A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #3809  by Meriadoc
 Wed Dec 01, 2010 11:21 pm
Hello Jaxryley,

vmware+xpsp3

TDL 4.03
cfg.ini
[main]
version=0.03
aid=40849
sid=0
builddate=4096
rnd=823518204
[inject]
*=cmd.dll
* (x64)=cmd64.dll
[cmd]
srv=hxxps://nl6fa53.com/;hxxps://li1i16b0.com/;hxxps://zz87jhfda88.com/;hxxps://n16fa53.com/;hxxps://01n02n4cx00.cc/;hxxps://lj1i16b0.com/
wsrv=hxxp://ijmgwareh0use.com/;hxxp://cljkcpixelabn.com/;hxxp://thynksn0taeg.com/;hxxp://jimgwareh0use.com/;hxxp://bestbanerget.com/;hxxp://pxlratator.com/
psrv=hxxp://cikh71ynks66.com/;hxxp://clkh71yhks66.com/
version=0.15
 #3819  by EP_X0FF
 Thu Dec 02, 2010 12:57 pm
Non informative post removed. There is no need to do virustotal links posting thread. Further posts of this kind without actual samples attached will be removed as well.
Additionally if you want to thank somebody for something it is better to use specially built-in reputation system.
 #3828  by AaLl86
 Fri Dec 03, 2010 2:55 pm
Hi Jaxryley!
Tested on Win7 X64 Vmware, TDL4 0.03 Ok!

Now i have only to find a way to debug it.... This damn faked Kdcom.dll!!!
Regards, Andrea
Jaxryley wrote:Sample which BSOD's my XP VM.

patch.exe - 4/43 - Sophos - Mal/TDSSPack-Z - MD5 : 92dc11c5b405058f4258cba91ebbd6db
http://www.virustotal.com/file-scan/rep ... 1291202768
patch.rar
 #3839  by nullptr
 Sat Dec 04, 2010 2:07 pm
install.exe
[main]
version=0.03
...
srv=hxxps://rukkeianno.com/;hxxps://kangojim1.com/;hxxps://lkaturi71.com/;hxxps://neywrika.in/;hxxps://86b6b6b6.com/
wsrv=hxxp://skolewcho.com/;hxxp://jikdooyt0.com/;hxxp://swltcho81.com/;hxxp://switcho81.com/;hxxp://rammyjuke.com/
psrv=hxxp://cri71ki813ck.com/
version=0.15
 #3852  by egomoo
 Mon Dec 06, 2010 1:07 am
I have write a small tool to check which driver has been random infected in Windows PE.

You shoud run the tool in the PE as in normal mode the rootkit has given a safe dirver replace the infected one.

http://www.safereturner.com/bug/CheckTDL.exe

It is useful if a new one that TDSSKiller do not detect in normal mode.

the scan reprot
http://www.virustotal.com/file-scan/rep ... 1291362952
  • 1
  • 31
  • 32
  • 33
  • 34
  • 35
  • 60