http://www.infosecurity-magazine.com...-more-to-come/"One of the most striking features of TDL4 is its ability to load its kernel-mode driver on systems with an enforced kernel-mode code signing policy (64-bit versions of Microsoft Windows Vista and 7) and perform kernel-mode hooks with kernel-mode patch protection policy enabled. This makes TDL4 a powerful weapon in the hands of cybercriminals", adds the paper.






LinkBack URL
About LinkBacks
Reply With Quote