Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

July 5th, 2011, 11:53 GMT · By

Free Removal Tools Available for Sophisticated TDL4 Bootkit

SHARE:

Adjust text size:


TDL4 is not indestructible
Enlarge picture
The TDL4 malware which features a highly sophisticated MBR rootkit has been characterized in the news lately as indestructible, but the truth is there are freely available tools that can remove it.

The comments of a Kaspersky Lab security expert who said that the TDL4 authors are trying to create an indestructible botnet have been misinterpreted by the press and generated panic among less technical users.

First of all, Kaspersky's Sergey Golovanov was referring to the botnet and not the malware itself and second, he said that this was their goal, not that they succeeded.

A botnet is a group of infected computers controlled by attackers via C&C servers or other protocols and channels.

The researcher was speaking in the context of the the botnet's redundancy mechanism which is based on the legit KAD peer-2-peer network. This allows its authors to update it even if the C&C servers are shut down.

In addition, the botnet uses custom encryption algorithms in order to hide its communications and make it harder to detect by network firewalls.

The malware itself is also complex. It contains a rootkit component that installs itself into the master boot record (MBR) and can modify the operating system even before it even loads.

It can infect both 32 and 64-bit versions of Windows and is one of the most sophisticated rootkits known to date. But despite this, the TDL4 bot can be removed from computers and most major antivirus programs are capable of doing this.

In addition, security companies have released stand-alone TDL4 removal tools that anyone can use for free without the need to replace their current antivirus program.

One of the companies who provide such an application is BitDefender. It's TDL4 removal tool is offered in both 32-bit and 64-bit versions. Kaspersky Lab also have a TDL4 cleaner dubbed TDSS Killer.

TELL US WHAT YOU THINK:

1,752 hits · 2 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


TDSS Rootkit Gets Self-Propagation Component

TDL4 Rootkit Updated to Bypass Microsoft Patch

Microsoft Patch Disables TDL4 Rootkit on 64-Bit Windows

READER COMMENTS:


Comment #1 by: JC on 08 Jul 2011, 19:55 UTC reply to this comment

ran bitdefender removal tool and scan aborted. Repeated and aborted again


Comment #2 by: NoFear on 29 Nov 2011, 21:44 UTC reply to this comment

Lots of posts on the internet, no successes; got infected, tried it myself. The BitDefender TDL4 Removal Tool does not work, it will not remove the infection.

If you can actually get it to download and run, it can't even find the infection, let alone remove it.

I'm a Sr. Systems Engineer, so I know what I'm doing and what I'm talking about.

The Kaspersky tool does not work either. It screws up the boot sector while attempting to remove, and if you can get back into Windows after that, the infection is still there.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM