Reply
Bot Obliterator
Quads
Posts: 13,259
Registered: ‎07-21-2008

Re: TDSSkiller / TDL4

I do find articles 

 

But I also find Malware to run and install on my Computer in the real world (Not VM), whether it's Rootkits like TDL3 / TDL4, worms, Rogues, Trojans........................

If the infection is downloading more Malware from somewhere I let it download everything that it wants. Once completed I then set about breaking the Malware piece by piece to allow other programs to run and remove all the files and registry entries etc.

 

Like this thread for a user.

 

http://community.norton.com/t5/Norton-Internet-Security-Norton/conime-virus/m-p/207475#M103235

 

Quads

Bot Obliterator
Quads
Posts: 13,259
Registered: ‎07-21-2008

Re: TDSSkiller / TDL4

TDL installers are still appearing that Norton does not detect once downloaded or just sitting on the Desktop.

 

They do have some sort of sense of humour this one is by Chuck Norris with the Firefox icon, pic below

 

6130i7D321E6DC1683DAE 

Quads

Super Spam Squasher
mo
Posts: 1,674
Registered: ‎08-18-2008

Re: TDSSkiller / TDL4

I wonder does Chuck Norris know he is now a Virus/TDL....:smileytongue: It could date the creator as Chucky boy was big in Videos in the 80s -90s

Cheers Mo
XP home,SP3
NIS2012
Bot Obliterator
Quads
Posts: 13,259
Registered: ‎07-21-2008
Bot Obliterator
Quads
Posts: 13,259
Registered: ‎07-21-2008

Re: TDSSkiller / TDL4

Bot Obliterator
Quads
Posts: 13,259
Registered: ‎07-21-2008

Re: TDL3 and NPE

Hahaha

 

On testing I infected with TDL3 /4 and ran Norton Power Eraser,  It detected the driver, but it also detected legit files so I don't know the actual reason for the detection or if it just happened to be a fuke in between the False Positives

 

NPE restarted the PC an preceeded to deleted or try and delete the driver and Controlset registry entry for it. Like Norton previously trying to or succeeding to delete the driver like "atapi.sys"

 

 


 <Remediate DateAndTime="Saturday, 26 June 2010 Time: 09:52">

- <Infections_Selected_For_Remediation>
- <DRIVERS Count="1">
- <Driver ID="1">
- <File_Information>
  <Path>D:\WINDOWS\system32\DRIVERS\intelppm.sys</Path> 
  <FileVersion><></FileVersion> 
  <ProductVersion><></ProductVersion> 
  <ProductName><></ProductName> 
  <Company><></Company> 
  <Copyrights><></Copyrights> 
  <MD5>27FDB47F3F2EFE36F72C0971A03406C0</MD5> 
  <SHA256>D2C269B6686A9B8769BB5546FC711FDE33FBA400 9B96863D241CD6B9D64506CB</SHA256> 
  <FileSize>36352 bytes</FileSize> 
  </File_Information>
- <SideEffects Count="2">
  <File>D:\WINDOWS\system32\DRIVERS\intelppm.sys</File> 
  <RegistryKey>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\intelppm</RegistryKey> 
  </SideEffects>
  </Driver>
  </DRIVERS>
  <SERVICES Count="0" /> 
  <PROCESSES Count="0" /> 
  <LAYERED_SERVICE_PROVIDERS Count="0" /> 
  <DESKTOP_SHORTCUTS Count="0" /> 
  <AUTORUN_FILES Count="0" /> 
  <STARTUP_ITEMS Count="0" /> 
  <BROWSER_HELPER_OBJECTS Count="0" /> 
  <BROWSER_TOOLBARS Count="0" /> 
  <BROWSER_PLUGINS Count="0" /> 
  <SHELL_EXTENSIONS Count="0" /> 
  <EXPLORER_PLUGINS Count="0" /> 
  <DIRECTORIES Count="0" /> 
  <FILES Count="0" /> 
  <SYSTEM_SETTINGS Count="0" /> 
  </Infections_Selected_For_Remediation>
  </Remediate>
- <RemediationStatusPostReboot DateAndTime="Saturday, 26 June 2010 Time: 09:54">
- <Infections_Remediated>
- <DRIVERS Count="1">
- <Driver ID="1">
- <File_Information>
  <Path>D:\WINDOWS\system32\DRIVERS\intelppm.sys</Path> 
  <FileVersion><></FileVersion> 
  <ProductVersion><></ProductVersion> 
  <ProductName><></ProductName> 
  <Company><></Company> 
  <Copyrights><></Copyrights> 
  <MD5>27FDB47F3F2EFE36F72C0971A03406C0</MD5> 
  <SHA256>D2C269B6686A9B8769BB5546FC711FDE33FBA400 9B96863D241CD6B9D64506CB</SHA256> 
  <FileSize><></FileSize> 
  </File_Information>
- <SideEffects Count="2" Status="Remediate_Failed">
  <File>D:\WINDOWS\system32\DRIVERS\intelppm.sys</File> 
  <RegistryKey>\REGISTRY\MACHINE\SYSTEM\CurrentCon trolSet\Services\intelppm</RegistryKey> 
  </SideEffects>

 


 

 

On checking I found that actually the driver had gone, So I placed it all back.

 

intelppm.sys = Intel Processor Driver

 

BSOD territory  as we know from people on the forum previously and why Norton won't remove the driver for ".........Tidserv!inf" or shouldn't, unless a definition has been added causing the removal problem again

 

If Malware that infects /patches legit system files etc.  is suspected, Tidserv is just one group, zeloaces is one other off the top of my head. it is not advised to use Norton Power Eraser to remove the types of infections as bigger problems can occur with removing drivers Windows needs.

 

Quads

 

 

Bot Obliterator
Quads
Posts: 13,259
Registered: ‎07-21-2008

Re: TDL3 and NPE

Symantec has tested NPE on TDL3 and NPE did detect the driver infected (I don't know which driver in this case).  NPE removed it and made the system (PC) unusable.

 

Quads

Bot Obliterator
Quads
Posts: 13,259
Registered: ‎07-21-2008

Re: TDL3 and TDSS Fixtool

TDL3 (+) and the Symantec free download "TDSS Fixtool"

 

It does "REPAIR" older TDL3 variant's, doesn't delete the file in question. If it's a newer variant at least the tool stops and does not attempt to instead delete the file even if it notifies that basically it can't repair the file.

 

9032iBE56060ECEBF82CC 

 

 

Better than causing a non bootable Windows.

 

Quads

Bot Obliterator
Quads
Posts: 13,259
Registered: ‎07-21-2008

Re: TDL3 and TDSS Fixtool

Boot.Tidserv, Tidserv.L  Bootkit

 

version 0.01, without x64 code (one dropper it seems), 
version 0.02 fully workable, (just few droppers)   buggy, can cause non booting XP
version 0.03 with changed infector (driver too), also few samples,   buggy, can cause non booting XP

 

Quads

Regular Contributor
Tywin7
Posts: 1,465
Registered: ‎09-02-2010

Re: TDL3 and TDSS Fixtool

Does TDDS tool detect latest TDDS?

Norton Internet Security 2011 , Windows 7 Home Premium 64 bit (Check if you are eligable for a FREE Norton upgrade)
Success is 10 percent inspiration and 90 percent perspiration.”--Thomas Alva Edison
I'm not a Symantec employee and my posts do not represent the views of Symantec.