Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old November 30th, 2009, 11:27 AM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,137
Default Latest update of Hitman Pro removes TDL3 rootkit

The TDL3 rootkit is currently a large issue for nearly all anti virus programs.
Hitman Pro 3.5 build 79 is able to detect and remove the TDL3 rootkit.

More information:

Hitman Pro: http://www.surfright.nl/en/home/pres...s-tdl3-rootkit

Prevx: http://www.prevx.com/blog/139/Tdss-r...s-the-net.html

Remove malware.com: http://remove-malware.com/malware/ma...hes-atapi-sys/

Technical information: http://rootbiez.blogspot.com/2009/11...-lets-put.html
  #2  
Old November 30th, 2009, 11:48 AM
Anar Anar is offline
Infrequent Poster
 
Join Date: Sep 2009
Posts: 31
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

Well ... beside the fact that you don't detect all variants I have access to, cleaning an infection results in a nice BSOD loop on boot ... my guess is because you deleted my (infected) disk driver:

Name:  Windows XP Professional-2009-11-30-17-45-23.png
Views: 8317
Size:  7.4 KB
  #3  
Old November 30th, 2009, 12:01 PM
markloman's Avatar
markloman markloman is offline
Developer
 
Join Date: Jan 2005
Posts: 71
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

Quote:
Originally Posted by Anar
Well ... beside the fact that you don't detect all variants I have access to, cleaning an infection results in a nice BSOD loop on boot ... my guess is because you deleted my (infected) disk driver:
Thanks for posting. What specific driver are you referring to? It can't be a standard Windows driver (like atapi.sys) since Hitman Pro does *not* remove files that are protected by eg. Windows File Protection (WFP). In stead, it uses a new technique to 'replace' the infected file with a clean and safe version (that was eg. still on the system). If a safe file was not found, the infection remains (Hitman Pro doesn't make any changes).
Anyway, could you provide some details about the infected system (especially the driver file that was infected by TDSS/Alureon)?

Last edited by markloman : November 30th, 2009 at 12:09 PM.
  #4  
Old November 30th, 2009, 12:24 PM
Baz_kasp's Avatar
Baz_kasp Baz_kasp is offline
Frequent Poster
 
Join Date: May 2008
Location: London
Posts: 593
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

Quote:
Originally Posted by erikloman
The TDL3 rootkit is currently a large issue for nearly all anti virus programs.
Hitman Pro 3.5 build 79 is able to detect and remove the TDL3 rootkit.

More information:

Hitman Pro: http://www.surfright.nl/en/home/pres...s-tdl3-rootkit

Prevx: http://www.prevx.com/blog/139/Tdss-r...s-the-net.html

Remove malware.com: http://remove-malware.com/malware/ma...hes-atapi-sys/

Technical information: http://rootbiez.blogspot.com/2009/11...-lets-put.html



Dr. Web CureIT already detects and cures TLD3, Kaspersky has defs (which also disinfect and cure) in for public testing before general release too: http://forum.kaspersky.com/index.php?showtopic=147016
  #5  
Old November 30th, 2009, 12:27 PM
Anar Anar is offline
Infrequent Poster
 
Join Date: Sep 2009
Posts: 31
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

No it isn't a standard disk driver and is therefore not protected by the WFP. It's the one installed by VMware (vmscsi.sys). You may want to rethink your cleaning process. Since I have seen different other TLD3 infected drivers that don't belong to Windows as well.
  #6  
Old November 30th, 2009, 12:29 PM
Baz_kasp's Avatar
Baz_kasp Baz_kasp is offline
Frequent Poster
 
Join Date: May 2008
Location: London
Posts: 593
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

Quote:
Originally Posted by Anar
No it isn't a standard disk driver and is therefore not protected by the WFP. It's the one installed by VMware (vmscsi.sys). You may want to rethink your cleaning process. Since I have seen different other TLD3 infected drivers that don't belong to Windows as well.


Well what is the chance that real people are going to be using VM's...or bothering to disinfect "infected" ones... rolling back to the last snapshot is probably a lot more pain free and easier. VM's often behave differently to a physical computer.
  #7  
Old November 30th, 2009, 12:58 PM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,137
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

Quote:
Originally Posted by Anar
No it isn't a standard disk driver and is therefore not protected by the WFP. It's the one installed by VMware (vmscsi.sys). You may want to rethink your cleaning process. Since I have seen different other TLD3 infected drivers that don't belong to Windows as well.
The statement about whether the file must belong to WFP is not entirely true. When the pre-infected driver is signed it is also not deleted but queued for replacement by a white driver. If a replacement cannot be found (either from disk or Windows CD), the infection remains.

I am curious though why the driver was deleted in your VMware session (assuming it was deleted). Over the past weekend we have detected well over 450 infections and none of them resulted in a BSOD.

Perhaps you have a different variant of TDL3? Can you please send the dropper to erik (at] surfright [dot) nl ?
  #8  
Old November 30th, 2009, 01:21 PM
Anar Anar is offline
Infrequent Poster
 
Join Date: Sep 2009
Posts: 31
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

Quote:
Originally Posted by erikloman
The statement about whether the file must belong to WFP is not entirely true. When the pre-infected driver is signed it is also not deleted but queued for replacement by a white driver.
For a more real life example ... Hitman just "removed" iaStor.sys (Intel Storage Driver) of my physical test box that got infected by TDL3. Result is again a BSOD on boot.

I just sent you the infected drivers as well as the dropper by mail.

Last edited by Anar : November 30th, 2009 at 01:33 PM.
  #9  
Old November 30th, 2009, 01:53 PM
Sjoeii's Avatar
Sjoeii Sjoeii is offline
Very Frequent Poster
 
Join Date: Aug 2006
Location: 52°18'51.59"N + 4°56'32.13"O
Posts: 1,240
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

Over here it also is tracking Hookcentre.sys
  #10  
Old December 1st, 2009, 12:08 PM
markloman's Avatar
markloman markloman is offline
Developer
 
Join Date: Jan 2005
Posts: 71
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

We have updated Hitman Pro 3.5 to build 80. It will now also handle TDL3 infections on systems with non standard third party disk drivers. Here are the release notes:

Build 80 (2009-12-01)
  • Fixed a problem removing TDL3 rootkit infection from systems with specific third party drivers.
  • As of build 79, Hitman Pro is digitally signed with a new Microsoft Authenticode certificate.
  #11  
Old December 1st, 2009, 12:59 PM
Dundertaker's Avatar
Dundertaker Dundertaker is offline
Frequent Poster
 
Join Date: Oct 2009
Location: Land of the Mer Lion
Posts: 366
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

Hi;

HitmanPro Build 79 did not update to Build 80. It scanned and is still with "Build 79". When will the update be available?

Regards!
  #12  
Old December 1st, 2009, 01:10 PM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,137
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

Quote:
Originally Posted by Dundertaker
Hi;

HitmanPro Build 79 did not update to Build 80. It scanned and is still with "Build 79". When will the update be available?

Regards!
If the automatic update fails you can always download the latest version here: www.hitmanpro.com/downloads

Although I am curious into why your version did not update. The update procedure should start when the splash window appears. A progress bar should indicate the download of the update. What part of this does not occur on your PC ?
  #13  
Old December 1st, 2009, 03:18 PM
Anar Anar is offline
Infrequent Poster
 
Join Date: Sep 2009
Posts: 31
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

I can confirm that build 80 handles infections of third party disk drivers correctly now. Thanks for the fix .
  #14  
Old December 1st, 2009, 03:23 PM
LagerX's Avatar
LagerX LagerX is offline
Frequent Poster
 
Join Date: Apr 2008
Posts: 248
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

Quote:
Originally Posted by Anar
I can confirm that build 80 handles infections of third party disk drivers correctly now. Thanks for the fix .

