Reply
Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: TDL3 and TDSS Fixtool

What is the sceenshot above of and what it means??

 

And this page http://community.norton.com/t5/Norton-Internet-Security-Norton/Auto-Protect-Description-Help/m-p/297...

 

Quads

Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: TDL3 and TDSS Fixtool

Looks like Boot.Tidserv (TDL4) Bootkit will cause patched / cracked versions of Windows 7 to become non bootable :smileyvery-happy: :smileyvery-happy: 

 

Quads

Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

TDL evolving

TDL4 is now being seen using or trying to use the Task Scheduler Privilege Escalation vulnerability as that appeared as seen with W32.Stuxnet 

 

Quads  

Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: TDL evolving

TDL4 has a version change, from 0.15 to 0.169

 

Can still cause this major problem

 

 


 

On running the installer  The  Computer shuts down or restarts. The computer will not POST or enter bios setup, will only show bios logo and then blinking cursor in top left no matter boot device selected.

 


 

 

Quads

Regular Contributor
BanMidou
Posts: 721
Registered: ‎12-17-2010

Re: TDL evolving

Is Norton able to detect?

 

 

"Or" has the version change made it harder to detect!

Midou

Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: TDL evolving

There are still FakeAV (Rogues) appearing with the TDL2 like PRAGMA, _VOID, H8SRT group.

 

Looks like more in the Rogues like HDD Rescue, Windows Recovery and the defragmenters.

 

Quads

Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: TDL evolving

Looks like Microsoft is trying to combat TDL4.03 on x64 systems.

 

http://www.microsoft.com/technet/security/advisory/2506014.mspx

 

Quads

Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: TDL evolving

Looks like there is a new TDL4 that gets around the Microsoft patch, and stops TDSSkiller from completeing the scan.  Other tools may not detect the newbie or cannot cure it.

 

Quads

Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008
Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: TDL evolving

Infected the PC with a new sample of Tidserv / TDSS /TDL4

 

 

I downloaded the FixTDSS tool for the most up to date version from the site http://www.symantec.com/security_response/writeup.jsp?docid=2010-090608-3309-99 It did run the scan but "No Infection Found" was the result.
TDSSkiller from that download site got stuck at 80% on startup.
New TDL4 TDSSkiller stuck.jpg
The updated TDSSkiller (not from the download page, not updated with new version yet) was able to run, detect and cure the new samples.


TDSSkiller 2.5.0.0.jpg

 

 

 

One sample though places a randomly named file with registry key so that when the MBR gets cured on the restart (or after using a CD/DVD to fix) on the startup the MBR gets reinfected again, and again and again. The registry key and /or random file has to be dealt with first, before dealing with the MBR, otherwise you would be going around in circles somewhat.

 

Quads