Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Security researchers discover 'indestructible' botnet
BBC ^ | June 30, 2011 | Unknown

Posted on 06/30/2011 6:54:05 AM PDT by decimon

More than four million PCs have been enrolled in a botnet security experts say is almost 'indestructible'

The botnet, known as TDL, targets Windows PCs and tries hard to avoid detection and even harder to shut down.

Code that hijacks a PC hides in places security software rarely looks and the botnet is controlled using custom-made encryption.

Security researchers said recent botnet shutdowns had made TDL's controllers harden it against investigation.

The 4.5 million PCs have become victims over the last three months following the appearance of the fourth version of the TDL virus.

The changes introduced in TDL-4 made it the "most sophisticated threat today," wrote Kaspersky Labs security researchers Sergey Golovanov and Igor Soumenkov in a detailed analysis of the virus.

"The owners of TDL are essentially trying to create an 'indestructible' botnet that is protected against attacks, competitors, and anti-virus companies," wrote the researchers.

(Excerpt) Read more at bbc.co.uk ...


TOPICS: Computers/Internet
KEYWORDS: microsofttax; tdl; virus
Navigation: use the links below to view more comments.
first previous 1-2021-36 last
To: arthurus

I agree, Norton is one of the most obnoxious pieces of Malware I’ve had the misfortune to deal worth. Worse than any virus in terms of its actual impact on me.


21 posted on 06/30/2011 8:16:07 AM PDT by Liberty1970 (For by grace are you saved through faith.)
[ Post Reply | Private Reply | To 18 | View Replies]

To: decimon

They also fall for those phishing exploits that tell you there’s something wrong with your pc click here.


22 posted on 06/30/2011 8:24:29 AM PDT by ichabod1 (Nuts; A house divided against itself cannot stand.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Texas Fossil

>June 30, 2011

“Sorry, but the TDL botnet is not ‘indestructible’ “<

Correct. Just like that MS wackadoo who announced that the Alureon rootkit is also indestructible, I laugh at these “experts” who scare Win users.

Of course what do I know. I used to consult for Kaspersky and Norton. The TLD4 is the nastiest MFer on the planet and every malware and rootkit guy I know has seen it do damage. The Alureon class 1-4, I detected on other clients laptops and it was fairly easy but time consuming to clean. The TDL botnets and rootkits re-write the registry on occasions so you have to use instinct by utilizing a registry cleaner and if that annoys you, use OTS which corrects the re-written code automatically.

Just to show everyone how nasty the TDL’s are, I actually witnessed it shut down the Malwarebytes pro version dead in it’s tracks. That’s the pro version, not the free one.


23 posted on 06/30/2011 8:57:19 AM PDT by max americana (FUBO NATION 2012)
[ Post Reply | Private Reply | To 3 | View Replies]

To: All

I ran into the same problems, I used Google to search some financial information, and a search return that I clicked on installed the virus of “XP Security 2012” pop-up virus.

I easily got rid of it, but as a result, I bought an Apple iPad 2 and now do all my searching, web browsing with it.

Screw the massively defective Windows garbage. Been surfing the web freely for over a month. And NO troubles at all.

The iPad is an absolutely amazing product!!!


24 posted on 06/30/2011 9:07:03 AM PDT by OhhTee5
[ Post Reply | Private Reply | To 23 | View Replies]

To: max americana

Is there a good diagnostic tool for root kits?

I have only had one, and the simple solution was to reload the system.

I have used SchmidtFraudFix (spelling may not be right) on a really nasty bug, think it was complements of the U.S. Gov. Made a mistake one day chasing news and wound up on a militia site and after a few moments something shut down my system and my anti-virus program had to neutralize it each time I rebooted. Used every tool in my tool kit and nothing worked, one of our IT guys told me about that tool and it worked. It is a totally command line tool for really nasty stuff.


25 posted on 06/30/2011 9:07:46 AM PDT by Texas Fossil (Government, even in its best state is but a necessary evil; in its worst state an intolerable one)
[ Post Reply | Private Reply | To 23 | View Replies]

To: Swordmaker

not a Mac thing but thought this might be of interest to you, because, well, it’s not a Mac thing.


26 posted on 06/30/2011 9:21:20 AM PDT by Tribune7 (We're flat broke, but he thinks these solar shingles and really fast trains will magically save us.)
[ Post Reply | Private Reply | To 25 | View Replies]

To: tacticalogic
I've seen research reports that found the most common vector for malware and virus distribution wasn't porn sites, but free game sites geared toward children. They'll click on anything.

I completely agree. I think historically speaking, porn sites have been a bit of a problem but overall it is the "free" game sites and other "free" stuff kind of sites that are the problem even though porn sites CAN BE a problem.

A lady I work with asked me to help her with her home computer that was infected with a virus. I thought I would mess with her and after getting rid of the virus, she asked how she got it. I asked who usually used the computer and she said her husband. I told her (with a straight face) it looked like it came from a gay porn site and if she was aware he husband surfed gay porn. Her mouth dropped open... she was speechless! LOL!! I couldn't help it anymore and told her I was joking. She just laughed and said "that was a good one"! Probably more relieved than anything!