I'm great to hear that!
Well done, Hitman Pro team!
__________________
Zemana AntiLogger
Avast! Internet Security 8.0
  #15  
Old December 1st, 2009, 03:28 PM
Edwin024's Avatar
Edwin024 Edwin024 is offline
Frequent Poster
 
Join Date: Nov 2004
Posts: 999
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

When I go to the link that Erik put here I see version 79, not 80...
  #16  
Old December 1st, 2009, 03:53 PM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,137
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

Quote:
Originally Posted by Edwin024
When I go to the link that Erik put here I see version 79, not 80...
Oops, forgot to update page on the website. The download always points to the latest though, even if the web page states it is an older previous version.
  #17  
Old December 1st, 2009, 03:54 PM
LagerX's Avatar
LagerX LagerX is offline
Frequent Poster
 
Join Date: Apr 2008
Posts: 248
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

Quote:
Originally Posted by Edwin024
When I go to the link that Erik put here I see version 79, not 80...

I see build 80
http://www.surfright.nl/en/hitmanpro
Maybe this is better link ^^
__________________
Zemana AntiLogger
Avast! Internet Security 8.0
  #18  
Old December 1st, 2009, 05:01 PM
Edwin024's Avatar
Edwin024 Edwin024 is offline
Frequent Poster
 
Join Date: Nov 2004
Posts: 999
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

There is no 64bit version of .80? It downloads still the 78 version, even when I see that .80 is announced on the page...
  #19  
Old December 1st, 2009, 05:19 PM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,137
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

Quote:
Originally Posted by Edwin024
There is no 64bit version of .80? It downloads still the 78 version, even when I see that .80 is announced on the page...
x64 release is November Decemter 4th.

Last edited by erikloman : December 1st, 2009 at 05:51 PM.
  #20  
Old December 1st, 2009, 05:23 PM
Edwin024's Avatar
Edwin024 Edwin024 is offline
Frequent Poster
 
Join Date: Nov 2004
Posts: 999
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

So we have to wait almost a year? I guess you meant December.
  #21  
Old December 1st, 2009, 07:05 PM
Saraceno's Avatar
Saraceno Saraceno is offline
Very Frequent Poster
 
Join Date: Mar 2008
Posts: 2,395
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

Great work to Anar with the testing and follow-up, and Erik and team for keeping a cool head with the program update.
__________________
Fine Art Landscape Photography
  #22  
Old January 15th, 2010, 06:14 PM
erikloman's Avatar
erikloman erikloman is offline
Developer
 
Join Date: Jun 2009
Location: Hengelo, The Netherlands
Posts: 1,137
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

Hitman Pro build 85 now removes TDL3.22 (also known as TDL3+).

The TDL3 rootkit infects the hard disk driver, usually atapi.sys or iastor.sys, so that it is loaded when Windows boots.

Whereas Dr.Web and TDSSKiller successfully removed previous versions of TDL3, only Hitman Pro build 85 is currently able to remove the newer TDL3.22.

You can PM if you are interested in a sample.
  #23  
Old January 15th, 2010, 07:18 PM
EliteKiller's Avatar
EliteKiller EliteKiller is offline
Very Frequent Poster
 
Join Date: Jan 2007
Location: TX
Posts: 1,123
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

I worked on a pc earlier this afternoon that had the new TDL3+ rootkit. HMP detected the infected atapi.sys and replaced it with a clean copy on reboot.
  #24  
Old January 15th, 2010, 07:26 PM
PC__Gamer's Avatar
PC__Gamer PC__Gamer is offline
Frequent Poster
 
Join Date: Dec 2009
Posts: 526
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

Quote:
Originally Posted by erikloman
Hitman Pro build 85 now removes TDL3.22 (also known as TDL3+).

The TDL3 rootkit infects the hard disk driver, usually atapi.sys or iastor.sys, so that it is loaded when Windows boots.

Whereas Dr.Web and TDSSKiller successfully removed previous versions of TDL3, only Hitman Pro build 85 is currently able to remove the newer TDL3.22.

You can PM if you are interested in a sample.
erik, drwebs beta has been able to remove all versions of TDL3 for some time, including the new versions, their support told me it will be released in an update to everyone (non-beta) in the next week or so.

http://www.wilderssecurity.com/showp...&postcount=836
__________________
Webroot SecureAnywhere Complete
  #25  
Old January 15th, 2010, 07:32 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Latest update of Hitman Pro removes TDL3 rootkit

Quote:
TDL3.22 (also known as TDL3+)
newer version out
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:08 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums