The “TDL-4″ botnet now has more than 4.5 million infected PCs running on it and is the “most sophisticated threat” to computer security today, according to Kaspersky Labs researcher Sergey Golovanov.
"Microsoft’s Windows operating system, running on a 64-bit machine provides enhanced security with driver signing of system and low level drivers. This policy, called the kernel mode code signing policy, disallows any unauthorized or malicious driver to be loaded.
The TDL4 rootkit bypasses driver signing policy on 64-bit machines by changing the boot options of Microsoft boot programs that will allow an unsigned driver to load."