A forum for reverse engineering, OS internals and malware analysis 

Forum for announcements and questions about tools and software.
 #891  by ConanTheLibrarian
 Mon Apr 26, 2010 1:33 pm
Sorry, I should have done that. I assumed you would have this sample already. I got it from this forum a little while ago. It was posted just b4 the new tdl3 came out. Norman TDSS Removal says:

TDSS/TDL3 Rootkit Detected
Warning - Rootkit disinfection failed. See log for details.

Attached is log and sample.
Attachments
(946 Bytes) Downloaded 40 times
pass: infected
(81.39 KiB) Downloaded 40 times
 #901  by lars
 Tue Apr 27, 2010 3:53 pm
windbreaker11 wrote:Sorry, I should have done that. I assumed you would have this sample already. I got it from this forum a little while ago. It was posted just b4 the new tdl3 came out. Norman TDSS Removal says:

TDSS/TDL3 Rootkit Detected
Warning - Rootkit disinfection failed. See log for details.

Attached is log and sample.
Thanks. This is actually a much older sample... v3.15 ... almost jurassic :lol:
So... it had nothing to do with the changes introduced recently with the random driver infection.

I have fixed the issue and there will be a new version out real soon.

UPDATE: It has now been released: http://download.norman.no/public/Norman ... leaner.exe

If you come across any other samples causing issues, I'm always happy to have a look.
 #1279  by EP_X0FF
 Tue Jun 15, 2010 2:49 pm
Hi,

I can confirm problems :)

NTC is looping with detection, removal. Rootkit not removed.
Infected driver - termdd.sys

Regards.