Monday, March 1, 2010

Clicking on a search result redirects to a bad page!

I clicked on one of the links sent by a friend as a FB message. The link took me to a youtube page that said I needed Adobe Flash Player 10.0. Being dumb (as usual I guess :P), I clicked on the install link and voila! there comes the TDL3. TDL3 is a variant of TDSS rootkit (Alureon), a virus. This virus basically registers itself as a print processor. Since the print subsystem (spoolsv.exe) has administrative rights, it is a trusted part of Microsoft Windows. Hence, a typical virus scanner cannot detect this virus. I ran a full system scan and found no infection. On searching online (of course in another computer!), I found Hitman Pro . Checkout the same website on how the virus eludes anti-virus software and re-directs search results. Downloading Hitman Pro and running the system scan got rid of TDL3. Now this is experience!