<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TDL evolving in Tech Outpost</title>
    <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/461276#M3417</link>
    <description>&lt;p&gt;We have had Maax++ infected users turn up on this forum in the past &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
    <pubDate>Thu, 26 May 2011 00:00:40 GMT</pubDate>
    <dc:creator>Quads</dc:creator>
    <dc:date>2011-05-26T00:00:40Z</dc:date>
    <item>
      <title>TDSSkiller / TDL4</title>
      <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/232195#M1043</link>
      <description>&lt;p&gt;TDSSkiller now correctly detects and cures TDL4  (as of Today)&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I tested only like 10 minutes ago, The scan checks via the raw I/O.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Screenshot below, plus attached to this post is the log of the scan&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;img src="/t5/image/serverpage/image-id/5674i1F26ADBB805CF776/image-size/original?v=mpbl-1&amp;amp;px=-1" align="center" alt="5674i1F26ADBB805CF776" title="5674i1F26ADBB805CF776" border="0"&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Be aware though if you are infected with more than TDL3 / TDL4,  like the thread for houston,&lt;/p&gt;&lt;p&gt;&lt;a href="http://community.norton.com/t5/Other-Norton-Products/Ads-popping-up-randomly-and-cannot-open-task-manager/td-p/229633" target="_blank" rel="nofollow"&gt;http://community.norton.com/t5/Other-Norton-Products/Ads-popping-up-randomly-and-cannot-open-task-manager/td-p/229633&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;This may mean that TDSSkiller may not work due to other Malware blocking it. Other Malware may have to be stopped first and maybe removed before using TDSSkiller.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Multiple infections have to be stopped a lot of the time in the correct order of steps.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Mon, 17 May 2010 21:53:14 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/232195#M1043</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2010-05-17T21:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: TDSSkiller / TDL4</title>
      <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/232740#M1056</link>
      <description>&lt;p&gt;The latest TDL (Tidserv)  I have found, &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.virustotal.com/analisis/1531b39e217bbac673b621b0f6a5f020ebae48a216832cf3d038ff65d46d1883-1274240886" target="_blank" rel="nofollow"&gt;http://www.virustotal.com/analisis/1531b39e217bbac673b621b0f6a5f020ebae48a216832cf3d038ff65d46d1883-1274240886&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I have the list of servers (not posted here)&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Wed, 19 May 2010 09:34:01 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/232740#M1056</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2010-05-19T09:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: TDSSkiller / TDL4</title>
      <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/232787#M1058</link>
      <description>&lt;p&gt;UPDATE:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;After infecting the PC with the latest installer,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;TDSSkiller, Did not detect the driver&lt;/p&gt;&lt;p&gt;TDSS Remover,  Did not detect the driver&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.virustotal.com/analisis/474509fae08f6040fc69366d628ac7e23645e53e41d3882f2375d2773196daf4-1274276299" target="_blank" rel="nofollow"&gt;http://www.virustotal.com/analisis/474509fae08f6040fc69366d628ac7e23645e53e41d3882f2375d2773196daf4-1274276299&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Intrusion Prevention &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;img src="/t5/image/serverpage/image-id/5726i9777F50E47B96998/image-size/original?v=mpbl-1&amp;amp;px=-1" align="center" alt="5726i9777F50E47B96998" title="5726i9777F50E47B96998" border="0"&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;For some reason, (maybe something went wrong, but I had to swap &amp;quot;kernel32.dll&amp;quot; over to.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Wed, 19 May 2010 14:11:24 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/232787#M1058</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2010-05-19T14:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: TDSSkiller / TDL4</title>
      <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/232999#M1063</link>
      <description>&lt;p&gt;I did find a product that doesn't need to be installed scanned and detected the infected swapped drivers,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;One Problem, it deleted the drivers while still scanning, didn't wait and ask the user if the files were to be deleted, Just deleted.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; Quads&lt;/p&gt;</description>
      <pubDate>Thu, 20 May 2010 01:10:30 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/232999#M1063</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2010-05-20T01:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: TDSSkiller / TDL4</title>
      <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/233383#M1064</link>
      <description>&lt;p&gt;Thanks Quads&lt;/p&gt;&lt;p&gt;Does not look like they are slowing down in producing these things.:smileysad:&lt;/p&gt;</description>
      <pubDate>Fri, 21 May 2010 01:45:11 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/233383#M1064</guid>
      <dc:creator>mo</dc:creator>
      <dc:date>2010-05-21T01:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: TDSSkiller / TDL4</title>
      <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/234050#M1069</link>
      <description>&lt;p&gt;It the &amp;quot;&lt;strong&gt;Backdoor.TDSS.2459&lt;/strong&gt;&amp;quot; variant  that TDSSkiller and TDSS Remover can't detect&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Sun, 23 May 2010 04:29:17 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/234050#M1069</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2010-05-23T04:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: TDSSkiller / TDL4</title>
      <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/234355#M1073</link>
      <description>&lt;p&gt;There are Rogues one being &amp;quot;Data Protection&amp;quot; that come with a TDL2 variant &amp;quot;PRAGMA&amp;quot;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;hr&gt;&lt;p&gt; &lt;/p&gt;&lt;div&gt;Windows Registry Editor Version 5.00&lt;/div&gt;&lt;div&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\PRAGMA]&lt;/div&gt;&lt;div&gt;&amp;quot;slrd&amp;quot;=dword:00000018&lt;/div&gt;&lt;div&gt;&amp;quot;slrm&amp;quot;=dword:00000005&lt;/div&gt;&lt;div&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\PRAGMA\injector]&lt;/div&gt;&lt;div&gt;&amp;quot;explorer.exe&amp;quot;=&amp;quot;pragmaserf&amp;quot;&lt;/div&gt;&lt;div&gt;&amp;quot;iexplore.exe&amp;quot;=&amp;quot;pragmaserf;pragmabbr&amp;quot;&lt;/div&gt;&lt;div&gt;&amp;quot;firefox.exe&amp;quot;=&amp;quot;pragmabbr&amp;quot;&lt;/div&gt;&lt;div&gt;&amp;quot;safari.exe&amp;quot;=&amp;quot;pragmabbr&amp;quot;&lt;/div&gt;&lt;div&gt;&amp;quot;chrome.exe&amp;quot;=&amp;quot;pragmabbr&amp;quot;&lt;/div&gt;&lt;div&gt;&amp;quot;opera.exe&amp;quot;=&amp;quot;pragmabbr&amp;quot;&lt;/div&gt;&lt;div&gt;&lt;hr&gt;&lt;/div&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.virustotal.com/analisis/d159f0059cfb2f1919cd4017e197a9167eca556fd2d32e02fea04ac7c1fd7bb2-1274670145" rel="nofollow" target="_blank"&gt;http://www.virustotal.com/analisis/d159f0059cfb2f1919cd4017e197a9167eca556fd2d32e02fea04ac7c1fd7bb2-1274670145&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;a rel="nofollow" href="http://www.threatexpert.com/report.aspx?md5=0d41357d15d5cff6ac74a81fd314779d" target="_blank"&gt;http://www.threatexpert.com/report.aspx?md5=0d41357d15d5cff6ac74a81fd314779d&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;With the ability to try and uninstall Security Software as part of the rogue&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Mon, 24 May 2010 09:51:59 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/234355#M1073</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2010-05-24T09:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: TDSSkiller / TDL4</title>
      <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/234848#M1079</link>
      <description>&lt;p&gt;Interesting I was reading the Symantec &amp;quot;Backdoor.Tidserv&amp;quot;  Writeup&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Warning, it's a mix and match of different TDL2's and TDL3's &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Including this entry&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&amp;quot;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\H8SRTd.sys&amp;quot; which actually belongs to &amp;quot;Backdoor.Tidserv.J&amp;quot;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I can see how people reading the writeup are going to get confused, seeing the different variants in one writeup. When a lot of the variants have to be looked at separately due to differences &lt;/p&gt;&lt;p&gt;Including differences in the removal procedures and programs used.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Sure a PC may be infected with more than one TDL2 (more than on set of files and registry entries) or TDL2 +TDL3. But the removal of them have to be looked at differently.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;TDL2's   can have it's files and registry entries removed / deleted (correctly),               TDL3's this is not the case&lt;/p&gt;&lt;p&gt;TDL3's   the infected driver (disk controller)  has to be swapped with a clean copy,    TDL2's this is not the case&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;TDL3 Infected drivers detected as &amp;quot;Backdoor.Tidserv!inf&amp;quot;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Tue, 25 May 2010 22:31:51 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/234848#M1079</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2010-05-25T22:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: TDSSkiller / TDL4</title>
      <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/234995#M1081</link>
      <description>&lt;p&gt;Nice work , Quads&lt;/p&gt;</description>
      <pubDate>Wed, 26 May 2010 14:57:44 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/234995#M1081</guid>
      <dc:creator>Stu</dc:creator>
      <dc:date>2010-05-26T14:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: TDSSkiller / TDL4</title>
      <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/236530#M1093</link>
      <description>&lt;p&gt;TDSSkiller has been updated again&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Mon, 31 May 2010 22:17:24 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/236530#M1093</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2010-05-31T22:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: TDSSkiller / TDL4</title>
      <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/237270#M1099</link>
      <description>&lt;p&gt;One version on TDSS (Tidserv) creates these entries and fools some removal programs in to thinking a Windows file like &amp;quot;userinit.exe&amp;quot; or &amp;quot;kernel32.dll&amp;quot; is infected when the Windows file seems clean Although it could have tried to infect a driver but failed due to some sort of flaw in the file I got. A bug inside a bug.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;div&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\[file name].exe&lt;/div&gt;&lt;div&gt;C:\WINDOWS\system32\ernel32.dll&lt;/div&gt;&lt;div&gt;C:\System Volume Information\_restore{3CE24A12-6763-49ED-BA82-A731C&lt;span class="wbr"&gt; &lt;/span&gt;C696DD0}\RP1\A0000056.dll&lt;/div&gt;&lt;div&gt;C:\WINDOWS\system32\spool\prtprocs\w32x86\[random].dll  (can be a few created in that folder)&lt;/div&gt;&lt;div&gt;C:\documents and settings\[username]\application data\[random].exe&lt;/div&gt;&lt;div&gt;Scheduler change: Tasks: d:\windows\tasks\mswd-[random].job&lt;/div&gt;&lt;div&gt;DNS Changer&lt;/div&gt;&lt;div&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{8F5D3DA0-7FC8-4&lt;span class="wbr"&gt; &lt;/span&gt;9DF-B703-88E747973326}: NameServer = 93.188.162.167,93.188.166.198&lt;/div&gt;&lt;div&gt;O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 93.188.162.167,93.188.166.198&lt;/div&gt;&lt;div&gt;O17 - HKLM\System\CS1\Services\Tcpip\..\{8F5D3DA0-7FC8-4&lt;span class="wbr"&gt; &lt;/span&gt;9DF-B703-88E747973326}: NameServer = 93.188.162.167,93.188.166.198&lt;/div&gt;&lt;div&gt;O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 93.188.162.167,93.188.166.198&lt;/div&gt;&lt;div&gt;O17 - HKLM\System\CS3\Services\Tcpip\..\{8F5D3DA0-7FC8-4&lt;span class="wbr"&gt; &lt;/span&gt;9DF-B703-88E747973326}: NameServer = 93.188.162.167,93.188.166.198&lt;/div&gt;&lt;div&gt;O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.162.167,93.188.166.198&lt;/div&gt;&lt;div&gt;Quads&lt;/div&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Thu, 03 Jun 2010 02:53:48 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/237270#M1099</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2010-06-03T02:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: TDSSkiller / TDL4</title>
      <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/237634#M1105</link>
      <description>&lt;p&gt;Good to know they make mistakes as well...:smileysurprised:&lt;/p&gt;</description>
      <pubDate>Fri, 04 Jun 2010 03:35:09 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/237634#M1105</guid>
      <dc:creator>mo</dc:creator>
      <dc:date>2010-06-04T03:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: TDSSkiller / TDL4</title>
      <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/237822#M1111</link>
      <description>&lt;p&gt;Mo&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I'm not sure is a bug or with someone trying to change things but has left something out of the installer (programming) but this one is to easy for those who can deal to TDL 2, 3, 4 successfully&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I got another installer from a Malware researcher I ran the installer and it's the same,  with  &amp;quot;TDL with a twist&amp;quot;.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;It's a matter of whether this is like a beta or first build of this change and so will only get better over time.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Sat, 05 Jun 2010 00:05:25 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/237822#M1111</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2010-06-05T00:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: TDSSkiller / TDL4</title>
      <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/237824#M1112</link>
      <description>&lt;p&gt;Ok I will sound like a dunce but you meant there was a mistake in the TDL removal software or a mistake/programming error in the TDL itself...sorry if I am a bit slow...:smileywink:&lt;/p&gt;</description>
      <pubDate>Sat, 05 Jun 2010 00:12:48 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/237824#M1112</guid>
      <dc:creator>mo</dc:creator>
      <dc:date>2010-06-05T00:12:48Z</dc:date>
    </item>
    <item>
      <title>Re: TDSSkiller / TDL4</title>
      <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/237826#M1113</link>
      <description>&lt;p&gt;A mistake in the TDL, TDSS, Tidserv malware itself.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Sat, 05 Jun 2010 00:32:00 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/237826#M1113</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2010-06-05T00:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: TDSSkiller / TDL4</title>
