Exetools

Exetools (https://forum.exetools.com/index.php)
-   General Discussion (https://forum.exetools.com/forumdisplay.php?f=2)
-   -   Best rootkit for win7? (https://forum.exetools.com/showthread.php?t=13044)

suddenLy 10-21-2010 17:45

Best rootkit for win7?
 
I'm wondering BEST rootkit exists on win7.

Have any idea? :confused:

sendersu 10-21-2010 18:25

Windows 7 64 does not allow every driver to get into kernel memory region due to a very strict digital signature check. If the driver has not been digitally signed, Windows won't allow it to be loaded.
So I guess you are rather asking about new modern way - a bootkit? ;)

Probably #1 is TDL3

Archer 10-27-2010 03:27

TDL x64 was found ITW for about a month ago.

JeRRy 10-27-2010 10:23

Nice quote , sendersu :P

http://www.prevx.com/blog/154/TDL-rootkit-x-goes-in-the-wild.html

STRELiTZIA 10-27-2010 15:02

_http://www.kernelmode.info/forum/viewtopic.php?f=16&t=19&start=660

Fyyre 10-30-2010 04:47

Quote:

Originally Posted by suddenLy (Post 69927)
I'm wondering BEST rootkit exists on win7.

Have any idea? :confused:

Best, in terms of what? TDL3 wins at being another bootkit/signing hack/patchguard kill... but is not exactly usable ;)

SLV 03-06-2011 21:07

Don't mix w7 and x64, w7x86 allows to load unsigned drivers, so many driver trojans use it as well.

Fyyre 03-08-2011 08:04

no mixing, no fun. besides... i patched that months ago.

-Fyyre

Quote:

Originally Posted by SLV (Post 71857)
Don't mix w7 and x64, w7x86 allows to load unsigned drivers, so many driver trojans use it as well.


SLV 03-08-2011 18:00

It's a dirty hack and can't be used in commercial (or malware lol) software because one day ms may publish a new version of system files and u will loose all ur customers (bots). The best way nowdays is to infect MBR or something not far from.

ch0pper 03-24-2011 08:53

probably the best for windows was Hacker defender back in the day.:D

but if you incorporate the stoned boot kit and take elements from Hacker defender you can have an awesome Windows 7 64 bit rootkit

http://www.stoned-vienna.com/

Molasar 03-25-2011 08:52

ch0pper: Have you seen sources for the TDL4 bootkit?


All times are GMT +8. The time now is 13:30.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX