Wrong confirmation ID
  • Email
  • Favorite
  • Download
  • Embed
  • Private Content

Defeating x64: Modern Trends of Kernel-Mode Rootkits

by Aleksandr Matrosov on Sep 25, 2011

  • 6,150 views

Versions of Microsoft Windows 64 bits were considered resistant against kernel mode rootkits because integrity checks performed by the system code. However, today there are examples of malware that use...

Versions of Microsoft Windows 64 bits were considered resistant against kernel mode rootkits because integrity checks performed by the system code. However, today there are examples of malware that use methods to bypass the security mechanisms Implemented. This presentation focuses on issues x64 acquitectura security, specifically in the signature policies kernel mode code and the techniques used by modern malware to sauté. We analyze the techniques of penetration of the address space of kernel mode rootkits used by modern in-the-wild: - Win64/Olmarik (TDL4) - Win64/TrojanDownloader.Necurs (rootkit dropper) - NSIS / TrojanClicker.Agent.BJ (rootkit dropper) special attention is given to bootkit Win64/Olmarik (TDL4) for being the most prominent example of a kernel mode rootkit aimed at 64-bit Windows systems. Detail the remarkable features of TDL4 over its predecessor (TDL3/TDL3 +): the development of user mode components and kernel mode rootkit techniques used to bypass the HIPS, hidden and system files as bootkit functionality. Finally, we describe possible approaches to the removal of an infected computer and presents a free forensics tool for the dump file system hidden TDL.

Accessibility

Categories

Tags

ekoparty rootkits bootkits

Upload Details

Uploaded via SlideShare as Microsoft PowerPoint

Usage Rights

© All Rights Reserved

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel

21 Embeds 1,173

http://amatrosov.blogspot.com 837
http://paper.li 156
http://www.redditmedia.com 65
http://tweetedtimes.com 36
https://twitter.com 20
http://a0.twimg.com 11
http://www.linkedin.com 9
http://www.securitylab.ru 6
http://translate.google.com 5
http://twitter.com 5
http://us-w1.rockmelt.com 4
http://translate.googleusercontent.com 4
http://www.slideshare.net 3
http://www.slideshare.net 3
http://amatrosov.blogspot.in 2
http://amatrosov.blogspot.fr 2
http://amatrosov.blogspot.de 1
http://amatrosov.blogspot.co.uk 1
http://amatrosov.blogspot.se 1
http://amatrosov.blogspot.com.au 1
http://amatrosov.blogspot.com.ar 1

More...

Statistics

Favorites
1
Downloads
179
Comments
0
Embed Views
1,173
Views on SlideShare
4,977
Total Views
6,150
Post Comment
Edit your comment Cancel

Defeating x64: Modern Trends of Kernel-Mode Rootkits — Presentation Transcript