Since people are posting here about blog articles from Symantec and Prevx, I might as well post a link to a blog post of a few days ago about Hitman Pro detecting 64-bit TDL3 (sorry no removal yet, but this variant is not yet widespread so we have some time to write removal code :roll: )
http://hitmanpro.wordpress.com/2010/08/ ... 3-rootkit/
There is also a movie illustrating the infection and detection:
http://www.youtube.com/watch?v=rMS-kxbo5fc
I would like to thank Fabian for the dropper and EP_X0FF for this excellent forum.
http://hitmanpro.wordpress.com/2010/08/ ... 3-rootkit/
There is also a movie illustrating the infection and detection:
http://www.youtube.com/watch?v=rMS-kxbo5fc
I would like to thank Fabian for the dropper and EP_X0FF for this excellent forum.
Erik Loman [HitmanPro]
SurfRight B.V. - www.surfright.com
SurfRight B.V. - www.surfright.com