TDL4 Rootkit - Being Used As A Proxy

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
5,702
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Jul 11, 2011

In this video I'll show you how the new TDL4 Rootkit uses an infected PC as a proxy server. This is one of the main -features- of the TDL4 rootkit

Category:

Science & Technology

Tags:

License:

Standard YouTube License

  • likes, 1 dislikes

Link to this comment:

Share to:

Uploader Comments (mrizos)

  • Matt, do you think Comodo's sandbox or Defense + will catch this? It is supposed to catch 99.5% of all unknown malware.. Even the comodo firewall will pickup the remote connections.

  • @Thesaakeman I'm pretty sure D+ would prevent this. I'll run a test and upload the video.

  • oh forgot to add thumbs up good vid matt ;)

  • @LokiV thanks!

  • nice video

  • @Serj960HD thx

see all

All Comments (93)

Sign In or Sign Up now to post a comment!
  • @12345shre not necessary in trouble you if the person that got hit by the rootkit and haves the dr web boot cd or windows instill disk you can save your pc

  • the stealth TDL4 is characteristic bot.

    however,this rootkit can be removed unless the bot master begans hacking u and break through your machine then u are in trouble!

  • @longhairsRcool PART 2: So even if you think you've removed it it's likely attached to a driver as that's what it's designed to do and with TDL4 it's a random driver i.e. with kernel level access and it can then re-install itself. The only smart way this can be removed as best as I know is with a bootup live CD and knowing what to remove. That said with infections this bad it's really probably smartest to just re-install windows 7 honestly and focus on stopping malware to start with.

  • Hey Mirzos, Security Expert, and computer programmer here. Just because this is partially detected by (correct me if I'm wrong) tdsskiller doesn't mean that if you try removing the hidden drive etc, using tdsskiller that the rootkit is gone. Being that it is a KERNEL MODE rootkit which bypasses kernel patching, kernel signing, and kernel code signing procedures by Microsoft it's very hard to remove conventionally.

  • @grand433 He uses Norton Internet Security 2012, and COMODO Firewall

  • Matt....

    It is to be noted that if u have dell...u will have to first remove the TDL4 rootkit that has infected the MBR....then replace the faked MBR code with a standard one....but the MBR code of dell is unique...u will have to first replace it with a standard one and then use DSRfix to have your dell mbr back....if u dont get the custom mbr code back...u ose access to recovery partition...no console will get the custom mbr back...

  • what is your favorite anti virus ? 

  • @mrizos

    hey man nice vids but just went onto task manager and seen loads of svchosts.exe what shall i do

  • Matt when you download malware virus and stuff to a Virtual Machine on your actual PC, do you risk getting your actual PC infectet?

    I am a little insecure about that...

    Please reply so I don't do something stupid...

  • I think this is what my brother has, but how do I get rid of it? I ran Superantispyware, malwarebytes, and tdss killer, but that won't find anything sas just finds traces. But it is still not fixed.

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more