Rootkit TDL 3 (alias TDSS, Alureon)

Forum for analysis and discussion about malware.

Re: Rootkit TDL 3 (alias TDSS, Alureon)

Postby gjf » Wed Apr 14, 2010 10:39 am

STRELiTZIA wrote:Hi,
Updated for fun :)
TDL3+ Cleaner 1.1
Tested on Windows Xp Sp2 and Sp3
Working with "Copy/Restore" exploit...


Sorry, but it does not work! OK, details....

I have used VMWare 7.0.1 build-227600 with WinXP SP3 Pro and altest updates. I have performed initial scan by VBA32 to be sure the system is clean.
Infected.zip
. After that I have infected the system and reboot. Then perform the second scan by VBA32 to see that system is infected.
Initial.zip


So I ahve started the file and install the service. After starting the process the PC beeps one time so I have rebooted the system. During the booting the message "pci.sys file is absent" was shown and booting stopped. I have no idea what's wrong with pci.sys (another driver was infected, it is clear from logs) and what's wrong at all.

So - no good! :(

AFAIK DrWeb cureIt utility cures TDL3, but there are a number of bugs with controllers other than ATA (especially SCSI, SATA etc). Another bug is BSOD with TrueCrypt partitions no matter is infection present or not.

So still have to wait. :roll:
You do not have the required permissions to view the files attached to this post.
gjf
 
Posts: 106
Joined: Mon Mar 15, 2010 10:23 am
Reputation point: 6

Re: Rootkit TDL 3 (alias TDSS, Alureon)

Postby nullptr » Wed Apr 14, 2010 12:36 pm

The TDL3+Cleaner Test Release from last week works fine as long as you identify the correct driver. The TDL3+ Cleaner 1.1 seems to delete a driver causing boot failure.
xp sp3 in Virtual PC.
nullptr
 
Posts: 35
Joined: Sun Mar 14, 2010 6:35 am
Reputation point: 55

Re: Rootkit TDL 3 (alias TDSS, Alureon)

Postby djpnuemo » Wed Apr 14, 2010 3:14 pm

nullptr wrote:The TDL3+Cleaner Test Release from last week works fine as long as you identify the correct driver. The TDL3+ Cleaner 1.1 seems to delete a driver causing boot failure.
xp sp3 in Virtual PC.


i had the same problem on a test machine (non-virtual).
djpnuemo
 
Posts: 10
Joined: Mon Mar 15, 2010 3:12 pm
Reputation point: 0

Re: Rootkit TDL 3 (alias TDSS, Alureon)

Postby STRELiTZIA » Wed Apr 14, 2010 5:17 pm

Thanks for reports :)
Attached Test Release with New option to manually add the second infected driver name.
using "Gmer" to get the second infected driver name.
You do not have the required permissions to view the files attached to this post.
User avatar
STRELiTZIA
 
Posts: 15
Joined: Sun Mar 14, 2010 7:02 am
Reputation point: 55

Re: Rootkit TDL 3 (alias TDSS, Alureon)

Postby djpnuemo » Wed Apr 14, 2010 6:49 pm

STRELiTZIA wrote:Thanks for reports :)
Attached Test Release with New option to manually add the second infected driver name.
using "Gmer" to get the second infected driver name.


appreciate the update.

i ran it and entered the second driver found, tcpip.sys, and now cannot browse. done all normal tcp/ip resets/reinstalls to no avail. infection is gone though! ;)
djpnuemo
 
Posts: 10
Joined: Mon Mar 15, 2010 3:12 pm
Reputation point: 0

Re: Rootkit TDL 3 (alias TDSS, Alureon)

Postby gjf » Wed Apr 14, 2010 8:14 pm

Don't know - too many moves. The simpliest way is to boot up ERD Commander and scan for a non-valid files :)
gjf
 
Posts: 106
Joined: Mon Mar 15, 2010 10:23 am
Reputation point: 6

Re: Rootkit TDL 3 (alias TDSS, Alureon)

Postby InsaneKaos » Wed Apr 14, 2010 10:08 pm

Recovery Console and a batch-script mostly can do the whole job. I've atteched a batchfile that should find and remove TDL in two steps with the RC.
You do not have the required permissions to view the files attached to this post.
InsaneKaos
 
Posts: 12
Joined: Fri Apr 09, 2010 1:47 pm
Location: Germany
Reputation point: 0

Re: Rootkit TDL 3 (alias TDSS, Alureon)

Postby gjf » Wed Apr 14, 2010 10:17 pm

InsaneKaos, did you test your script on infected systems? I don't believe simple fc command will reveal rootkit. AFAIK TDL3 gives original unpatched file during file operations, doesn't it?
gjf
 
Posts: 106
Joined: Mon Mar 15, 2010 10:23 am
Reputation point: 6

Re: Rootkit TDL 3 (alias TDSS, Alureon)

Postby InsaneKaos » Wed Apr 14, 2010 10:28 pm

I've tested it over 10 times, for me it works.

FC will reveal it. The script copies all sys-files to Windows\DriversToCkeck while you are logged on RC. Then do the FC stuff against the driver in System32\Drivers while in normal mode. If it found a difference, it will copy the driver from System32\Drivers to Windows\ and replace it when you reboot again into RC. (The Driver in System32\Drivers is infected, but TDL will reflect a clean copy, so you can use it).
InsaneKaos
 
Posts: 12
Joined: Fri Apr 09, 2010 1:47 pm
Location: Germany
Reputation point: 0

Re: Rootkit TDL 3 (alias TDSS, Alureon)

Postby gjf » Wed Apr 14, 2010 10:33 pm

Oh, I've missed RC moment! In this case sure it will work. Thanks.
What about hypotetic situation when TDL3 infects system driver, but not from Microsoft one?
gjf
 
Posts: 106
Joined: Mon Mar 15, 2010 10:23 am
Reputation point: 6

PreviousNext

Return to Malware

Who is online

Users browsing this forum: No registered users and 2 guests