A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #2352  by sww
 Thu Aug 26, 2010 11:40 am
EP_X0FF wrote:btw, IO filtering seems to be the same.
Thanks god :)
 #2354  by a_d_13
 Thu Aug 26, 2010 12:02 pm
Hello,

Thanks go to Fabian for the dropper :D
Attached is an archive containing all the files dropped by the infection, his dropper, and an offline dump of the MBR. The MBR contains a simple ROR decryption loop, so there is also a file "decrypted_mbr" with the encryption removed.

Thanks,
--AD
Attachments
Pass: infected
(205.68 KiB) Downloaded 194 times
 #2356  by EP_X0FF
 Thu Aug 26, 2010 12:04 pm
Software updated, gonna try to kill it with fixmbr :)
 #2359  by Meriadoc
 Thu Aug 26, 2010 12:08 pm
x64

tdsskiller doesn't detect

edit: HMP detects.

VM wasted by tdl :D
Last edited by Meriadoc on Thu Aug 26, 2010 12:39 pm, edited 2 times in total.
 #2360  by EP_X0FF
 Thu Aug 26, 2010 12:22 pm
I assume further improvements because this rootkit version is very easy to remove. And it is really buggy, I can't get real machines free from debuggers to work after infection, only after mbr recovery.
 #2361  by USForce
 Thu Aug 26, 2010 12:41 pm
EP_X0FF wrote:I assume further improvements because this rootkit version is very easy to remove. And it is really buggy, I can't get real machines free from debuggers to work after infection, only after mbr recovery.
totally agreed. Rootkit is simply bugged
 #2362  by EP_X0FF
 Thu Aug 26, 2010 1:03 pm
USForce wrote:
EP_X0FF wrote:I assume further improvements because this rootkit version is very easy to remove. And it is really buggy, I can't get real machines free from debuggers to work after infection, only after mbr recovery.
totally agreed. Rootkit is simply bugged
Dogma support please login for the bugreports, LOL
  • 1
  • 2
  • 3
  • 4
  • 5
  • 60