Rootkit TDL3

ChrisJakarta
StarLounger
Posts: 97
Joined: 05 Feb 2010, 11:06
Location: Jakarta, Indonesia

Rootkit TDL3

Post by ChrisJakarta »

It seems that the problems encountered when updating Windows with the MS10-015 update is (was) caused by a nasty called 'rootkit TFL3' (see BSOD after MS10-015? TDL3 authors "apologize"). This article states "...only really few specific anti-rootkits are able to detect the infection when active".

Searching for information about this nasty has not been very helpful. I can find no clear way of determining if I am infected (other than by updating MS10-015 - and it seems even that has been corrected by the nastyware disseminator), how to avoid infection, or the cure if required. Is this something I should be worried about?

Actually I am a little surprised that the response of the experts seems to be "OK we've found the cause of the problem with MS10-015, so that's alright', and even apparent appreciation to the nastyware disseminator for correcting the problem. :sad:

Chris

User avatar
StuartR
Administrator
Posts: 12601
Joined: 16 Jan 2010, 15:49
Location: London, Europe

Re: Rootkit TDL3

Post by StuartR »

ChrisJakarta wrote:...apparent appreciation to the nastyware disseminator for correcting the problem...
I think this was intended as irony,
StuartR


ChrisJakarta
StarLounger
Posts: 97
Joined: 05 Feb 2010, 11:06
Location: Jakarta, Indonesia

Re: Rootkit TDL3

Post by ChrisJakarta »

StuartR wrote:
ChrisJakarta wrote:...apparent appreciation to the nastyware disseminator for correcting the problem...
I think this was intended as irony,
Stuart,

Yes, I'm sure you are right. But for those less well-informed who were worried about the problems with MS10-015, and perhaps (like me) not clear about what rootkits really are (they don't often appear in the malware descriptions), the impression given by these communications is that the problem has been solved by a patch in some offending code. Whereas, unless I am much mistaken, this poorly-described nasty remains a big (and increasing) problem.

Chris

User avatar
StuartR
Administrator
Posts: 12601
Joined: 16 Jan 2010, 15:49
Location: London, Europe

Re: Rootkit TDL3

Post by StuartR »

ChrisJakarta wrote:... this poorly-described nasty remains a big (and increasing) problem...
I agree, very nasty, and I also agree that far too few people understand the issue. That is why there are so many millions of PCs in botnets.
StuartR


User avatar
John Gray
PlatinumLounger
Posts: 5405
Joined: 24 Jan 2010, 08:33
Location: A cathedral city in England

Re: Rootkit TDL3

Post by John Gray »

Has anyone come across an antiRootkit product that will detect and remove the TDL3 rootkit, all variants?
John Gray

"(or one of the team)" - how your appointment letter indicates you won't be seeing the Consultant...

User avatar
HansV
Administrator
Posts: 78391
Joined: 16 Jan 2010, 00:14
Status: Microsoft MVP
Location: Wageningen, The Netherlands

Re: Rootkit TDL3

Post by HansV »

Hitman Pro 3.5 is mentioned as the one tool that can do that. (Free download, unlimited free scanning, 30 days free malware removal)
Best wishes,
Hans

ChrisJakarta
StarLounger
Posts: 97
Joined: 05 Feb 2010, 11:06
Location: Jakarta, Indonesia

Re: Rootkit TDL3

Post by ChrisJakarta »

HansV wrote:Hitman Pro 3.5 is mentioned as the one tool that can do that. (Free download, unlimited free scanning, 30 days free malware removal)
Yeh, Hans, I saw that. But how does one know that these programs are bona-fide, and not another spoof that adds more malware?

Chris

User avatar
HansV
Administrator
Posts: 78391
Joined: 16 Jan 2010, 00:14
Status: Microsoft MVP
Location: Wageningen, The Netherlands

Re: Rootkit TDL3

Post by HansV »

Hitman Pro has been around for a while, and it's a reputable tool. It uses the online scanning engines from several well-known anti-malware companies such as Avira (AntiVir) and Eset (NOD32).
Best wishes,
Hans