.esetnod32.ru/messages/forum8/topic7187/message53634/">Hidden File System Reader</a></b> <i>Hidden File System Reader tool for TDSS, Cidox,ZeroAccess, etc.</i> в форуме <a href="http://forum.esetnod32.ru/forum8/">Полезные программы</a>. <br />
			Прошел по ссылке, только на Скачать нажал и восьмерка повесилась <img src="http://forum.esetnod32.ru/upload/main/smiles/5/icon_smile.gif" border="0" data-code=":)" data-definition="SD" alt=":)" style="width:16px;height:16px;" title="С улыбкой" class="bx-smile" /> <br />
			<i>08.10.2012 17:50:43, Арвид.</i>]]></description>
			<link>http://forum.esetnod32.ru/messages/forum8/topic7187/message53634/</link>
			<guid>http://forum.esetnod32.ru/messages/forum8/topic7187/message53634/</guid>
			<pubDate>Mon, 08 Oct 2012 17:50:43 +0400</pubDate>
			<category>Полезные программы</category>
		</item>
		<item>
			<title>Hidden File System Reader</title>
			<description><![CDATA[<b><a href="http://forum.esetnod32.ru/messages/forum8/topic7187/message53631/">Hidden File System Reader</a></b> <i>Hidden File System Reader tool for TDSS, Cidox,ZeroAccess, etc.</i> в форуме <a href="http://forum.esetnod32.ru/forum8/">Полезные программы</a>. <br />
			Боюсь <B>Santy</B> ты будешь первопроходцем <img src="http://forum.esetnod32.ru/upload/main/smiles/5/icon_smile.gif" border="0" data-code=":)" data-definition="SD" alt=":)" style="width:16px;height:16px;" title="С улыбкой" class="bx-smile" /> <br />
			<i>08.10.2012 17:42:27, zloyDi.</i>]]></description>
			<link>http://forum.esetnod32.ru/messages/forum8/topic7187/message53631/</link>
			<guid>http://forum.esetnod32.ru/messages/forum8/topic7187/message53631/</guid>
			<pubDate>Mon, 08 Oct 2012 17:42:27 +0400</pubDate>
			<category>Полезные программы</category>
		</item>
		<item>
			<title>Hidden File System Reader</title>
			<description><![CDATA[<b><a href="http://forum.esetnod32.ru/messages/forum8/topic7187/message53626/">Hidden File System Reader</a></b> <i>Hidden File System Reader tool for TDSS, Cidox,ZeroAccess, etc.</i> в форуме <a href="http://forum.esetnod32.ru/forum8/">Полезные программы</a>. <br />
			<noindex><a href="http://www.eset.com/download/utilities/detail/family/173/" target="_blank" rel="nofollow">http://www.eset.com/download/utilities/detail/family/173/</a></noindex><br /><br />Этой утилитой кто-нибудь пользуется? что она умеет делать? <br />
			<i>08.10.2012 17:31:03, santy.</i>]]></description>
			<link>http://forum.esetnod32.ru/messages/forum8/topic7187/message53626/</link>
			<guid>http://forum.esetnod32.ru/messages/forum8/topic7187/message53626/</guid>
			<pubDate>Mon, 08 Oct 2012 17:31:03 +0400</pubDate>
			<category>Полезные программы</category>
		</item>
	</channel>
</rss>
