![]() |
|
#1
|
||||
|
||||
|
The TDL3 rootkit is currently a large issue for nearly all anti virus programs.
Hitman Pro 3.5 build 79 is able to detect and remove the TDL3 rootkit. More information: Hitman Pro: http://www.surfright.nl/en/home/pres...s-tdl3-rootkit Prevx: http://www.prevx.com/blog/139/Tdss-r...s-the-net.html Remove malware.com: http://remove-malware.com/malware/ma...hes-atapi-sys/ Technical information: http://rootbiez.blogspot.com/2009/11...-lets-put.html |
|
#2
|
|||
|
|||
|
Well ... beside the fact that you don't detect all variants I have access to, cleaning an infection results in a nice BSOD loop on boot ... my guess is because you deleted my (infected) disk driver:
|
|
#3
|
||||
|
||||
|
Quote:
Anyway, could you provide some details about the infected system (especially the driver file that was infected by TDSS/Alureon)? Last edited by markloman : November 30th, 2009 at 12:09 PM. |
|
#4
|
||||
|
||||
|
Quote:
Dr. Web CureIT already detects and cures TLD3, Kaspersky has defs (which also disinfect and cure) in for public testing before general release too: http://forum.kaspersky.com/index.php?showtopic=147016 |
|
#5
|
|||
|
|||
|
No it isn't a standard disk driver and is therefore not protected by the WFP. It's the one installed by VMware (vmscsi.sys). You may want to rethink your cleaning process. Since I have seen different other TLD3 infected drivers that don't belong to Windows as well.
|
|
#6
|
||||
|
||||
|
Quote:
Well what is the chance that real people are going to be using VM's...or bothering to disinfect "infected" ones... rolling back to the last snapshot is probably a lot more pain free and easier. VM's often behave differently to a physical computer. |
|
#7
|
||||
|
||||
Quote:
I am curious though why the driver was deleted in your VMware session (assuming it was deleted). Over the past weekend we have detected well over 450 infections and none of them resulted in a BSOD. Perhaps you have a different variant of TDL3? Can you please send the dropper to erik (at] surfright [dot) nl ? |
|
#8
|
|||
|
|||
|
Quote:
I just sent you the infected drivers as well as the dropper by mail. Last edited by Anar : November 30th, 2009 at 01:33 PM. |
|
#9
|
||||
|
||||
|
Over here it also is tracking Hookcentre.sys
__________________
Join us at the KasperskyClub www.twitter.com/kaspersky_Club www.facebook.com/kaspersky |
|
#10
|
||||
|
||||
|
We have updated Hitman Pro 3.5 to build 80. It will now also handle TDL3 infections on systems with non standard third party disk drivers. Here are the release notes:
Build 80 (2009-12-01)
|
|
#11
|
||||
|
||||
|
Hi;
HitmanPro Build 79 did not update to Build 80. It scanned and is still with "Build 79". When will the update be available? Regards! |
|
#12
|
||||
|
||||
|
Quote:
Although I am curious into why your version did not update. The update procedure should start when the splash window appears. A progress bar should indicate the download of the update. What part of this does not occur on your PC ? |
|
#13
|
|||
|
|||
|
I can confirm that build 80 handles infections of third party disk drivers correctly now. Thanks for the fix
. |
|
#14
|
||||
|
||||
|
Quote:
I'm great to hear that! Well done, Hitman Pro team!
__________________
Zemana AntiLogger Avast! Internet Security 8.0 |
|
#15
|
||||
|
||||
|
When I go to the link that Erik put here I see version 79, not 80...
|
|
#16
|
||||
|
||||
|
Quote:
|
|
#17
|
||||
|
||||
|
Quote:
I see build 80 http://www.surfright.nl/en/hitmanpro Maybe this is better link ^^
__________________
Zemana AntiLogger Avast! Internet Security 8.0 |
|
#18
|
||||
|
||||
|
There is no 64bit version of .80? It downloads still the 78 version, even when I see that .80 is announced on the page...
|
|
#19
|
||||
|
||||
|
Quote:
Last edited by erikloman : December 1st, 2009 at 05:51 PM. |
|
#20
|
||||
|
||||
|
So we have to wait almost a year?
I guess you meant December. |
|
#21
|
||||
|
||||
|
Great work to Anar with the testing and follow-up, and Erik and team for keeping a cool head with the program update.
__________________
Fine Art Landscape Photography
|
|
#22
|
||||
|
||||
|
Hitman Pro build 85 now removes TDL3.22 (also known as TDL3+).
The TDL3 rootkit infects the hard disk driver, usually atapi.sys or iastor.sys, so that it is loaded when Windows boots. Whereas Dr.Web and TDSSKiller successfully removed previous versions of TDL3, only Hitman Pro build 85 is currently able to remove the newer TDL3.22. You can PM if you are interested in a sample. |
|
#23
|
||||
|
||||
|
I worked on a pc earlier this afternoon that had the new TDL3+ rootkit. HMP detected the infected atapi.sys and replaced it with a clean copy on reboot.
|
|
#24
|
||||
|
||||
|
Quote:
http://www.wilderssecurity.com/showp...&postcount=836
__________________
Webroot SecureAnywhere Complete |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|