Author Topic: Reports Of Unbootable Machines After 2/09/10 Ms Updates  (Read 2484 times)

0 Members and 1 Guest are viewing this topic.

Offline negster22

  • Global Moderator
  • Gold Member
  • Posts: 1919
    • Secure Computer Solutions
Re: Reports Of Unbootable Machines After 2/09/10 Ms Updates
« Reply #15 on: February 23, 2010, 10:53:29 PM »
Not sure if everyone is aware of this revelation, but the presence of a TDL3 aka TDSS rootkit infection  was what was causing the affected systems to become unbootable after installation of  the MS10-015 update.  Apparently, the rootkit driver used a hardcoded address method to calculate its Windows kernel entry points.  Since MS10-015 updated the OS kernel, the addresses the rootkit code referenced were no longer valid, resulting in BSODs.

In effect, the update was a TDSS detector, though not a very friendly one!

http://www.prevx.com/blog/143/BSOD-after-MS-TDL-authors-apologize.html

Quote
Most of those users were angry with Microsoft, but the problem this time is not related to Microsoft. Indeed a number of the users affected by this BSOD was infected by TDL3/TDSS rootkit.

More exactly, TDL3 rootkit looks incompatible with MS10-015 update. This is the cause of the BSOD. Problem resides in the lazyness of rootkit writers when writing the driver infection routine.
Microsoft MVP - Consumer Security 2006 - 2011
BITS n PC's

Offline quietman7

  • Microsoft® MVP
  • Malware Removal Mentors
  • Silver Member
  • Posts: 1078
Re: Reports Of Unbootable Machines After 2/09/10 Ms Updates
« Reply #16 on: February 24, 2010, 06:58:30 AM »
Rootkit Authors Issue Patch For Critical Bug

Hackers update rootkit causing Windows blue screens
Quote
Resolve conflict with Microsoft update so users don't notice infection.

Hackers behind the rootkit responsible for crippling Windows machines after users installed a Microsoft security patch have updated their malware so that it no longer crashes systems, researchers confirmed today....

Microsoft readies new rootkit detection tool in light of Windows XP patching problems
Microsoft MVP - Consumer Security 2007-2013