This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Community Information

TDSS/TDL4/Alureon gain self-propagation!

1 min read

This thread's last reply is from June 4, 2011, 6:21 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

One of the most notorious rootkits has just acquired a self-propagating mechanism that could allow it to spread to new victims, a security researcher has warned.

</snip>

The first is by infecting removable media drives with a file that gets executed each time a computer connects to the device. The technique has been around for years and has been used by plenty of other computer worms, including the one known as Conficker. Other than using files with titles such as myporno.avi.lnk and pornmovs.lnk, there's nothing particularly unusual about the way TDSS goes about doing this.

The second method is to spread over local area networks by creating a rogue DHCP server and waiting for attached machines to request an IP address. When the malware finds a request, it responds with a valid address on the LAN and an address to a malicious DNS server under the control of the rootkit authors. The DNS server then redirects the targeted machine to malicious webpages.


Full Story @ The Register
Kaspersky Blog Post
Zero Bump