![]() |
Rootkit TDL 3 |
Post Reply
|
Page 123 70> |
| Author | |
bootsect
Senior Member
Joined: 24 December 2009 Location: kernelmode.info Online Status: Offline Posts: 682 |
Post Options
Quote Reply
Topic: Rootkit TDL 3Posted: 13 July 2010 at 5:30pm |
|
there should be no problem with rku and tdl3 detection. If any then please post this at http://www.kernelmode.info because i'm not visiting sysinternals due to posted above reasons.
|
|
![]() |
|
BloodyFox
Newbie
Joined: 22 January 2010 Online Status: Offline Posts: 13 |
Post Options
Quote Reply
Posted: 12 July 2010 at 10:03pm |
|
My mistake, RkU3.8.388.590 SR2 does detect the infected driver...
|
|
![]() |
|
Meriadoc
Senior Member
Joined: 22 August 2006 Online Status: Offline Posts: 233 |
Post Options
Quote Reply
Posted: 10 July 2010 at 6:53am |
|
LOL@Papa Legba
|
|
|
aeria gloris
|
|
![]() |
|
BloodyFox
Newbie
Joined: 22 January 2010 Online Status: Offline Posts: 13 |
Post Options
Quote Reply
Posted: 08 July 2010 at 8:49pm |
|
Papa Legba, really no offence, but but please read a little bit more and then come again to write something that makes sense. Anyone has idea how to detect the infected driver with the latest version where RKU 3.8 doesn't show it?
|
|
![]() |
|
bootsect
Senior Member
Joined: 24 December 2009 Location: kernelmode.info Online Status: Offline Posts: 682 |
Post Options
Quote Reply
Posted: 06 July 2010 at 12:21pm |
|
LOL again.
Always enjoying watching when some "experts" are coming here and starting post bullsh1t, just like you :) Keep trying, tdl your
![]() |
|
![]() |
|
Papa Legba
Newbie
Joined: 05 July 2010 Online Status: Offline Posts: 4 |
Post Options
Quote Reply
Posted: 05 July 2010 at 7:06pm |
|
tdl 3 is really a quite simple malware. First of course the user rans in hi's computer the tdl3 dropper executable, then which then injects the spooler and the tdl3 dll file will then be unpacked to create the tdl.sys file and the cmdhooker now the systems miniport driver will be infected by hooking method... quite simple actually. Since the malware deletes it's own traces after it have been written to the computers file system of course it's hard to detect by antiviruses because they dont find the indications of the infection thats why the answer for detecting this malware is for the antiviruses to create a computer boot time scanner that regognizes the tdl3 code in the lower disk driver.
Most antivirus scanners had a boot time scanner allready back in the 90's so why not now? One solution to this problem could be that microsoft updates the miniport driver and make it protected. |
|
![]() |
|
bootsect
Senior Member
Joined: 24 December 2009 Location: kernelmode.info Online Status: Offline Posts: 682 |
Post Options
Quote Reply
Posted: 05 July 2010 at 6:08pm |
ROFL. ![]() Just like I said in previous post
|
|
![]() |
|
Papa Legba
Newbie
Joined: 05 July 2010 Online Status: Offline Posts: 4 |
Post Options
Quote Reply
Posted: 05 July 2010 at 6:11am |
|
tdl3 is propably so old rootkit at the moment that it is detected by allmost every antivirus and the different versions of this rootkit such as, batch, vbs, html and js have made it's heuristic and deeper detection much easier to the antivirus industry so i think that it's not a problem anymore. The biggest problem are propably the rootkits that comes with antivirus programs.
|
|
![]() |
|
bootsect
Senior Member
Joined: 24 December 2009 Location: kernelmode.info Online Status: Offline Posts: 682 |
Post Options
Quote Reply
Posted: 03 July 2010 at 8:14am |
Personally totally uninterested here. Sysinternals is like a bread for numerous trolls and it lost all creditability in case of malware/malware research. |
|
![]() |
|
a_d_13
Senior Member
Joined: 08 September 2007 Online Status: Offline Posts: 266 |
Post Options
Quote Reply
Posted: 03 July 2010 at 3:06am |
|
For the record, there is another thread at another forum that is all about TDL3, with lots of useful information. Check out: http://www.kernelmode.info/forum/viewtopic.php?f=16&t=19
Thanks, --AD |
|
![]() |
|
Post Reply
|
Page 123 70> |
| Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |