09-24-2010 01:06 PM
What is the sceenshot above of and what it means??
And this page http://community.norton.com/t5/Norton-Internet-Sec
Quads
10-26-2010 05:00 PM
Looks like Boot.Tidserv (TDL4) Bootkit will cause patched / cracked versions of Windows 7 to become non bootable
Quads
12-08-2010 03:13 PM
TDL4 is now being seen using or trying to use the Task Scheduler Privilege Escalation vulnerability as that appeared as seen with W32.Stuxnet
Quads
03-13-2011 02:50 PM
TDL4 has a version change, from 0.15 to 0.169
Can still cause this major problem
On running the installer The Computer shuts down or restarts. The computer will not POST or enter bios setup, will only show bios logo and then blinking cursor in top left no matter boot device selected.
Quads
03-14-2011 01:09 AM
Is Norton able to detect?
"Or" has the version change made it harder to detect!
Midou
04-02-2011 06:07 PM
There are still FakeAV (Rogues) appearing with the TDL2 like PRAGMA, _VOID, H8SRT group.
Looks like more in the Rogues like HDD Rescue, Windows Recovery and the defragmenters.
Quads
04-12-2011 07:40 PM
Looks like Microsoft is trying to combat TDL4.03 on x64 systems.
http://www.microsoft.com/technet/security/advisory
Quads
04-30-2011 07:12 PM
Looks like there is a new TDL4 that gets around the Microsoft patch, and stops TDSSkiller from completeing the scan. Other tools may not detect the newbie or cannot cure it.
Quads
05-01-2011 04:00 PM
05-02-2011 06:19 PM
Infected the PC with a new sample of Tidserv / TDSS /TDL4
One sample though places a randomly named file with registry key so that when the MBR gets cured on the restart (or after using a CD/DVD to fix) on the startup the MBR gets reinfected again, and again and again. The registry key and /or random file has to be dealt with first, before dealing with the MBR, otherwise you would be going around in circles somewhat.
Quads
