LandzDown Forum

Software & More => Web News => Topic started by: Frands on June 30, 2011, 04:56:10 PM

Title: The TDL-4 botnet
Post by: Frands on June 30, 2011, 04:56:10 PM
Hi,

Security researchers has discovered 'indestructible' botnet

QuoteMore than four million PCs have been enrolled in a botnet security experts say is almost "indestructible".

The botnet, known as TDL, targets Windows PCs and is difficult to detect and shut down.

Code that hijacks a PC hides in places security software rarely looks and the botnet is controlled using custom-made encryption.

Security researchers said recent botnet shutdowns had made TDL's controllers harden it against investigation.

The 4.5 million PCs have become victims over the last three months following the appearance of the fourth version of the TDL virus.


Please read the whole story here:  http://www.bbc.co.uk/news/technology-13973805 (http://www.bbc.co.uk/news/technology-13973805)
Title: Re: The TDL-4 botnet
Post by: Corrine on June 30, 2011, 10:28:14 PM
A couple of Snips from the Kaspersky article:  TDL4 – Top Bot - Securelist (http://www.securelist.com/en/analysis/204792180/TDL4_Top_Bot)

QuoteAffiliates receive between $20 to $200 for every 1,000 installations of TDL, depending on the location of the victim computer. Affiliates can use any installation method they choose. Most often, TDL is planted on adult content sites, bootleg websites, and video and file storage services.

{SNIP}

TDSS contains code to remove approximately 20 malicious programs, including Gbot, ZeuS, Clishmic, Optima, etc. TDSS scans the registry, searches for specific file names, blacklists the addresses of the command and control centers of other botnets and prevents victim machines from contacting them.

This 'antivirus' actually helps TDSS; on the one hand, it fights cybercrime competition, while on the other hand it protects TDSS and associated malware against undesirable interactions that could be caused by other malware on the infected machine.