View Full Version : AntiVir and TDSS rootkit
Durad
September 1st, 2009, 10:51 AM
AntiVir is installed and up to date, it does not detect TDSS rootkit, if I extract infected files all of them are detected.
Toby75
September 1st, 2009, 11:23 AM
Most AV's won't. It can't do any damage if it's zipped or archived. It's only when it's extracted that it will be detected and prevented from executing.
Durad
September 1st, 2009, 01:37 PM
Let me explane better:
AntiVir is installed and up-to-date
TDSS is running and active
AntiVir does not detect it
if I use LIVECD and extract files to USB stick and scan with AntiVIr than it detect all files.
So the thing is that AntiVir is unable to detect TDSS on already infected machine.
dawgg
September 1st, 2009, 02:05 PM
Doesnt Avira even detect it if you do a scan with all settings at Max?
Julian
September 1st, 2009, 02:47 PM
There are plenty of TDSS variants, no AV detects them all. But a good HIPS should help, KIS should even all block of them in auto mode.
On Windows x64 no TDSS variant should be working.
Edit: Oops, seems like active sample was meant here.
Durad
September 1st, 2009, 03:59 PM
Everything on maximum...
Habakuck
September 1st, 2009, 05:35 PM
-{ Quote: "Let me explane better:
AntiVir is installed and up-to-date
TDSS is running and active
AntiVir does not detect it
if I use LIVECD and extract files to USB stick and scan with AntiVIr than it detect all files.
So the thing is that AntiVir is unable to detect TDSS on already infected machine." }-
Öhm, you exactly described how a rootkit works. :lurking: It hides infected files from the system. So the file is hidden from the AV too.
LiveCD system is not affected so the files can be caught.
tgell
September 1st, 2009, 06:26 PM
Durad,
Are you testing this rootkit on a virtual machine or are you actually infected? See if this will remove it.
http://www.esagelab.com/projects/
http://www.esagelab.com/files/tdss_remover_latest.rar
Meriadoc
September 2nd, 2009, 02:09 AM
-{ Quote: "AntiVir does not detect it" }-
Is this a surprise...really?
Macstorm
September 2nd, 2009, 03:24 AM
Hmm I'm tempted to infect my own rig to try it ;)
the avira forum has its own room to discuss issues related to malware. link (http://forum.avira.com/wbb/index.php?page=Board&boardID=140)
Saraceno
September 2nd, 2009, 03:43 AM
Without comparing products, if you're still testing, does Hitman Pro remove it? There was a video showing it removing the TDSS rootkit, and it uses Avira as one of its removal engines.
Macstorm
September 2nd, 2009, 09:59 PM
BTW Durad, for a proper rootkit search you have to start a dedicated scan task from the GUI: Local protection tab | Scanner | Rootkit search
dawgg
September 3rd, 2009, 10:00 AM
-{ Quote: "Öhm, you exactly described how a rootkit works. :lurking: It hides infected files from the system. So the file is hidden from the AV too.
LiveCD system is not affected so the files can be caught." }-
... but it the AV's job to detect malware and most AVs and other specialist removal tools are indeed capable of detecting rootkit infections, and have been able to do so for some time now.
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums