'Indestructible' Virus TDL-4. Guess who's got it!

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

Post Reply
User avatar
Iroscato
Jedi Council Member
Posts: 2360
Joined: 2011-02-07 03:04pm
Location: Great Britain (It's great, honestly!)

'Indestructible' Virus TDL-4. Guess who's got it!

Post by Iroscato »

An almost indestructible virus called TDL-4 has been making the rounds in the internet, and it's infected millions of pcs. And yeah, I've got it. I've blasted it with every anti virus program I've got to no avail, so I'm just going to reset the damn thing to factory default and have done with it. I just wanted to give people a heads-up about it, it's almost unremovable, and it assaults you with adware and spyware every time you use Google.
I'm 99% sure this is what I've got...


http://news.yahoo.com/indestructible-td ... 41405.html
..A researcher at security software firm Kaspersky Labs has uncovered a sophisticated botnet threat that already controls more than 4.5 million Windows-based PCs around the world, with nearly one-third of all infected machines located in the United States. Moreover, there is reason to believe that the latest strain of TDSS uncovered this week -- which commands the infected PCs to run malware programs -- will be able to evolve over time.
According to Kaspersky researcher Sergey Golovanov, the new TDSS strain is the most sophisticated cybersecurity threat facing PC users today. It's even designed to delete other malicious programs not associated with the TDSS botnet, to eliminate the competition as well as ensure that PC users remain unaware that their machines are infected.

The malicious software uses a range of methods to evade detection, and employs encryption to facilitate communication between its bots and the botnet command-and-control center, Golovanov wrote in a Securelist posting. "TDSS also has a powerful rootkit component, which allows it to conceal the presence of any other types of malware in the system," he added.

The Law-Enforcement Challenge

Similar to Trojan horses and worms, TDL-4's malicious code functions as a web-based robot or "bot" capable of performing automated tasks. Once a PC becomes infected, it becomes a "zombie" machine under the control of TDL-4's criminal masterminds. "Since the beginning of this year, the botnet has installed nearly 30 additional malicious programs, including fake antivirus programs, adware and the Pushdo spambot," Golovanov explained.

Now that the number of infected machines has achieved critical mass, the cyberthieves running the resulting "botnet" also have the ability to conduct a wide range of coordinated malicious activities. For example, the botnet could be used to send out spam messages or launch denial-of-service attacks on selected web sites.

Earlier this year, the FBI seized servers that had infected as many as two million computers with the botnet-producing Coreflood virus, a key-logging program that enabled cybercriminals to steal personal and financial information by recording PC users' keystrokes. However, the FBI and its international law-enforcement partners will find it far more challenging to shut down the TDL-4 botnet.

According to Golovanov, the creators of TDL-4 have added countermeasures to ensure they continue to have access to infected computers even if their primary botnet control centers are shut down. "The owners of TDL are essentially trying to create an 'indestructible' botnet that is protected against attacks, competitors and antivirus companies," Golovanov noted.

The Best Protection

To protect themselves, PC users should run the full version of a security software suite that delivers automatic updates. PC users also should avoid visiting those online destinations where infection is most likely to take place.

Golovanov noted that TDL-4's owners are paying their online affiliates to infect Windows-based machines visiting web sites hosting adult and bootleg multimedia content or offering online video- and file-storage services. "Going on the prices quoted by affiliate programs, this number of infected computers in the U.S. is worth $250,000 -- a sum which presumably made its way to the creators of TDSS," Golovanov observed.

Symantec advises PC users to increase their browser security settings and ensure that their PC is patched with the most current Microsoft Windows Update. What's more, PC users should never click on an e-mail attachment unless the user has verified that it comes from a trusted source.
...
Obviously, in a few months, the US military will use it's brand new, sentient defence network to get rid of it, only for it to reveal itself to be the virus itself. Then nukes will inexplicably fall from the sky. Watch this space.
Yeah, I've always taken the subtext of the Birther movement to be, "The rules don't count here! This is different! HE'S BLACK! BLACK, I SAY! ARE YOU ALL BLIND!?

- Raw Shark

Destiny and fate are for those too weak to forge their own futures. Where we are 'supposed' to be is irrelevent.

- SirNitram (RIP)
User avatar
Enigma
is a laughing fool.
Posts: 7777
Joined: 2003-04-30 10:24pm
Location: c nnyhjdyt yr 45

Re: 'Indestructible' Virus TDL-4. Guess who's got it!

Post by Enigma »

Have you tried combofix?
ASVS('97)/SDN('03)

"Whilst human alchemists refer to the combustion triangle, some of their orcish counterparts see it as more of a hexagon: heat, fuel, air, laughter, screaming, fun." Dawn of the Dragons

ASSCRAVATS!
User avatar
Iroscato
Jedi Council Member
Posts: 2360
Joined: 2011-02-07 03:04pm
Location: Great Britain (It's great, honestly!)

Re: 'Indestructible' Virus TDL-4. Guess who's got it!

Post by Iroscato »

Enigma wrote:Have you tried combofix?
Never heard of it, and doubt it would work, I've tried 5 different brands of AV and nothing's shifting or can't even find the bastard :(
Yeah, I've always taken the subtext of the Birther movement to be, "The rules don't count here! This is different! HE'S BLACK! BLACK, I SAY! ARE YOU ALL BLIND!?

- Raw Shark

Destiny and fate are for those too weak to forge their own futures. Where we are 'supposed' to be is irrelevent.

- SirNitram (RIP)
User avatar
Executor32
Jedi Council Member
Posts: 2088
Joined: 2004-01-31 03:48am
Location: In a Georgia courtroom, watching a spectacle unfold

Re: 'Indestructible' Virus TDL-4. Guess who's got it!

Post by Executor32 »

I'd say go ahead and try it, then. It can get rid of almost anything, and is powerful enough that you can severely fuck things up if try to use its more advanced feature without knowing what you're doing. You're ready to just factory-reset the thing, though, so it's not like you have anything to lose, right?
どうして?お前が夜に自身お触れるから。
Long ago in a distant land, I, Aku, the shape-shifting Master of Darkness, unleashed an unspeakable evil,
but a foolish samurai warrior wielding a magic sword stepped forth to oppose me. Before the final blow
was struck, I tore open a portal in time and flung him into the future, where my evil is law! Now, the fool
seeks to return to the past, and undo the future that is Aku...
-Aku, Master of Masters, Deliverer of Darkness, Shogun of Sorrow
Datana
Jedi Master
Posts: 1011
Joined: 2002-07-04 03:16am
Contact:

Re: 'Indestructible' Virus TDL-4. Guess who's got it!

Post by Datana »

TDL-4 depends on a low-level component before the filesystem proper, so a re-install of Windows will just get you re-infected unless you either fdisk to blow away the existing partitions and full format, or remove the infection from the MBR first.

Three step process required:

TDSSKiller is needed to remove the MBR infestation.

Combofix is required to remove most of the active Windows components once TDSSKiller has done its work.

Malwarebytes is needed to remove the remaining bits, as well as to fix errors caused by Combofix.
Member of the Anti-PETA Anti-Fascist League
User avatar
The Jester
Padawan Learner
Posts: 475
Joined: 2005-05-30 08:34am
Location: Japan

Re: 'Indestructible' Virus TDL-4. Guess who's got it!

Post by The Jester »

According to Kaspersky, if your computer is indeed part of the TDL-4 botnet, you can use TDSS Killer to remove it.
User avatar
Broomstick
Emperor's Hand
Posts: 28846
Joined: 2004-01-02 07:04pm
Location: Industrial armpit of the US Midwest

Re: 'Indestructible' Virus TDL-4. Guess who's got it!

Post by Broomstick »

So... how did you find out you had it? And how does one know one is infected?

I do keep my anti-virus/firewall up to date, scan the computer, do my best to avoid skanky sites... and I still worry.
A life is like a garden. Perfect moments can be had, but not preserved, except in memory. Leonard Nimoy.

Now I did a job. I got nothing but trouble since I did it, not to mention more than a few unkind words as regard to my character so let me make this abundantly clear. I do the job. And then I get paid.- Malcolm Reynolds, Captain of Serenity, which sums up my feelings regarding the lawsuit discussed here.

If a free society cannot help the many who are poor, it cannot save the few who are rich. - John F. Kennedy

Sam Vimes Theory of Economic Injustice
Simon_Jester
Emperor's Hand
Posts: 30165
Joined: 2009-05-23 07:29pm

Re: 'Indestructible' Virus TDL-4. Guess who's got it!

Post by Simon_Jester »

Should Macintosh users be worrying about this thing?
This space dedicated to Vasily Arkhipov
User avatar
White Haven
Sith Acolyte
Posts: 6360
Joined: 2004-05-17 03:14pm
Location: The North Remembers, When It Can Be Bothered

Re: 'Indestructible' Virus TDL-4. Guess who's got it!

Post by White Haven »

TDSSKiller will probably kill it, but there's a very good chance that it'll leave your system in an unbootable state when used against TDL-4 in its current incarnation. I've been tangling with what I believe to be TDL-4, although it's hard to positively ID, on a customer system and it is indeed a nasty sonofabitch.
Image
Image
Chronological Incontinence: Time warps around the poster. The thread topic winks out of existence and reappears in 1d10 posts.

Out of Context Theatre, this week starring Darth Nostril.
-'If you really want to fuck with these idiots tell them that there is a vaccine for chemtrails.'

Fiction!: The Final War (Bolo/Lovecraft) (Ch 7 9/15/11), Living (D&D, Complete)Image
User avatar
Edi
Dragonlord
Dragonlord
Posts: 12461
Joined: 2002-07-11 12:27am
Location: Helsinki, Finland

Re: 'Indestructible' Virus TDL-4. Guess who's got it!

Post by Edi »

Simon_Jester wrote:Should Macintosh users be worrying about this thing?
Mac users should have AV installed and kept up to date, since there are all kinds of nasties that affect Macs these days too. Not sure about this one, but I wouldn't be surprised if it targeted the Mac too. The DNS changer virus from a couple of years back happily infected Macs.
Warwolf Urban Combat Specialist

Why is it so goddamned hard to get little assholes like you to admit it when you fuck up? Is it pride? What gives you the right to have any pride?
–Darth Wong to vivftp

GOP message? Why don't they just come out of the closet: FASCISTS R' US –Patrick Degan

The GOP has a problem with anyone coming out of the closet. –18-till-I-die
Post Reply