Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

TDSS/TDL4/Alureon gain self-propagation!

Notifications for Security Updates, as well as News and Information from across the web - mostly security minded.

Update Contributors: Members of the Malware Removal University.

Regular Members: Our Regular Members are invited to start and/or participate in all other topics. Join in and share the news that's important to you.

TDSS/TDL4/Alureon gain self-propagation!

Unread postby Sludge3000 » June 4th, 2011, 2:20 am

One of the most notorious rootkits has just acquired a self-propagating mechanism that could allow it to spread to new victims, a security researcher has warned.

</snip>

The first is by infecting removable media drives with a file that gets executed each time a computer connects to the device. The technique has been around for years and has been used by plenty of other computer worms, including the one known as Conficker. Other than using files with titles such as myporno.avi.lnk and pornmovs.lnk, there's nothing particularly unusual about the way TDSS goes about doing this.

The second method is to spread over local area networks by creating a rogue DHCP server and waiting for attached machines to request an IP address. When the malware finds a request, it responds with a valid address on the LAN and an address to a malicious DNS server under the control of the rootkit authors. The DNS server then redirects the targeted machine to malicious webpages.


Full Story @ The Register
Kaspersky Blog Post
User avatar
Sludge3000
Regular Member
 
Posts: 695
Joined: April 15th, 2009, 3:47 pm
Location: Somewhere fluffy
Advertisement
Register to Remove

Re: TDSS/TDL4/Alureon gain self-propagation!

Unread postby Sludge3000 » June 4th, 2011, 2:21 am

Zero Bump
User avatar
Sludge3000
Regular Member
 
Posts: 695
Joined: April 15th, 2009, 3:47 pm
Location: Somewhere fluffy


Return to News Desk



Who is online

Users browsing this forum: No registered users and 118 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware