A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #2585  by EP_X0FF
 Wed Sep 01, 2010 2:02 pm
They closing Dogma Millions and stopping payments. This means TDL3 is going to history and they working on a new project likely. However this can be fake. Will see result in October.
 #2588  by Buster_BSA
 Wed Sep 01, 2010 2:21 pm
Jaxryley wrote:Sandboxie, Bufferzone, Returnil and VM's etc are OK for some malware samples but a lot are aware of such and won't run or only half run.
I want to see a malware being aware of Sandboxie when LOG_API.DLL and HideDriver are being used. ;)
 #2601  by Jaxryley
 Wed Sep 01, 2010 9:40 pm
Buster_BSA wrote: I want to see a malware being aware of Sandboxie when LOG_API.DLL and HideDriver are being used. ;)
With Sandboxie I meant the exploits that need to drop a rootkit.sys which Sandboxie doesn't allow.

Other than for rootkits Sandboxie/BSA/HideDriver is my main testing environment.
 #2620  by EP_X0FF
 Fri Sep 03, 2010 5:58 am
By the way, ESET antirootkit (ala SysInspector) is totally unable to detect any kind of working TDL3/4 as well as AV scanner, x64 version also.
"Vitalik" posted fake as always :)
  • 1
  • 15
  • 16
  • 17
  • 18
  • 19
  • 60