A forum for reverse engineering, OS internals and malware analysis 

Forum for announcements and questions about tools and software.
 #4076  by Meriadoc
 Tue Dec 21, 2010 7:58 am
Seems there was a recent update,

2010-12-16

http://free.antivirus.com/rootkit-buster

download
Filename: RootkitBuster_3.60.1016.zip
MD5 checksum: 88b29adec76a4703605efb10c54d3d83

someone's been busy

Image
Attachments
(6.71 KiB) Downloaded 34 times
 #4087  by a_d_13
 Tue Dec 21, 2010 2:19 pm
Hello,

Thank you for the information. I have updated the download link in the list of antirootkits.

Thanks,
--AD
 #4091  by Meriadoc
 Tue Dec 21, 2010 4:27 pm
new vm - tdl fail
Image Image

not expected
Image
 #4094  by nullptr
 Wed Dec 22, 2010 9:37 am
Actually TDL3 is one of the few things it will clean, but you need to reboot before scanning.
0xF84FD000 atapi_TM.sys 98304 bytes - original miniport infector.

0xF879A000 C:\WINDOWS\system32\drivers\i8042prt_TM.sys 53248 bytes - later TDL3
Note the driver name change after cure ;)

It detected sdra64, I can't remember what name that went by.
Apart from that, it's still more bluster than buster.
 #4102  by Meriadoc
 Wed Dec 22, 2010 4:13 pm
Mm my bad I should have verified it but had little time, which is why I probably forgot to reboot...thanks nullptr :)