I have found Malwarebytes to be amongst the best but I think the most effective tool I have used is the Avast boot-time scan. Very effective and efficient too.
27 posted on 06/30/2011 9:24:58 AM PDT by copaliscrossing (Progressives are Socialists)
[ Post Reply | Private Reply | To 11 | View Replies]

To: Texas Fossil

I’m on the Avast forums as an “evangelist”, who rids your pc of rootkits and malware but I won’t tell you which one to avoid the trolls.

The best tools are the free ones, and it’s not who you use them but to understand how they work. For basics, you AV will not protect you 100%. The top 3 tools you should have is Malwarebytes (free, but I prefer the pro), GMER and Combofix. GMER used to scan then fix the rootkit and malware but the ‘fix” part sucks nowadays so Combofix does the trick.

For the TDL hard cases, DDS does the trick and WHEN the TDL’s really get wild and re-write the MS Windows registry and open a backdoor for future invasions which it does, OTS corrects the registry for you.

It’s nice to know that in the past years I’ve done this, I have never given up on a pc and told me clients to re-boot the system to the orig. factory settings. There is ALWAYS a way to save your files from the hard drive and all that work should always be saved.


28 posted on 06/30/2011 9:25:04 AM PDT by max americana (FUBO NATION 2012)
[ Post Reply | Private Reply | To 25 | View Replies]

To: max americana

I forgot to mention Combofix in my post above. I agree it is a great tool also.


29 posted on 06/30/2011 9:27:56 AM PDT by copaliscrossing (Progressives are Socialists)
[ Post Reply | Private Reply | To 28 | View Replies]

To: raybbr
My wife has gotten two of those “Fake Alert” viruses and she was not surfing porn. Shopping sites.

So have I. Fortunately the worst incident happened when I was using my Linux box. Even then it took several tries to get out of it.

I'm getting to the point where I will be pretty restrictive where I go with my Win 7 machine, since it is essential it stays clean. Do my surfing on my laptop under Ubuntu.

30 posted on 06/30/2011 9:28:44 AM PDT by ChildOfThe60s ( If you can remember the 60s....you weren't really there)
[ Post Reply | Private Reply | To 7 | View Replies]

To: copaliscrossing

The same dudes who created Combofix were originally from Norton and they were pissed how weak Norton really was. Some of them even created one of the best, not-known AV’s which uses cloud technology: Previx. They have a cult following..


31 posted on 06/30/2011 9:33:04 AM PDT by max americana (FUBO NATION 2012)
[ Post Reply | Private Reply | To 29 | View Replies]

To: decimon
Following links about this story and virus, I arrived at a recommended solution if you suspect infection, namely TDSSKiller at http://support.kaspersky.com/viruses/utility

The other utilities look interesting as well.

32 posted on 06/30/2011 10:22:41 AM PDT by catnipman (Cat Nipman: Made from the right stuff!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Thanks for the ping.


33 posted on 06/30/2011 10:40:46 AM PDT by GOPJ (Black flash mobs: street level reflections of elite liberal hate for middle class America..)
[ Post Reply | Private Reply | To 17 | View Replies]

To: Liberty1970; arthurus

Norton is not only junk, but very difficult junk to get rid of.

Several years ago when I had problems with it, I uninstalled and the uninstall corrupted Corel Draw (which is essential to my work) so that it would not run. It deleted a certain file. After extensive research I found A)which file and then a copy of the file, thankfully and B) an awful lot of other Corel users had also gotten shafted and couldn’t load Corel.

Half day’s work in the toilet. Now, I contact online Norton support, and forced them to connect me with a supervisor (yep, India). When I pointed out that Norton was making Corel inoperative for a LARGE number of people, he gave me the BS that Norton doesn’t support other apps (especially the ones that they corrupt). Well, we went round and round and the SOB hung up on me.

Anyone that wants to really get rid of Norton better be able to manually edit the registry. That’s what I had to do.


34 posted on 07/01/2011 5:57:40 PM PDT by ChildOfThe60s ( If you can remember the 60s....you weren't really there)
[ Post Reply | Private Reply | To 21 | View Replies]

To: decimon; Ernest_at_the_Beach

Thanks decimon.
The botnet, known as TDL, targets Windows PCs

35 posted on 07/02/2011 7:26:07 AM PDT by SunkenCiv (It's the Obamacare, stupid! -- Thanks Cincinna for this link -- http://www.friendsofitamar.org)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ChildOfThe60s

i am not sufficiently technically oriented to edit the registry. I don’t know what to look for or how to even get there.


36 posted on 07/04/2011 4:38:05 PM PDT by arthurus (Read Hazlitt's "Economics In One Lesson.")
[ Post Reply | Private Reply | To 34 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-36 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson