Sysinternals Homepage
Forum Home Forum Home > Windows Discussions > Malware
  New Posts New Posts RSS Feed: Rootkit TDL 3
  FAQ FAQ  Forum Search   Calendar   Register Register  Login Login

Rootkit TDL 3

 Post Reply Post Reply Page  123 70>
Author
Message Reverse Sort Order
bootsect View Drop Down
Senior Member
Senior Member
Avatar

Joined: 24 December 2009
Location: kernelmode.info
Online Status: Offline
Posts: 682
Post Options Post Options   Quote bootsect Quote  Post ReplyReply Direct Link To This Post Topic: Rootkit TDL 3
    Posted: 13 July 2010 at 5:30pm
there should be no problem with rku and tdl3 detection. If any then please post this at http://www.kernelmode.info because i'm not visiting sysinternals due to posted above reasons.
Back to Top
BloodyFox View Drop Down
Newbie
Newbie


Joined: 22 January 2010
Online Status: Offline
Posts: 13
Post Options Post Options   Quote BloodyFox Quote  Post ReplyReply Direct Link To This Post Posted: 12 July 2010 at 10:03pm
My mistake, RkU3.8.388.590 SR2 does detect the infected driver...
Back to Top
Meriadoc View Drop Down
Senior Member
Senior Member
Avatar

Joined: 22 August 2006
Online Status: Offline
Posts: 233
Post Options Post Options   Quote Meriadoc Quote  Post ReplyReply Direct Link To This Post Posted: 10 July 2010 at 6:53am
LOL@Papa Legba
aeria gloris
Back to Top
BloodyFox View Drop Down
Newbie
Newbie


Joined: 22 January 2010
Online Status: Offline
Posts: 13
Post Options Post Options   Quote BloodyFox Quote  Post ReplyReply Direct Link To This Post Posted: 08 July 2010 at 8:49pm
Papa Legba, really no offence, but but please read a little bit more and then come again to write something that makes sense. Anyone has idea how to detect the infected driver with the latest version where RKU 3.8 doesn't show it?
Back to Top
bootsect View Drop Down
Senior Member
Senior Member
Avatar

Joined: 24 December 2009
Location: kernelmode.info
Online Status: Offline
Posts: 682
Post Options Post Options   Quote bootsect Quote  Post ReplyReply Direct Link To This Post Posted: 06 July 2010 at 12:21pm
LOL again.

Always enjoying watching when some "experts" are coming here and starting post bullsh1t, just like you :) Keep trying, tdl your
Since the malware deletes it's own traces after it have been written to the computers file system
was especially laughable LOL

Back to Top
Papa Legba View Drop Down
Newbie
Newbie
Avatar

Joined: 05 July 2010
Online Status: Offline
Posts: 4
Post Options Post Options   Quote Papa Legba Quote  Post ReplyReply Direct Link To This Post Posted: 05 July 2010 at 7:06pm
tdl 3 is really a quite simple malware. First of course the user rans in hi's computer the tdl3 dropper executable, then which then injects the spooler and the tdl3 dll file will then be unpacked to create the tdl.sys file and the cmdhooker now the systems miniport driver will be infected by hooking method... quite simple actually. Since the malware deletes it's own traces after it have been written to the computers file system of course it's hard to detect by antiviruses because they dont find the indications of the infection thats why the answer for detecting this malware is for the antiviruses to create a computer boot time scanner that regognizes the tdl3 code in the lower disk driver.

Most antivirus scanners had a boot time scanner allready back in the 90's so why not now? One solution to this problem could be that microsoft updates the miniport driver and make it protected.
Back to Top
bootsect View Drop Down
Senior Member
Senior Member
Avatar

Joined: 24 December 2009
Location: kernelmode.info
Online Status: Offline
Posts: 682
Post Options Post Options   Quote bootsect Quote  Post ReplyReply Direct Link To This Post Posted: 05 July 2010 at 6:08pm
tdl3 is propably so old rootkit at the moment that it is detected by allmost every antivirus and the different versions of this rootkit such as, batch, vbs, html and js have made it's heuristic and deeper detection much easier to the antivirus industry so i think that it's not a problem anymore


ROFL.Clap

Just like I said in previous post
Back to Top
Papa Legba View Drop Down
Newbie
Newbie
Avatar

Joined: 05 July 2010
Online Status: Offline
Posts: 4
Post Options Post Options   Quote Papa Legba Quote  Post ReplyReply Direct Link To This Post Posted: 05 July 2010 at 6:11am
tdl3 is propably so old rootkit at the moment that it is detected by allmost every antivirus and the different versions of this rootkit such as, batch, vbs, html and js have made it's heuristic and deeper detection much easier to the antivirus industry so i think that it's not a problem anymore. The biggest problem are propably the rootkits that comes with antivirus programs.
Back to Top
bootsect View Drop Down
Senior Member
Senior Member
Avatar

Joined: 24 December 2009
Location: kernelmode.info
Online Status: Offline
Posts: 682
Post Options Post Options   Quote bootsect Quote  Post ReplyReply Direct Link To This Post Posted: 03 July 2010 at 8:14am
Originally posted by BloodyFox

As the topic is unlocked again, please don't be shy and share your experience with the latest versions of the TDL3 and please let's not make it again VT results postings wall. Fresh know-how for the latest infection mechanism and detection/removing will be much more useful :)


Personally totally uninterested here. Sysinternals is like a bread for numerous trolls and it lost all creditability in case of malware/malware research.
Back to Top
a_d_13 View Drop Down
Senior Member
Senior Member
Avatar

Joined: 08 September 2007
Online Status: Offline
Posts: 266
Post Options Post Options   Quote a_d_13 Quote  Post ReplyReply Direct Link To This Post Posted: 03 July 2010 at 3:06am
For the record, there is another thread at another forum that is all about TDL3, with lots of useful information.  Check out: http://www.kernelmode.info/forum/viewtopic.php?f=16&t=19

Thanks,
--AD
Back to Top
 Post Reply Post Reply Page  123 70>

Forum Jump Forum Permissions View Drop Down