Page 1 of 1

'Indestructible' Virus TDL-4. Guess who's got it!

Posted: 2011-07-05 08:34am
by Iroscato
An almost indestructible virus called TDL-4 has been making the rounds in the internet, and it's infected millions of pcs. And yeah, I've got it. I've blasted it with every anti virus program I've got to no avail, so I'm just going to reset the damn thing to factory default and have done with it. I just wanted to give people a heads-up about it, it's almost unremovable, and it assaults you with adware and spyware every time you use Google.
I'm 99% sure this is what I've got...


http://news.yahoo.com/indestructible-td ... 41405.html
..A researcher at security software firm Kaspersky Labs has uncovered a sophisticated botnet threat that already controls more than 4.5 million Windows-based PCs around the world, with nearly one-third of all infected machines located in the United States. Moreover, there is reason to believe that the latest strain of TDSS uncovered this week -- which commands the infected PCs to run malware programs -- will be able to evolve over time.
According to Kaspersky researcher Sergey Golovanov, the new TDSS strain is the most sophisticated cybersecurity threat facing PC users today. It's even designed to delete other malicious programs not associated with the TDSS botnet, to eliminate the competition as well as ensure that PC users remain unaware that their machines are infected.

The malicious software uses a range of methods to evade detection, and employs encryption to facilitate communication between its bots and the botnet command-and-control center, Golovanov wrote in a Securelist posting. "TDSS also has a powerful rootkit component, which allows it to conceal the presence of any other types of malware in the system," he added.

The Law-Enforcement Challenge

Similar to Trojan horses and worms, TDL-4's malicious code functions as a web-based robot or "bot" capable of performing automated tasks. Once a PC becomes infected, it becomes a "zombie" machine under the control of TDL-4's criminal masterminds. "Since the beginning of this year, the botnet has installed nearly 30 additional malicious programs, including fake antivirus programs, adware and the Pushdo spambot," Golovanov explained.

Now that the number of infected machines has achieved critical mass, the cyberthieves running the resulting "botnet" also have the ability to conduct a wide range of coordinated malicious activities. For example, the botnet could be used to send out spam messages or launch denial-of-service attacks on selected web sites.

Earlier this year, the FBI seized servers that had infected as many as two million computers with the botnet-producing Coreflood virus, a key-logging program that enabled cybercriminals to steal personal and financial information by recording PC users' keystrokes. However, the FBI and its international law-enforcement partners will find it far more challenging to shut down the TDL-4 botnet.

According to Golovanov, the creators of TDL-4 have added countermeasures to ensure they continue to have access to infected computers even if their primary botnet control centers are shut down. "The owners of TDL are essentially trying to create an 'indestructible' botnet that is protected against attacks, competitors and antivirus companies," Golovanov noted.

The Best Protection

To protect themselves, PC users should run the full version of a security software suite that delivers automatic updates. PC users also should avoid visiting those online destinations where infection is most likely to take place.

Golovanov noted that TDL-4's owners are paying their online affiliates to infect Windows-based machines visiting web sites hosting adult and bootleg multimedia content or offering online video- and file-storage services. "Going on the prices quoted by affiliate programs, this number of infected computers in the U.S. is worth $250,000 -- a sum which presumably made its way to the creators of TDSS," Golovanov observed.

Symantec advises PC users to increase their browser security settings and ensure that their PC is patched with the most current Microsoft Windows Update. What's more, PC users should never click on an e-mail attachment unless the user has verified that it comes from a trusted source.
...
Obviously, in a few months, the US military will use it's brand new, sentient defence network to get rid of it, only for it to reveal itself to be the virus itself. Then nukes will inexplicably fall from the sky. Watch this space.

Re: 'Indestructible' Virus TDL-4. Guess who's got it!

Posted: 2011-07-05 09:33am
by Enigma
Have you tried combofix?

Re: 'Indestructible' Virus TDL-4. Guess who's got it!

Posted: 2011-07-05 09:38am
by Iroscato
Enigma wrote:Have you tried combofix?
Never heard of it, and doubt it would work, I've tried 5 different brands of AV and nothing's shifting or can't even find the bastard :(

Re: 'Indestructible' Virus TDL-4. Guess who's got it!

Posted: 2011-07-05 10:28am
by Executor32
I'd say go ahead and try it, then. It can get rid of almost anything, and is powerful enough that you can severely fuck things up if try to use its more advanced feature without knowing what you're doing. You're ready to just factory-reset the thing, though, so it's not like you have anything to lose, right?

Re: 'Indestructible' Virus TDL-4. Guess who's got it!

Posted: 2011-07-05 11:08am
by Datana
TDL-4 depends on a low-level component before the filesystem proper, so a re-install of Windows will just get you re-infected unless you either fdisk to blow away the existing partitions and full format, or remove the infection from the MBR first.

Three step process required:

TDSSKiller is needed to remove the MBR infestation.

Combofix is required to remove most of the active Windows components once TDSSKiller has done its work.

Malwarebytes is needed to remove the remaining bits, as well as to fix errors caused by Combofix.

Re: 'Indestructible' Virus TDL-4. Guess who's got it!

Posted: 2011-07-05 11:19am
by The Jester
According to Kaspersky, if your computer is indeed part of the TDL-4 botnet, you can use TDSS Killer to remove it.

Re: 'Indestructible' Virus TDL-4. Guess who's got it!

Posted: 2011-07-05 11:40am
by Broomstick
So... how did you find out you had it? And how does one know one is infected?

I do keep my anti-virus/firewall up to date, scan the computer, do my best to avoid skanky sites... and I still worry.

Re: 'Indestructible' Virus TDL-4. Guess who's got it!

Posted: 2011-07-05 11:51am
by Simon_Jester
Should Macintosh users be worrying about this thing?

Re: 'Indestructible' Virus TDL-4. Guess who's got it!

Posted: 2011-07-05 01:04pm
by White Haven
TDSSKiller will probably kill it, but there's a very good chance that it'll leave your system in an unbootable state when used against TDL-4 in its current incarnation. I've been tangling with what I believe to be TDL-4, although it's hard to positively ID, on a customer system and it is indeed a nasty sonofabitch.

Re: 'Indestructible' Virus TDL-4. Guess who's got it!

Posted: 2011-07-05 04:10pm
by Edi
Simon_Jester wrote:Should Macintosh users be worrying about this thing?
Mac users should have AV installed and kept up to date, since there are all kinds of nasties that affect Macs these days too. Not sure about this one, but I wouldn't be surprised if it targeted the Mac too. The DNS changer virus from a couple of years back happily infected Macs.