The above blog version used is one of the earlier versions.
Here is a GMER log showing the TDL3 atapi.sys suspicious modification entry of a later version
GMER 1.0.15.15252 - http://www.gmer.net
Rootkit scan 2009-12-03 16:21:49
Windows 5.1.2600 Service Pack 3
Running: zioycjt9.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\kwwyyaob.sys
Shortened to fit by Quads
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device -> \Driver\atapi \Device\Harddisk0\DR0 84A8D618
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification
---- EOF - GMER 1.0.15 ----
Borrowed from another thread.
The Version of TDL3 I played with didn't even show that.
Quads





