windbreaker11 wrote:Ok, but there is a new atapi infecting root out there that behaves like TDL3, except replacing atapi.sys even in Recovery Console doesn't fix. When you load windows, atapi.sys is infected again. I have only the leads in Gmer to tell me this. I have yet to get a sample of it yet because I was unable to neuralize it and I work remotely. Has there been any recent TDL3 activity? Any knowledge of this new behavior?
Hey, I think the malware I encountered today was something like this.
esagelabs tdss remover didn't work!
TDL3 Razor didn't work.
screen shot:
the two hidden library in the processes were from a installation of microsoft antispyware that I removed earlier.
I restarted the machine and performed the same gmer scan.
The hidden modules went away but the atapi.sys modification still remains.
I was working on this machine remotely, they are sending it to me because of a blue screen.
will update in the future.