A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #1528  by USForce
 Wed Jul 14, 2010 11:33 pm
EP_X0FF wrote:Cannot reproduce :?

I made quick test.

Clean machine, from repository, XP SP3.

infected machine with this sample, file: termdd.sys, rebooted.
installed tdss remover, rebooted when asked
scanned with tdss remover, it detected tdl3, "fixed it", rebooted.

After reboot tdl3 is successfully removed.
Actually I've only run a quick test, maybe I could be wrong. Though I'm starting to be tired of TDL3 bugs :x :roll:
 #1543  by nullptr
 Thu Jul 15, 2010 11:56 am
For anyone that cares to know or doesn't know ;)
MSE 1.0.1963.0, esage TDSS remover and Strelitzia's tool will all remove latest TDL 3 with a little help from RKu.
(They're the only ones I've tested that at some stage have worked)

- Remove Load Image callback notification (not necessary for MSE)
- remove user mode NtxxxVirtualMemory code hooks from explorer.exe and svchost.exe

Run remover or Quick Scan for MSE
 #1553  by SecConnex
 Thu Jul 15, 2010 6:38 pm
I know that HIPS would probably be evaded, but what if it is paired with MSE, and then tested against TDL3?
 #1566  by Meriadoc
 Fri Jul 16, 2010 12:28 pm
The Case of TDL3 Rootkit http://northsecuritylabs.blogspot.com/2 ... otkit.html
Let us check out the new facilities of Hypersight Rootkit Detector using a sample of TDL3 rootkit. This epic rootkit was a nightmare for virus analysts recently.
System requirements:
* Processor: Intel with VT-x support
* Operating system: Windows XP x86, Windows Server 2003 x86, Windows Vista x86, Windows 7 x86 with PAE enabled
Uninstall Hypersight Rootkit Detector in Safe Mode
Known issues
* Virtual machine images (VMware, VirtualBox) must be stopped when monitoring is turned on
* Windows Aero is not supported at present time

Download here : http://northsecuritylabs.com/download_new.aspx
scroll down press Download button.
 #1569  by nullptr
 Fri Jul 16, 2010 3:14 pm
Microsoft Security Essentials Version: 1.0.1963.0
Antimalware Client Version: 2.1.6805.0
Engine Version: 1.1.6004.0
Antivirus definitions: 1.87.23.0
Antispyware definitions: 1.87.23.0
Successfully removing latest TDL 3.
 #1570  by Meriadoc
 Fri Jul 16, 2010 6:45 pm
Will the initial Security Essentials install update with an already active TDL3?..without an update SE will do nothing at all?
pumpin' iron
pumpin' iron
pumpin' iron
pumpin' iron
CompanyName
C21 H23 NO5
lol :)
 #1573  by nullptr
 Sat Jul 17, 2010 5:26 am
Meriadoc wrote:Will the initial Security Essentials install update with an already active TDL3?..without an update SE will do nothing at all?
As expected, MSE is unable to update due to TDL3 user mode hooks. To work around it, the easiest way is to remove hooks from wuauclt.exe, explorer.exe and svchost.exe. Then MSE will update and remove infection.
 #1574  by Meriadoc
 Sat Jul 17, 2010 7:03 am
nullptr wrote:
Meriadoc wrote:Will the initial Security Essentials install update with an already active TDL3?..without an update SE will do nothing at all?
As expected, MSE is unable to update due to TDL3 user mode hooks. To work around it, the easiest way is to remove hooks from wuauclt.exe, explorer.exe and svchost.exe. Then MSE will update and remove infection.
Thanks :) ;)just wanted to point that out.
  • 1
  • 25
  • 26
  • 27
  • 28
  • 29
  • 40