      <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/238117#M1115</link>
      <description>&lt;p&gt;Thanks for making it clearer.Do you think they know it's there and will correct it?&lt;/p&gt;</description>
      <pubDate>Sun, 06 Jun 2010 06:34:39 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/238117#M1115</guid>
      <dc:creator>mo</dc:creator>
      <dc:date>2010-06-06T06:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: TDSSkiller / TDL4</title>
      <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/239471#M1133</link>
      <description>&lt;p&gt;I'm starting to think these things are like unraveling DNA code...  :smileyvery-happy:&lt;/p&gt;</description>
      <pubDate>Thu, 10 Jun 2010 17:54:17 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/239471#M1133</guid>
      <dc:creator>TracyLCraw</dc:creator>
      <dc:date>2010-06-10T17:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: TDSSkiller / TDL4</title>
      <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/239500#M1136</link>
      <description>&lt;blockquote&gt;&lt;hr&gt;TracyLCraw wrote:&lt;br&gt;&lt;p&gt;I'm starting to think these things are like unraveling DNA code...  :smileyvery-happy:&lt;/p&gt;&lt;hr&gt;&lt;/blockquote&gt;&lt;p&gt;Somewhat similar:smileyhappy:&lt;/p&gt;</description>
      <pubDate>Thu, 10 Jun 2010 20:06:55 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/239500#M1136</guid>
      <dc:creator>mdturner</dc:creator>
      <dc:date>2010-06-10T20:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: TDSSkiller / TDL4</title>
      <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/239775#M1153</link>
      <description>&lt;p&gt;Articles on TDL (1,2,3 &amp;amp; unofficial 4) there are other names it's known as.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Has hit number 1&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="nofollow" href="http://www.infoworld.com/t/malware/four-year-old-rootkit-tops-the-charts-pc-threats-791"&gt;http://www.infoworld.com/t/malware/four-year-old-rootkit-tops-the-charts-pc-threats-791&lt;/a&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Pesky rootkit looks like it's getting refined for attacks&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Remember Alureon, the pesky rootkit, which hit the Windows enterprise scene in 2006 and absolutely &lt;a target="_blank" href="http://campustechnology.com/articles/2010/03/03/microsoft-reissues-windows-kernel-patch.aspx" rel="nofollow"&gt;bum rushed&lt;/a&gt; some Windows systems earlier this year?&lt;/p&gt;&lt;p&gt;Microsoft does and will for quite some time. The rootkit, which also goes by some of its technical aliases -- TDSS, Zlob and DNSChanger -- has to date infected nearly 2 million Windows systems.&lt;/p&gt;&lt;p&gt;Alureon is the guest of honor rootkit in Microsoft's recently released May Threat Report. Alureon accounted for 18 percent of all malware-infected Windows PCs in May.&lt;/p&gt;&lt;p&gt;This is Alureon's encore performance as the &lt;em&gt;rootkit du jour&lt;/em&gt; in the &lt;a target="_blank" href="http://blogs.technet.com/b/mmpc/archive/2010/04/30/msrt-april-threat-reports-alureon.aspx" rel="nofollow"&gt;April Threat Report&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Alureon is considered the culprit for the &amp;quot;screen of death,&amp;quot; and system crash issues widely reported when users installed &lt;a target="_blank" href="http://www.microsoft.com/technet/security/bulletin/ms10-015.mspx" rel="nofollow"&gt;Microsoft Security Bulletin MS10-015&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Microsoft Malware Prevention Center staffers Vishal Kapoor and Joe Johnson said there were &amp;quot;several changes to the design of the rootkit to avoid detection and cleaning, revealing that the rootkit is still under active development and distribution.&amp;quot;&lt;/p&gt;&lt;p&gt;This means that Alureon is going to be around for a while yet&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;By Jabulani Leffall&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;At least it can't beat Quads for PC's that turn up at my door :smileyvery-happy: :smileyvery-happy:&lt;/p&gt;&lt;p&gt;Bring on the next change &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads&lt;/p&gt;</description>
      <pubDate>Fri, 11 Jun 2010 22:15:53 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/239775#M1153</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2010-06-11T22:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: TDSSkiller / TDL4</title>
      <link>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/240145#M1164</link>
      <description>&lt;p&gt;Nice article that you linked to thanks!&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads to you play detective with this stuff?&lt;/p&gt;</description>
      <pubDate>Sun, 13 Jun 2010 19:12:12 GMT</pubDate>
      <guid>http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/240145#M1164</guid>
      <dc:creator>TracyLCraw</dc:creator>
      <dc:date>2010-06-13T19:12:12Z</dc:date>
    </item>
  </channel>
</rss>

