New variant Alureon.K is spreading.
Blocks tools like aswMBR, TDSSKiller, GMER, etc.
Hooks at miniport level to hide sectors.
Has a watchdog that restores IRP_MJ_SCSI, StartIo pointers if changed; ala TDL3/4.
Loads from extra partition.
Protects both MBR and 'VBR' sector (to hide the extra partition).
Additional partition presumably is a VBR but its not (has NTFS marker, but has partition table as well).
This is what I could gather from infected system past hour.
Anyone has more info on this?
Erik Loman [HitmanPro]
SurfRight B.V. -