tdl3 rootkit browsers hook to directdr.com & urbtk.com

Page 2 of 2 FirstFirst 12

  1. Posts : 16
    Windows 10 32 bit oem & Arch Linux x86_64
    Thread Starter
       #11

    os still stable


    almost 1 month later and have had no ill effects, just a wee update. still a happy camper :>
      My Computer


  2. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #12

    Good to know, thanks for the update :)
      My Computer


  3. Posts : 529
    windows 8.1 Pro x64
       #13

    my question is how does infect machines? I mean how does it get on in the first place.

    is it drive by or something you have to execute.
      My Computer


  4. Posts : 16
    Windows 10 32 bit oem & Arch Linux x86_64
    Thread Starter
       #14

    reply to chrysalis


    usually people get infected by downloading "cracked software" or from p2p sites torrents ect, and u can also get bitten by visiting malicious sites,u could even download and install a codec which isnt what it seems, these rootkits are very clever my advice would be to use the wot (web of trust add on) which is available for firefox and internet explorer,malwareytes updated and scheduled to scan daily is another advantage for the end user [you], for that extra wee bit of security id recommend no script add on for firefox, which will disable any malicious sites from doing a drive by on you, hope u found this usefull and remember, "google is ur friend" he is wiser than yoda
      My Computer


  5. Posts : 529
    windows 8.1 Pro x64
       #15

    well I mean how does this specific trojan infect.
      My Computer


  6. Posts : 846
    Windows 10 Pro
       #16

    chrysalis said:
    well I mean how does this specific trojan infect.
    I don't understand it but if you want the details here you go.
    http://virusvn.com/download/video-tu...ysis_paper.pdf
      My Computer


  7. Posts : 16
    Windows 10 32 bit oem & Arch Linux x86_64
    Thread Starter
       #17

    NEW TDSS TDL 4 PFFT combofix pwns


    my machine still goin strong 1 year later, but yesterday a family member brought me their laptop saying it was unusable due to the large amount of fake A.V alerts, my first port of call was to install mbam from a thumbdrive and it found 3000+ infections (seriously) thats a record for me, i let mbam clean em all (took a while) , afterward i decided to put FF on the lappy & prompt the owner to say goodbye to internet exploder, however on doing this i was redirected to gala search engine and the FF download was not pointing to mozilla.com , having seen this type of behaviour before, i downloaded combofix from bleeping computer to a thumbdrive, renamed it 123.exe and copied over to infected machine, i let combofix do its thing and yup it found a TDL 4 , corrupt MBR, im glad to say combofix also fixed this laptop which was running xp sp2 java version 5 & slimewire i left a READ ME.txt on desktop prompting owner to delete limewire, and of course i updated java,flash sp3, windows updates ect, so we have a new tdss in our midst and combofix nailed it once more :))
      My Computer


 
Page 2 of 2 FirstFirst 12

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 15:34.
Find Us