Tuesday, July 12, 2011

Is your computer part of TDL-4 botnet?

Botnet is the biggest threat on the internet these days. The term botnet refers to a collection of compromised computers that are controlled by a malicious hacker or hacker's group.

The TDL-4 is the newest and scariest on the internet, it is called the 'indestructible' botnet by some of the researchers because it safeguards itself from removal in a few ways:

1) it infects a computer's master boot record, allowing it to run before Windows starts up, enabling it to stay under the radar of its host's antivirus software,

2) it has its own antivirus built in, so it can remove other malware that might be picked up by real antivirus and alert the user that there's a problem, and

3) its communication with its peers is encrypted and well timed, such that it communicates when the user of the computer is surfing the 'net.

So what's the point of it? Money. Like most malware created today, its authors are organized and after dollars. All that spam in your mailbox? That's from a botnet selling pirated software and pharmaceuticals. Your personal data is worth money. The front and back of a credit card as a scanned document will sell for $20. Your PayPal account credentials will net someone 30% of the balance of the account.

The good news is TDL-4 is NOT indestrutible. The malware can be detected and removed by Kaspersky Lab's free TDSSKiller.

No comments:

Post a Comment