DragonMaster Jay wrote:Shall we call this x64 version of TDSS, TDL4?Well the I/O filtering is the same, the watchdog is the same, the device 'layering' is the same, the encrypted file system is the same and TDL3's internal configuration is the same. Just the loading is different. Instead of infecting a system driver it now uses the MBR. Also it is not x64 only, this new variant also infects MBR on x86 (same dropper).
Seems by that TDSSKiller log, they have gone ahead and named it TDL4.
Also, this is a somewhat new infection routine to directly infect the MBR, instead of an actual system file.
But I agree we should give this a name. Perhaps TDL3mbr? I suggest we let EP_X0FF decide how we should address this variant.
Erik Loman [HitmanPro]
SurfRight B.V. - www.surfright.com
SurfRight B.V. - www.surfright.com