TDL3 Rootkit

Discussion in 'Prevx Releases' started by Dark Star 72, Jan 16, 2010.

Thread Status:
Not open for further replies.
  1. Dark Star 72

    Dark Star 72 Registered Member

    A little while ago there was an interesting blog by Marco (Eraser) and comment here about Prevx being the only company able to detect this rootkit at the time although detection and removal wasn't incorporated into the Prevx3 version that was then available.
    With the proliferation of TDL3 and the newer variants of the TDL3/Alureon family does Prevx 3.0.5.50 now detect and remove these or is it still a case of requiring remote assistance to remove it?

    Edit: This is the link to the previous discussion

    https://www.wilderssecurity.com/showthread.php?t=258778&highlight=TDL3
     
    Last edited: Jan 16, 2010
  2. Triple Helix

    Triple Helix Specialist

    Good Question!

    TH
     
  3. PrevxHelp

    PrevxHelp Former Prevx Moderator

    We're currently in the process of improving our cleanup of TDL3 (and similar threats) but are still just helping users on a case-by-case basis for now as we don't want to give out our new techniques to the mass public just yet :)

    We will definitely keep our users here and readers on our blog up-to-date with new interesting developments but right now we're working on a much more streamlined generic approach to defeat this new generation of threats which should put us significantly in front of where the malware authors are at the moment.

    Of course I'll divulge more information a bit later... but for now we're fairly tight lipped - no need to escalate the inevitable cat and mouse game any faster than it already is :)
     
  4. Meriadoc

    Meriadoc Registered Member

    pmed PH.
     
  5. Dark Star 72

    Dark Star 72 Registered Member

    Many thanks for the update Joe, interesting :thumb:
     
  6. EraserHW

    EraserHW Malware Expert

    TDL3 rootkit authors are quickly defeating every new public fix approach, they are really active in counteracting them by releasing every few days a new update of the rootkit
     
  7. Meriadoc

    Meriadoc Registered Member

    Sometimes several updates in a day!
     
  8. kasperking

    kasperking Registered Member

    well how effective is the real time protection of prevx in preventing the infection in the first place?
     
  9. PC__Gamer

    PC__Gamer Registered Member

    yep, my question too.

    the behaviour blocker should pick up on such a threat, surely?
     
  10. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Yes - at the moment we're blocking every variant we're aware of. We recently had a submission of two TDL3 variants we didn't automatically flag but have subsequently added a new rule which will block them generically in the future.

    As always, let us know if you come across anything new and we'll investigate it further! :)
     
  11. Hugger

    Hugger Registered Member

    "Yes - at the moment we're blocking every variant we're aware of."

    What settings are you using?
    As is out of the box or have you increased the settings?
    Thanks.
     
  12. Fajo

    Fajo Registered Member

    I'm going to call you on this one Joe. So is every other AV Vendor. If you don't know about them you can't block them. ;)
     
  13. EraserHW

    EraserHW Malware Expert

    That's why technologies like heuristic are more and more developed :) They can assist you intercepting new unknown threats even without knowing them each one :)
     
  14. Threedog

    Threedog Registered Member

    I agree with you Eraser. The good old days of relying on signatures only is quickly fading into the past. Unfortunately, just as any any antimalware app is getting close to having all the answers, the malware authors change the questions.
     
  15. PrevxHelp

    PrevxHelp Former Prevx Moderator

    :D Precisely true - However, my response is just me being diplomatic. I can't be 100% sure we're finding every variant in existence but our heuristics have correctly latched onto every variant we've received so far :)
     
  16. jmonge

    jmonge Registered Member

    is prevx safeonline compatible with keyscrambler?
     
  17. JohnnyDollar

    JohnnyDollar Guest

    Is that with default settings? If not what settings are you using?
     
  18. Triple Helix

    Triple Helix Specialist

    This is the way I always have it without problems!

    TH
     

    Attached Files:

  19. Threedog

    Threedog Registered Member

    Mine is configured the same as Triple Helix's. Max/Med/Med. I never have any problems.
     
  20. trjam

    trjam Registered Member

    agree. At the start setting it this high resulted in some FPs, but they have worked hard to correct that.
     
  21. Triple Helix

    Triple Helix Specialist

    I can't remember the the last time I got a false positive with Prevx it's been ages :thumb::thumb:

    TH
     
  22. JohnnyDollar

    JohnnyDollar Guest

    Oh ok, I have been using medium on all settings. I'll try the high setting on AH and see how that is. If no fp then I may nudge it up to max.:thumb:
     
  23. Page42

    Page42 Registered Member

    I'm finally going the other way... nudging the settings down a notch, to Max/High/High. I've been running with Max across the board, but I finally decided to bring it down, especially after getting HitmanPro.exe fp's while running a HMP scan. And according to TH and Threedog, I should probably come down even more. :eek:
     
  24. Triple Helix

    Triple Helix Specialist

    I'm going to try that also to see how it goes! ;)

    TH
     
  25. NAMOR

    NAMOR Registered Member

Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice