Recommended for You:
Fix up your PC Fast

TuneUp Utilities 2012 takes out the trash: Get back long lost disk space and performance in a snap – Free Download!






You are not connected. Please login or register

View previous topic View next topic Go down  Message [Page 1 of 1]

1 TDL3 rootkit x64 goes in the wild on Fri Aug 27, 2010 3:38 am

Blaze


Malware Researcher
Malware Researcher
It took some time but now x64 Windows operating systems are officially the new target of rootkits.

We talked about TDL3 rootkit some months ago as the most advanced rootkit ever seen in the wild. Well, the last version of TDL3 was released months ago and documented as build 3.273. After that, no updates have been released to the rootkit driver. This was pretty suspicious, more so if you've been used to seeing rebuild versions of TDL3 rootkit every few days to defeat security software.

Obviously, the rootkit was stable and it is currently running without any major bug on every 32 bit Windows operating system. Still though, the dropper needed administrator rights to install the infection in the system. Anyway, the team behind TDL3 rootkit was just too quiet to not expect something new.


...Read more: http://www.prevx.com/blog/154/TDL-rootkit-x-goes-in-the-wild.html


..........................................................
Feel free to follow me on Twitter: bartblaze

2 Re: TDL3 rootkit x64 goes in the wild on Wed Sep 15, 2010 3:34 pm

DragonMaster Jay


Site Owner
Site Owner
Looks like Kaspersky's TDSSKiller is working fine to kill the rootkit.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

3 Re: TDL3 rootkit x64 goes in the wild on Thu Sep 16, 2010 2:22 am

Blaze


Malware Researcher
Malware Researcher
Have you tested MBRCheck already on an infected machine ?


..........................................................
Feel free to follow me on Twitter: bartblaze

4 Re: TDL3 rootkit x64 goes in the wild on Thu Sep 16, 2010 5:15 am

DragonMaster Jay


Site Owner
Site Owner
I have not. I know the dudes at KernelMode probably did. I think AD said it was not ready yet.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

Ad Bot


View previous topic View next topic Back to top  Message [Page 1 of 1]

Permissions in this forum:
You cannot reply to topics in this forum