Professional Documents
Culture Documents
18
Rustock.B Rootkit SYSENTER_EIP hook
19
TDL3 Rootkit ATAPI IRP hooks
20
TDL3 Rootkit ATAPI IRP hooks
21
TDL3 Rootkit ATAPI IRP hooks
22
TDL3 Rootkit Shared Memory structure (Kernel-/User mode)
23
TDL3 Rootkit Shared Memory structure (Kernel-/User mode)
24
TDL3 Rootkit Shared Memory structure (Kernel-/User mode)
25
TDL3 Rootkit TDL mini FS (file system)
26
TDL3 Rootkit Traces in the system worker threads
27
TDL3 Rootkit Traces in the system worker threads
28
TDL4 Rootkit Finding TDL4 with its invalid device object
29
TDL4 Rootkit ATAPI DriverStartIO hook
30
TDL4 Rootkit ATAPI DriverStartIO hook
31
TDL4 Rootkit Finding the Kernel Callback with a Windbg script
32
TDL4 Rootkit Dropper dumping after TDL4 infection (before
reboot)
33
TDL4 Rootkit Dumping injected user mode payload
34
TDL4 Rootkit Finding inline hooks in user mode payload
35
Questions?
36