Giter Site home page Giter Site logo

TDL and logs leaved behind about tdl HOT 1 CLOSED

hfiref0x avatar hfiref0x commented on May 30, 2024
TDL and logs leaved behind

from tdl.

Comments (1)

hfiref0x avatar hfiref0x commented on May 30, 2024

TDL does not log anything anywhere except in the console window output.

The only certificate this vboxdrv.sys uses is in virtual box driver itself.

If vboxdrv.sys was removed from disk and all registry entries removed then only possible leftovers are:

  1. eventlog (which is ridiculous)

  2. kernel pool (this vbox does not properly free kernel memory afaik)

  3. MmUnloadedDrivers (it has limited capacity and updates every time new driver loaded/unloaded)

  4. named objects it may create during work and not deleted at driver unload

  5. and 3) no credible 100% verdict, because driver file can be already deleted and they cannot calculate and compare hash

  6. raises a chance of protection driver bugchecks and no 100% credible verdict

  7. afaik there are no such objects in this vboxdrv version

If the protection driver was loaded before TDL it will be able to log and intercept any load driver attempt, and ban driver load by for (simple) example file hash which will be calculated from registry callback filter on ImagePath value of hardcoded VBox key when SCM/Native will try to install driver.

I'm afraid this is not TDL issue. TDL was never designed to be against any 3rd party software protection drivers, only against Windows itself.

from tdl.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.