Jump to content



Massive bot-net (RootKit)


No replies to this topic

#1 nka

    Geek God

  • [QiT] Admins
  • PipPipPipPipPipPipPipPipPipPip
  • 12,054 posts
  • LocationQuebec, Canada

Posted 10 July 2011 - 05:33 PM

Il y a un giga-botnet qui crée des RootKit. Cela affecte les 32 et 64 bits de WIndows et meme Linux!



Quote

QUICK EASY DETECTION OF INFECTION ON A WINDOWS SYSTEM

There are at least two options to do that, all with tools already included in the operating system:

Open a command prompt, with Windows-R, entering cmd and enter.

Use the command diskpart to open Diskpart in a new command line window.

Enter lis dis in the new prompt, if it remains empty the computer is infected with the rootkit. If the disks display, it is not.

The second option to detect the 64-bit rootkit is the following: Launch Disk Management from the Computer Management pane.

If it does not show disks, it means the system is infected with the rootkit. If it shows disks, everything is fine.

The above only helps detect the 64-bit Alureon Rootkit. For other issues please use a GOOD Anti-Virus app.

Here is a link to the Norton Power Eraser. It seems to be able to remove the TDL4 variant.
http://security.syma....aspx?lcid=1033
As well as the TDDSSkiller app
http://community.nor...DL4/td-p/232195
TDSS Removers (32 and 64 versions)
http://www.malwareci...e-now-1106.html
http://support.kaspe.../tdsskiller.zip

Additional Removal programs and instructions
http://blog.jeffels....1/tdl4-removal/
http://support.kaspe...s?qid=208280748


Links to helpful info on this issue.
http://arstechnica.c...estructable.ars
http://www.microsoft...n32%2FAlureon.F
http://www.ghacks.ne...tkit-infection/
http://www.bleepingc...sing-tdsskiller
http://www.spywarere...oveAlureon.html
http://www.securelis...80/TDL4_Top_Bot

AS ALWAYS USE SAFE COMPUTING PRACTICES. STAY OFF FILE SHARING SITES AND AVOID PORN/SPAM SITES.








1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users