A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #6144  by Julian
 Sun May 01, 2011 6:15 pm
PX5 wrote:Hang it up folks, dont a single cleaner work on the current infection, no need boasting this cleaner does or this cleaner doesnt.
It seems Kaspersky 2012 can clean it. At least Hitman Pro didn't find infected driver stack after cleaning with KIS.
 #6146  by CodeAddiction
 Sun May 01, 2011 7:35 pm
Hello,
PX5 said:
Even in 2 live cases, attempts to boot from a Windows CD failed, I even tried booting from the UBCD4Win and it failed as well, so they have figured a way to monitor/hook cd-roms/DVD
Using both my BartPE and Win7PE bootable CDs on a freshly infected box, this was not the case for me. Successfully booted into RAM environment.
 #6148  by rossetoecioccolato
 Sun May 01, 2011 9:24 pm
If this was actually caused by TDL4 then this would be a very big advancement in rootkit technology.
Not if they are flashing the firmware of the optical drive. Have seen this for a few years with BIOS-based infection. No reason it could not be applied to bootkit as well. Interesting to know which optical drive it is. If the drive is infected it may brick up when you try to read the firmware.
 #6157  by InsaneKaos
 Mon May 02, 2011 2:49 pm
Okay, I've tested aswMBR, HitmanPro, TDSSKiller against TDL4 on Windows XP 32bit SP3 and Windows 7 32bit SP1, both with the miniport driver atapi.sys. (VirtualBox)
  • aswMBR: Was able to detect and also to remove TDL4. It is necessary that aswMBR detect it as TDL4, otherwise the "FIX" -button will not be available.
  • Hitman Pro: Was not able to detect it as TDL4 (It detected TDL3 instead) and gave me no options to remove it.
  • TDSSKiller: Detected and removed TDL4 without any problems.
Greetings, Kaos.
 #6158  by erikloman
 Mon May 02, 2011 3:19 pm
InsaneKaos wrote:Okay, I've tested aswMBR, HitmanPro, TDSSKiller against TDL4 on Windows XP 32bit SP3 and Windows 7 32bit SP1, both with the miniport driver atapi.sys. (VirtualBox)
  • aswMBR: Was able to detect and also to remove TDL4. It is necessary that aswMBR detect it as TDL4, otherwise the "FIX" -button will not be available.
  • Hitman Pro: Was not able to detect it as TDL4 (It detected TDL3 instead) and gave me no options to remove it.
  • TDSSKiller: Detected and removed TDL4 without any problems.
Greetings, Kaos.
Did you use the beta? It should list $MBR as infected. Click next to remove.
 #6159  by nullptr
 Mon May 02, 2011 4:04 pm
erikloman wrote: Did you use the beta? It should list $MBR as infected. Click next to remove.
Do you need the paid version of HMP to detect it? With the 30 day free licence, I couldn't even get HMP to detect it.
I can confirm InsaneKaos' findings regarding latest TDSSKiller 2.5.0.0 and aswMBR.
  • 1
  • 42
  • 43
  • 44
  • 45
  • 46
  • 60