A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #16135  by kmd
 Fri Oct 19, 2012 8:25 am
rkhunter wrote:At least for me, Matrosov post looks nice. He also told that HiddenFsReader was updated for dump files of this rootkit version.

his post full of self arrogance, misses details and contains simple lame stuff like mentioned there unpacking and tdi driver research. is it good? nope i do not buy this. hiddenfsreader? dump tdlfs container and rc4 it with key from boot record. aside from this he clearly copypasted most of info from there. lets say - would he post this without discussion here? no. just like in old times idiot from prevx copypasted whole thread about tdl4 in his blogpost.
 #16136  by sww
 Fri Oct 19, 2012 8:35 am
kmd wrote:his post full of self arrogance, misses details and contains simple lame stuff like mentioned there unpacking and tdi driver research.
I think that most of the good researches in ESET were done by Eugene Rodionov.If i'm not missing something ;)
 #16137  by rkhunter
 Fri Oct 19, 2012 8:43 am
kmd wrote:
rkhunter wrote:At least for me, Matrosov post looks nice. He also told that HiddenFsReader was updated for dump files of this rootkit version.

his post full of self arrogance, misses details and contains simple lame stuff like mentioned there unpacking and tdi driver research. is it good? nope i do not buy this. hiddenfsreader? dump tdlfs container and rc4 it with key from boot record. aside from this he clearly copypasted most of info from there. lets say - would he post this without discussion here? no. just like in old times idiot from prevx copypasted whole thread about tdl4 in his blogpost.
Of course all we have an our opinion...but is it correct point of view that "don't write anything at all"? Of course all we can to discuss any paper or something else, but seems this is criticism. If you can do something better, let's do, nope?
 #16139  by thisisu
 Fri Oct 19, 2012 8:50 am
rkhunter wrote:At least for me, Matrosov post looks nice.
Agreed.

Even though I don't understand what I'm looking at, I thought the comparisons between old version and new version with screenshots should be helpful to anyone wanting to get better understanding. He had at least 3 sets of these which was nice IMO.
 #16140  by EP_X0FF
 Fri Oct 19, 2012 8:51 am
So maybe mr. Matrosov will register there and post something? :) Enough lurking around. Even for corporate bussiness it's looking strange.
  • 1
  • 11
  • 12
  • 13
  • 14
  • 15