SecurityGarden

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, February 18, 2010

Alureon/TDSS Rootkit and Restart Issues After Installing MS10-015

Posted on 7:28 AM by Unknown
In an update regarding the restart issues after Security Bulletin MS10-015 (KB977165) is installed, Microsoft reported that the reboot occurs because the system is infected with malware, specifically what Microsoft refers to as the Alureon rootkit. The Alureon rootkit is more commonly known in the security community as the TDSS/Tidserv rootkit.

Although instructions are available for using the Recovery Console to uninstall KB977165, that method does not remove the rootkit, leaving the system severely compromised. To illustrate the type of control over the computer the rootkit has, as reported by Marco Giuliani in the Prevx Blog, the TDSS/Tidserv rootkit authors have already pushed an update taking care of the MS10-015 BSOD (blue screen of death):
"All TDL3 droppers have been server-side rebuilt every day during November, December, January and February. This allowed the authors to break weak signatures or badly written generic detection routines. Actually this was the only effective obstacle, otherwise only really few specific anti-rootkits are able to detect the infection when active.

Even the rootkit itself has been updated and armored, to defense itself against the attack of a number of anti-rootkit specific tools. It's funny following the full story of the rootkit, because it looks like a nice chess game between security vendors and malware authors. It's one of the few times you can see a team of rootkit writers counteracting almost in real time to security vendors.

We already knew the rootkit is able to infect a system driver and to filter every disk I/O request by applying a strong filtering mechanism. Now the rootkit added a watchdog thread able to prevent any change to the service registry key related to the infected driver.By doing so, it is able to block some basic cleanup tools.

Another self defense feature added to the rootkit is that no one is anymore able to get a handle to the infected driver file. By doing so, the rootkit is preventing some cleanup tools to read the content of the file. Prior versions of the rootkit allowed to read the infected file, though they were showing the clean copy of it. This trick was used by some security tools to recover the original clean copy of the file to restore."

If you have encountered this reboot issue after installing MS10-015, it is highly recommended that the you back up important files and completely restore the system from a cleanly formatted disk. For assistance, see these Microsoft Help & How-to articles:
  • Back up your files
  • Install, reinstall, or uninstall Windows
To determine if your computer is infected, run a full-system scan with an up-to-date antivirus product such as Microsoft Security Essentials, the Windows Live OneCare safety scanner or ESET Online Scanner.

In the event you are unable to locate the Windows XP CD or DVD and do not have the recovery console installed, free assistance is available form Microsoft by calling 1-866-PCSafety (1-866-727-2338) or from https://consumersecuritysupport.microsoft.com. International customers can find local support contact numbers here: http://support.microsoft.com/common/international.aspx.

Although with a rootkit re-installing the operating system is the recommended safe method for recovery, an alternative option if you have lost the installation media is the Kaspersky TDSS Killer tool.

References:
  • Kaspersky TDSS Killer tool
  • MSRC: Update - Restart Issues After Installing MS10-015 and the Alureon Rootkit
  • Prevx: BSOD after MS10-015? TDL3 authors "apologize"

Clubhouse Tags: Clubhouse, Microsoft, Windows, Security, Updates, Vulnerabilities, Information



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...
Email ThisBlogThis!Share to XShare to Facebook
Posted in Microsoft, Security, Updates, Vulnerabilities, Windows | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Security Bulletin Advance Notice for August, 2013
    On Tuesday, August 13, 2013, Microsoft is planning to release eight (8) bulletins.  Three of the bulletins are identified as Critical with f...
  • Critical Out-of-Band Update Released for MS10-046
    Microsoft released Security Bulletin MS10-046 out-of-band to address a vulnerability in Windows. The security update is identified as crit...
  • Hotmail Security to Protect and Recover Your Account
    Time and time again I see reports from Hotmail users who have lost control of their e-mail account.  As explained by Walter Harp, Director o...
  • Long Awaited Outlook.com Calendar Refresh Rollout
    The long-awaited Outlook.com calendar refresh has been released and is in the process of being rolled out. Because the servers are grouped i...
  • Microsoft Security Advisory 2269637 Released
    Microsoft released Security Advisory 2269637 which relates to a remote attack vector to a class of vulnerabilities affecting applications t...
  • Oracle Java Update
    Oracle released the Java SE 7u40 today.  In addition to bug fixes and enhancements, the update includes the following: advanced monitoring ...
  • Adobe Reader Security Updates
    Adobe has released security updates for Adobe Reader and Acrobat XI (11.0.03) and earlier versions for Windows and Macintosh. Adobe identif...
  • Advance Notice: Security Updates for Java SE
    The Sun Security Blog published the following update announcement: "On November 3, 2009, Sun will release the following security update...
  • Adobe Flash Player and Adobe Air Security Updates
    Adobe released updates to both Adobe Flash Player and Adobe AIR to correct a critical vulnerability in both products. From the Adobe Securi...
  • Waledac Botnet Takedown
    The Waledac botnet had the capability of sending 1.5 billion spam e-mails per day. During a three-week period in December, 2009, approximat...

