A few days ago guys from MMPC reported about rootkit [backdoor] called VirTool:WinNT/Exforel.A.
Review has included information in terms of network communication. But rootkit also contains some internal noteworthy features. First of all, startup processes from context of trusted services.exe. This is done with help of shellcode which injected into services.
Code injection:
Shellcode logic:
Another interesting feature of rootkit - method with help of which it do pages of process writable.
Pages translation scheme:
Undocumented kernel objects offsets table: