TDL3 Rootkit

Discussion in 'Prevx Releases' started by Dark Star 72, Jan 16, 2010.

Thread Status:
Not open for further replies.
  1. Dark Star 72

    Dark Star 72 Registered Member

    Joined:
    May 27, 2007
    Posts:
    703
    A little while ago there was an interesting blog by Marco (Eraser) and comment here about Prevx being the only company able to detect this rootkit at the time although detection and removal wasn't incorporated into the Prevx3 version that was then available.
    With the proliferation of TDL3 and the newer variants of the TDL3/Alureon family does Prevx 3.0.5.50 now detect and remove these or is it still a case of requiring remote assistance to remove it?

    Edit: This is the link to the previous discussion

    https://www.wilderssecurity.com/showthread.php?t=258778&highlight=TDL3
     
    Last edited: Jan 16, 2010
  2. Triple Helix

    Triple Helix Webroot Product Advisor

    Joined:
    Nov 20, 2004
    Posts:
    12,014
    Location:
    Ontario, Canada
    Good Question!

    TH
     
  3. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    We're currently in the process of improving our cleanup of TDL3 (and similar threats) but are still just helping users on a case-by-case basis for now as we don't want to give out our new techniques to the mass public just yet :)

    We will definitely keep our users here and readers on our blog up-to-date with new interesting developments but right now we're working on a much more streamlined generic approach to defeat this new generation of threats which should put us significantly in front of where the malware authors are at the moment.

    Of course I'll divulge more information a bit later... but for now we're fairly tight lipped - no need to escalate the inevitable cat and mouse game any faster than it already is :)
     
  4. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
    pmed PH.
     
  5. Dark Star 72

    Dark Star 72 Registered Member

    Joined:
    May 27, 2007
    Posts:
    703
    Many thanks for the update Joe, interesting :thumb:
     
  6. EraserHW

    EraserHW Malware Expert

    Joined:
    Oct 19, 2005
    Posts:
    588
    Location:
    Italy
    TDL3 rootkit authors are quickly defeating every new public fix approach, they are really active in counteracting them by releasing every few days a new update of the rootkit
     
  7. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
    Sometimes several updates in a day!
     
  8. kasperking

    kasperking Registered Member

    Joined:
    Nov 21, 2008
    Posts:
    406
    well how effective is the real time protection of prevx in preventing the infection in the first place?
     
  9. PC__Gamer

    PC__Gamer Registered Member

    Joined:
    Dec 26, 2009
    Posts:
    526
    yep, my question too.

    the behaviour blocker should pick up on such a threat, surely?
     
  10. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Yes - at the moment we're blocking every variant we're aware of. We recently had a submission of two TDL3 variants we didn't automatically flag but have subsequently added a new rule which will block them generically in the future.

    As always, let us know if you come across anything new and we'll investigate it further! :)
     
  11. Hugger

    Hugger Registered Member

    Joined:
    Oct 27, 2007
    Posts:
    1,003
    Location:
    Hackensack, USA
    "Yes - at the moment we're blocking every variant we're aware of."

    What settings are you using?
    As is out of the box or have you increased the settings?
    Thanks.
     
  12. Fajo

    Fajo Registered Member

    Joined:
    Jun 13, 2008
    Posts:
    1,812
    I'm going to call you on this one Joe. So is every other AV Vendor. If you don't know about them you can't block them. ;)
     
  13. EraserHW

    EraserHW Malware Expert

    Joined:
    Oct 19, 2005
    Posts:
    588
    Location:
    Italy
    That's why technologies like heuristic are more and more developed :) They can assist you intercepting new unknown threats even without knowing them each one :)
     
  14. Threedog

    Threedog Registered Member

    Joined:
    Mar 20, 2005
    Posts:
    1,125
    Location:
    Nova Scotia, Canada
    I agree with you Eraser. The good old days of relying on signatures only is quickly fading into the past. Unfortunately, just as any any antimalware app is getting close to having all the answers, the malware authors change the questions.
     
  15. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    :D Precisely true - However, my response is just me being diplomatic. I can't be 100% sure we're finding every variant in existence but our heuristics have correctly latched onto every variant we've received so far :)
     
  16. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    12,883
    Location:
    Canada
    is prevx safeonline compatible with keyscrambler?
     
  17. JohnnyDollar

    JohnnyDollar Guest

    Is that with default settings? If not what settings are you using?
     
  18. Triple Helix

    Triple Helix Webroot Product Advisor

    Joined:
    Nov 20, 2004
    Posts:
    12,014
    Location:
    Ontario, Canada
    This is the way I always have it without problems!

    TH
     

    Attached Files:

  19. Threedog

    Threedog Registered Member

    Joined:
    Mar 20, 2005
    Posts:
    1,125
    Location:
    Nova Scotia, Canada
    Mine is configured the same as Triple Helix's. Max/Med/Med. I never have any problems.
     
  20. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,057
    Location:
    North Carolina
    agree. At the start setting it this high resulted in some FPs, but they have worked hard to correct that.
     
  21. Triple Helix

    Triple Helix Webroot Product Advisor

    Joined:
    Nov 20, 2004
    Posts:
    12,014
    Location:
    Ontario, Canada
    I can't remember the the last time I got a false positive with Prevx it's been ages :thumb::thumb:

    TH
     
  22. JohnnyDollar

    JohnnyDollar Guest

    Oh ok, I have been using medium on all settings. I'll try the high setting on AH and see how that is. If no fp then I may nudge it up to max.:thumb:
     
  23. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    5,829
    Location:
    Last Breath Farm
    I'm finally going the other way... nudging the settings down a notch, to Max/High/High. I've been running with Max across the board, but I finally decided to bring it down, especially after getting HitmanPro.exe fp's while running a HMP scan. And according to TH and Threedog, I should probably come down even more. :eek:
     
  24. Triple Helix

    Triple Helix Webroot Product Advisor

    Joined:
    Nov 20, 2004
    Posts:
    12,014
    Location:
    Ontario, Canada
    I'm going to try that also to see how it goes! ;)

    TH
     
  25. NAMOR

    NAMOR Registered Member

    Joined:
    May 19, 2004
    Posts:
    1,526
    Location:
    Arkham Asylum
Thread Status:
Not open for further replies.