Categories

  • Adobe
  • Advisory
  • Amero
  • AntiVirus
  • Apple
  • Ask
  • AVG
  • Bing
  • Browser
  • Child Safety
  • email
  • ESET
  • Ethics
  • Facebook
  • Firefox
  • Firewall
  • FixIt
  • Fraud
  • General
  • Google
  • Hotmail
  • IE10
  • IE6
  • IE7
  • IE8
  • IE9
  • Java
  • Lavasoft
  • malware
  • Microsoft
  • Microsoft Apps
  • Mozilla
  • MVP
  • NCSAM
  • Office
  • Office 2007
  • Office 2010
  • Opera
  • Outlook.com
  • Phishing
  • Privacy
  • safety
  • Search
  • Security
  • Service Pack
  • SkyDrive
  • Skype
  • Software
  • SP1
  • sp2
  • SP3
  • Spotlight
  • Sumatra
  • tutorial
  • UAC
  • Updates
  • Vulnerabilities
  • Windows
  • Windows 7
  • Windows 8
  • Windows Live
  • Windows Live OneCare
  • Windows Vista
  • Windows XP
  • WinPatrol

Blog Archive

  • ►  2013 (93)
    • ►  October (2)
    • ►  September (8)
    • ►  August (9)
    • ►  July (5)
    • ►  June (8)
    • ►  May (7)
    • ►  April (15)
    • ►  March (9)
    • ►  February (16)
    • ►  January (14)
  • ►  2012 (98)
    • ►  December (7)
    • ►  November (6)
    • ►  October (11)
    • ►  September (5)
    • ►  August (10)
    • ►  July (8)
    • ►  June (12)
    • ►  May (7)
    • ►  April (12)
    • ►  March (6)
    • ►  February (6)
    • ►  January (8)
  • ►  2011 (130)
    • ►  December (8)
    • ►  November (10)
    • ►  October (7)
    • ►  September (12)
    • ►  August (9)
    • ►  July (6)
    • ►  June (13)
    • ►  May (14)
    • ►  April (13)
    • ►  March (15)
    • ►  February (10)
    • ►  January (13)
  • ▼  2010 (146)
    • ►  December (10)
    • ►  November (15)
    • ►  October (19)
    • ►  September (15)
    • ►  August (14)
    • ►  July (8)
    • ►  June (19)
    • ►  May (5)
    • ►  April (11)
    • ►  March (6)
    • ▼  February (14)
      • Celebrating Freedomlist!
      • Waledac Botnet Takedown
      • How-to: Reduce Vulnerability to Drive-by Downloads
      • Adobe Download Manager Security Update
      • To Bruno Knaapen: God Speed
      • Alureon/TDSS Rootkit and Restart Issues After Inst...
      • Adobe Flash Player and Adobe Air Security Updates
      • Update - Restart Issues After Installing MS10-015
      • Windows XP Restart Issues After Installing MS10-015
      • Microsoft Security Advisory (977377)
      • February 2010 Security Bulletin Release
      • Windows 7 RC Expiration Approaches
      • February 2010 Bulletin Release Advance Notification
      • Security Advisory 980088 Released
    • ►  January (10)
  • ►  2009 (33)
    • ►  December (11)
    • ►  November (11)
    • ►  October (11)
Powered by Blogger.

About Me

Unknown
View my complete profile