A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #1757  by SecConnex
 Wed Aug 04, 2010 6:00 pm
Apparently, Greatis product RegRun Warrior can detect and possibly remove TDL3 infection.

I have not tried. I hope someone else can.

The tool: http://www.greatis.com/security/RegRun_Warrior.htm


Note: I have saw many malware blogs from them showing a file infected by TDL3, and in the blog it shows it was detected by RegRun Warrior. Also, their tool UnHackMe might be a claim to detect TDL3 as well.

Also, this comment on the RegRun Warrior page bothers me:
"1. Virus removal is a simple when the virus is not active. The Warrior allows you to scan your computer from the "clean" Windows PE system."
 #1789  by EP_X0FF
 Thu Aug 05, 2010 5:30 am
This fake is paid, TDL3 detection is based on checking of mutex presence.
3006345f-6baf-4669-a7e1-aaa310564be9
This is not detection this is total fake. Interesting what will be if I will create the same named mutex on clean system? TDL3 infection verdict? :mrgreen: Apparently you don't need buggy paid sh*t from Dmitri Sokolov to remove TDL3 while system is _offline_. There is nothing to fix in registry.
There are a lot of free trustworthy tools for detection/removal of TDL3 available.
  • 1
  • 28
  • 29
  • 30
  • 31
  • 32
  • 40