A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #1688  by Meriadoc
 Fri Jul 30, 2010 1:56 am
Quads wrote:I wonder if the TDSS update for SAS was for detection of TDL2 variants (PRAGMA, H8SRT, _VOID etc.)

Quads
Detects but doesn't remove.
 #1689  by SecConnex
 Fri Jul 30, 2010 2:16 am
PRAGMA* is for a separate detection, since it is not TDSS itself. Instead it is Trj.Kryptik using TDL2's rootkit techniques. It lacks a few symptoms that TDSS encompasses.
 #1692  by EP_X0FF
 Fri Jul 30, 2010 6:45 am
I tested TDL3+ (posted on previous page) against Prevx 3.0, because I've heard some rumors about "super powers" inside this tool few month ago and "private technologies" somewhere inside Prevx which is able to detect and remove TDL3. As expected this calculator is totally blind and additionally flagged clean msvcrt.dll from clean Windows XP installation as malicious.
 #1694  by Buster_BSA
 Fri Jul 30, 2010 8:19 am
Seems like PrevX has good professionals of marketing with them but the reality is that sometimes PrevX is just more smoke than any other thing.

Reading some comments about PrevX someone may thing is kinda an esoteric security product. :o :D
 #1698  by PX5
 Fri Jul 30, 2010 1:11 pm
All you heard was rumor, Prevx has never claimed to be able to see this infection, much less remove it.

We have standalone private tools for tdl3, thats it. ;)
  • 1
  • 27
  • 28
  • 29
  • 30
  • 31
  • 40