TLD4 rootkit

Talk about Rootkits - what they are, how they work. etc..

If this topic has helped you then please...



 

TLD4 rootkit

Postby jamescv7 » Mon Nov 15, 2010 1:21 pm

How the TLD4 rootkit gets around driver signing policy on a 64-bit machine

Microsoft’s Windows operating system, running on a 64-bit machine provides enhanced security with driver signing of system and low level drivers. This policy, called the kernel mode code signing policy, disallows any unauthorized or malicious driver to be loaded. [1.]

The TDL4 rootkit bypasses driver signing policy on 64-bit machines by changing the boot options of Microsoft boot programs that will allow an unsigned driver to load.


http://sunbeltblog.blogspot.com/2010/11 ... river.html
jamescv7
Master Contributor
 
Posts: 3712
Joined: Sun Sep 20, 2009 12:14 am
Location: Riyadh,Saudi Arabia
Has thanked: 104 times
Have thanks: 54 times
OS: Windows XP Professional
Architecture: 32bit

TLD4 rootkit

Advertisement

Advertisement
 

Re: TLD4 rootkit

Postby sss20 » Mon Nov 15, 2010 11:09 pm

I'm always shocked when i read this kind of articles...the creators of this rootkit found a really smart way to pass the driver signing policy on a 64-bit machine....
As far as the rootkit itself.....well we all knew that the 64bit won't be a rootkit fortress forever.....
sss20
Master Contributor
 
Posts: 3358
Joined: Thu Jul 30, 2009 6:43 am
Has thanked: 132 times
Have thanks: 151 times
OS: Windows 7 Professional
Architecture: 64bit

Re: TLD4 rootkit

Postby Quackimducky » Tue Nov 16, 2010 4:26 am

Im scared
User avatar
Quackimducky
Regular Contributor
 
Posts: 518
Joined: Sat Aug 14, 2010 6:49 am
Location: S.E.A
Has thanked: 14 times
Have thanks: 9 times

Re: TLD4 rootkit

Postby virtu » Tue Nov 16, 2010 4:53 am

Low chances any of our Windows 64-BIT members will infect themselves with it as long as they continue to use common sense and a security program.
A fool with an antivirus tool is still a fool.
If you can't convince them, confuse them.
The last thing I want to do is insult you. But it IS on the list.
User avatar
virtu
Master Contributor
 
Posts: 2605
Joined: Sat Dec 27, 2008 4:37 am
Location: Earth...maybe
Has thanked: 5 times
Have thanks: 25 times
OS: Windows 7 Home
Architecture: 32bit

Re: TLD4 rootkit

Postby gusthebus » Tue Nov 16, 2010 6:30 am

This isn't good. I hope that they will patch up the driver signing vulnerability
KIS 2012
gusthebus
Global Moderator
 
Posts: 750
Joined: Fri Aug 13, 2010 10:47 pm
Location: St. Louis, Missouri
Has thanked: 70 times
Have thanks: 22 times
OS: Windows 7 Ultimate
Architecture: 64bit

Re: TLD4 rootkit

Postby Dieselman » Tue Nov 16, 2010 9:10 am

This is why you need to familarize yourself with every running process on your pc. So you can tell when something is not right. I know that I usually always have 58 processes running. I also look at Autoruns for any changes regularly.
Dieselman
 

Re: TLD4 rootkit

Postby GakunGak » Tue Nov 16, 2010 9:46 am

@Dieselman: Suppose you notice TLD4 process in Task Manager. Will he allow you to kill him via end task? If I understood correctly, process is resident and starts at boot.
Can it be removed in safe mode?
Avast 6 Free, Private Firewall, System Protect, MBAM Pro, Web Security Guard, Sandboxie Pro
Dieselman wrote:"But wait there's more!". Whatever.
GakunGak
Senior Contributor
 
Posts: 688
Joined: Tue Mar 17, 2009 10:08 am
Has thanked: 33 times
Have thanks: 21 times
OS: Windows 7 Ultimate
Architecture: 32bit

Re: TLD4 rootkit

Postby Dieselman » Tue Nov 16, 2010 11:00 am

I dont use Task Manager. I use Process Explorer but until I run into I am not exactly sure.
Dieselman
 

Re: TLD4 rootkit

Postby GakunGak » Tue Nov 16, 2010 12:48 pm

I use this, it can also unload service before ending a task, and also start/stop windows services, try it out:
http://www.tucows.com/preview/516579
Task Killer
Sometimes I can kill a process that I am unable with Task Manager or Process Hacker/Explorer
Avast 6 Free, Private Firewall, System Protect, MBAM Pro, Web Security Guard, Sandboxie Pro
Dieselman wrote:"But wait there's more!". Whatever.
GakunGak
Senior Contributor
 
Posts: 688
Joined: Tue Mar 17, 2009 10:08 am
Has thanked: 33 times
Have thanks: 21 times
OS: Windows 7 Ultimate
Architecture: 32bit

Re: TLD4 rootkit

Postby sss20 » Tue Nov 16, 2010 1:05 pm

Dieselman wrote:This is why you need to familarize yourself with every running process on your pc.

And have common sense....don;t run app. that are from an unkwon source or don't have digital sign.
Use a solid security and always be careful when you're browsing..don't go to unkwnon sites.
sss20
Master Contributor
 
Posts: 3358
Joined: Thu Jul 30, 2009 6:43 am
Has thanked: 132 times
Have thanks: 151 times
OS: Windows 7 Professional
Architecture: 64bit


Return to Rootkit Talk

Who is online

Users browsing this forum: No registered users and 1 guest

cron