Nobody loves malware developers – apparently, not even other malware developers. A fight between a devious rootkit creator and a backstabbing patron proves the old adage: all’s fair in love and (cyber) war.

The Register broke the story about an unknown Russian hacker who sells his rootkit code, called TDL, online. Even hackers have to eat, right? Unfortunately for him, one particular sale provided him with enough humble pie to last a lifetime.
A group that snapped up TDL evolved it into ZeroAccess – a variant that actually undoes damage wrought by TDL. In other words, if your PC is infected by TDL and then you catch ZeroAccess, TDL is removed from your system.
The Register spoke to Jacques Erasmus, a malware expert at Webroot, who provided the site with his technical expertise. The ongoing feud centers around the malware’s latest iteration TDL3, he said. Erasmus explained that a specific module called Anti-TDL is actually what’s eradicating the infection. The cyber guru believes the group that designed ZeroAccess purposely took the time to craft anti-TDL. Competition among illegal code jockeys is a brutal thing.
Colorado-based Webroot specializes in identifying and solving Internet security threats. Its Threat Blog has previously covered the pitfalls of ZeroAccess. One variant of the rootkit can effectively render anti-virus software useless via a “virtual tripwire.” While deleting TDL is a pleasant side effect, it’s still not something you want clinging to your system’s innards. (via PC World)
Have you encountered TDL or its bastard child ZeroAccess and lived to tell the tale? Let us know in the comment section.
1 Comments on Windows rootkit battle proves there’s no honor among thieves

MIchael
Most popular headlines
Windows Blue to allow boot to desktop and brings start menu back? (3)
- Tue 16 Apr 16:12 by DoMiN8ToR
- Software, Windows 8
The upcoming update of Windows 8 might allow users to boot to the desktop again.
Jobs in US entertainment industry on all-time high - piracy?! (8)
- Fri 12 Apr 15:10 by DoMiN8ToR
- Piracy
The number of jobs in the film and music industry in the United States has increased despite the claimed negative effects of illegal downloads.
The Piratebay domain moves to Greenland - circumvents blockade (3)
- Tue 9 Apr 14:23 by DoMiN8ToR
- Piracy
The PirateBay has moved to the domain thepiratebay.gl in fear that their previous domain would be ceased by Swedish authorities
Intel 9 series chipset has native SATA Express (SATA over PCIe) support (2)
- Wed 17 Apr 13:57 by DoMiN8ToR
- Solid State (ssd)
A Chinese tech site has posted a picture that reveals details on Intel's 9 series chipset.


