TDL3 Rootkit 64 Bit Driver

Page 1 of 2 12 LastLast

  1. Posts : 112
    7
       #1

    TDL3 Rootkit 64 Bit Driver


    KernelMode.info • View topic - Rootkit TDL 3 (alias TDSS, Alureon)
    I can now confirm that the latest TDL3 has a working 64-bit driver. It supports injecting into 32- and 64-bit processes from kernel-mode, and is capable of hiding data just like the 32-bit version.
      My Computer


  2. Posts : 8,476
    Windows® 8 Pro (64-bit)
       #2

    Hitman pro has the ability to remove TDL3 rootkit.
      My Computer


  3. Posts : 121
    Windows 7
       #3

    Why don't you upload it to offensive computing.
      My Computer


  4. Posts : 8,476
    Windows® 8 Pro (64-bit)
       #4

    dranfu said:
    Why don't you upload it to offensive computing.
      My Computer


  5. Posts : 2,303
    Windows 7 & Windows Vista Ultimate
       #5

    Dinesh said:
    Hitman pro has the ability to remove TDL3 rootkit.
    Not the one that is in the thread Jaxryley linked to.
      My Computer


  6. Posts : 8,476
    Windows® 8 Pro (64-bit)
       #6

    Corrine said:
    Dinesh said:
    Hitman pro has the ability to remove TDL3 rootkit.
    Not the one that is in the thread Jaxryley linked to.
    Hi, how do you know that?
      My Computer


  7. Posts : 121
    Windows 7
       #7

    @Jaxryley

    Offensive Computing | Community Malicious code research and analysis

    All files uploaded here will be imported into the Offensive Computing Malware database. By using this service, you certify that you are not uploading any ...
      My Computer


  8. Posts : 112
    7
    Thread Starter
       #8

    dranfu said:
    @Jaxryley

    Offensive Computing | Community Malicious code research and analysis

    All files uploaded here will be imported into the Offensive Computing Malware database. By using this service, you certify that you are not uploading any ...
    Thanks dranfu but I am kept quite busy uploading samples to Malwarebytes.

    If you join the KernelMode forum then the samples are available to download.

    I do try to join in over at KernelMode but those fellas over there are so far advanced that I'm left scratching my head most of the time.
      My Computer


  9. Posts : 2,303
    Windows 7 & Windows Vista Ultimate
       #9

    Dinesh said:
    Corrine said:
    Dinesh said:
    Hitman pro has the ability to remove TDL3 rootkit.
    Not the one that is in the thread Jaxryley linked to.
    Hi, how do you know that?
    As indicated in the thread, this is a new variant that researchers have still not obtained the dropper, although it appears that a_d_13 has file dumps for this variant from infected machines. All the bits are needed in order to create definitions. If anyone can do it, a_d_13 will.
      My Computer


  10. Posts : 2,303
    Windows 7 & Windows Vista Ultimate
       #10

    Here's an article by Marco Giuliani of Prevx on the variant:

    TDL3 rootkit x64 goes in the wild

    (Sidebar: I have a great deal of respect for Marco and recall all his work on the Gromozon rootkit removal tool.)
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 09:53.
Find Us