A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #17064  by AaLl86
 Fri Dec 07, 2012 9:27 am
RageMachine wrote:I found this on a system, very interesting and runs as a service on the target system. Was unable to kill the PID using all methods of force I knew (TerminateProcess, terminate threads, closing handles, WM_DEstroy, attaching debugger and then killing it) It prevents the target user from launching new devices on the system and its root dir in C:\Windows\Installer is untouchable. Defeated by removing registry key from windows repair.
* Enables driver test signing mode
* installs two drivers and makes keys under HKLM\System\CurrentControlSet****\Services\
* Has target of syshost.exe in C:\windows\installer\{ }\
* Removes Windows Update related services including bits\wuauserv
* prevents loading of new drivers and continually closes handles to its files and keys
Very interesting by the way... I certainly try it... Thanks for sharing!!!
Andrea
 #17437  by kmd
 Sat Dec 29, 2012 10:46 am
hate to say that, but there is nothing *fresh* in this investigation.

excuse me, but everything except not really meaningful parts about loader (now comes with about each rootkit) was already posted by

I. Kaspersky lab http://www.securelist.com/en/blog?print ... blogid=473
II. this forum http://www.kernelmode.info/forum/viewto ... 7&start=10
http://www.kernelmode.info/forum/viewto ... =14&t=1177

does it really need reinvent the wheel for your blogposts?
or we are going now like it was before in tdl3 case - post numerous articles about the same?
 #17439  by EP_X0FF
 Sat Dec 29, 2012 11:20 am
kmd wrote:hate to say that, but there is nothing *fresh* in this investigation.

excuse me, but everything except not really meaningful parts about loader (now comes with about each rootkit) was already posted by

I. Kaspersky lab http://www.securelist.com/en/blog?print ... blogid=473
II. this forum http://www.kernelmode.info/forum/viewto ... 7&start=10
http://www.kernelmode.info/forum/viewto ... =14&t=1177

does it really need reinvent the wheel for your blogposts?
or we are going now like it was before in tdl3 case - post numerous articles about the same?
If so then it is frustrating and disappointing.
 #17441  by rkhunter
 Sat Dec 29, 2012 11:55 am
kmd wrote:hate to say that, but there is nothing *fresh* in this investigation.

excuse me, but everything except not really meaningful parts about loader (now comes with about each rootkit) was already posted by

I. Kaspersky lab http://www.securelist.com/en/blog?print ... blogid=473
II. this forum http://www.kernelmode.info/forum/viewto ... 7&start=10
http://www.kernelmode.info/forum/viewto ... =14&t=1177

does it really need reinvent the wheel for your blogposts?
or we are going now like it was before in tdl3 case - post numerous articles about the same?
Your critics very important, thank you. Hope there are a lot of people who love my research and can gain useful info.
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 8