Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old November 29th, 2010, 09:41 AM
AaLl86 AaLl86 is offline
Infrequent Poster
 
Join Date: Nov 2010
Location: Milan, Italy
Posts: 4
Lightbulb My AntiTdl Software

Hi All!
I'm new in this community. I'll introduce myself: my name is Andrea and i'm an italian "unemployed" security researcher.
I would like to present my implementation of TDL3 Removal Tool. Is a personal big project, it runs on Windows Xp, Vista, 7, on all 32 bit platform (no 64 bit already). It's still in alpha but fully working. It doesn't support RAID software system like Windows Dynamic disk. This is the only limitation it has.

I'll appreciative if some of you can test it.... the link is:
-aall86.altervista.org/files/AntiTdl_0.1.zip-

Tell me what do you think, and sorry for my english but it's not my native language...

Have a nice day.
Andrea
  #2  
Old November 29th, 2010, 09:53 AM
The_ChamP's Avatar
The_ChamP The_ChamP is offline
Very Frequent Poster
 
Join Date: Mar 2010
Location: Mumbai
Posts: 1,145
Default Re: My AntiTdl Software

u have not put any address in ur link
__________________
7 x64 Pro + WSA + Mbam Free + HMP + Shadowdefender + Macrium free
  #3  
Old November 29th, 2010, 11:02 AM
eBBox's Avatar
eBBox eBBox is offline
Frequent Poster
 
Join Date: Aug 2006
Location: Aalborg, Denmark
Posts: 481
Default Re: My AntiTdl Software

Quote:
Originally Posted by The_ChamP
u have not put any address in ur link

The link is there Just remove this: "-" in the beginning and this "-" in the end without qoutes.
__________________
Many good security options these days
  #4  
Old November 29th, 2010, 11:12 AM
The_ChamP's Avatar
The_ChamP The_ChamP is offline
Very Frequent Poster
 
Join Date: Mar 2010
Location: Mumbai
Posts: 1,145
Default Re: My AntiTdl Software

oh yea rite..my mistake
__________________
7 x64 Pro + WSA + Mbam Free + HMP + Shadowdefender + Macrium free
  #5  
Old November 29th, 2010, 12:02 PM
AaLl86 AaLl86 is offline
Infrequent Poster
 
Join Date: Nov 2010
Location: Milan, Italy
Posts: 4
Default Re: My AntiTdl Software

Quote:
Originally Posted by The_ChamP
u have not put any address in ur link
It's strange... i've written the link but the system automatically change it. The right link is: -aall86.altervista.org/files/AntiTdl_0.1.zip-

Thx
  #6  
Old November 29th, 2010, 02:10 PM
De Hollander's Avatar
De Hollander De Hollander is offline
Frequent Poster
 
Join Date: Sep 2005
Location: Windmills and cows
Posts: 688
Default Re: My AntiTdl Software

Side note: according to (VirusTotal) McAfee-GW-Edition 2010.1C / 2010.11.29 /triggers a Heuristic.BehavesLike.Win32.Rootkit.H alert with AntiTDL.sys.
  #7  
Old November 30th, 2010, 01:53 AM
RejZoR's Avatar
RejZoR RejZoR is offline
Polymorphic Sheep
 
Join Date: May 2004
Location: Europe/Slovenia/Ljubljana
Posts: 5,366
Default Re: My AntiTdl Software

There is always something that will trigger their crap on something. Same is for my .NET Framework 4 fix. Bunch of heuristic detections just because i used an EXE wrapper for BAT.
__________________
RejZoR's Little Secrets
  #8  
Old November 30th, 2010, 04:34 AM
AaLl86 AaLl86 is offline
Infrequent Poster
 
Join Date: Nov 2010
Location: Milan, Italy
Posts: 4
Default Re: My AntiTdl Software

No, sorry but my software is not a virus.... I can guarantee for it....
Is an antivirus software in alpha Version... try it if you would.... and tell me what do you think....

I don't know why Mcafee consider it a virus :-(

Btw, Meriadoc, i'm not abler to answer you in pm....


Quote:
Originally Posted by De Hollander
Side note: according to (VirusTotal) McAfee-GW-Edition 2010.1C / 2010.11.29 /triggers a Heuristic.BehavesLike.Win32.Rootkit.H alert with AntiTDL.sys.
  #9  
Old November 30th, 2010, 04:57 AM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: My AntiTdl Software

Quote:
AntiTDL.sys
f/p due to enthusiastic McAfee 'flag everything' heuristics.

Andrea pm box emptied.
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #10  
Old November 30th, 2010, 05:54 AM
De Hollander's Avatar
De Hollander De Hollander is offline
Frequent Poster
 
Join Date: Sep 2005
Location: Windmills and cows
Posts: 688
Default Re: My AntiTdl Software

Just submitted your file to

virus_research@avertlabs.com
http://vil.nai.com/vil/submit-sample.aspx
https://www.webimmune.net/default.asp

and maybe they will respond to fix the false positive
  #11  
Old November 30th, 2010, 06:24 AM
richo richo is offline
Regular Poster
 
Join Date: Jul 2005
Posts: 62
Default Re: My AntiTdl Software

So what exactly is your software supposed to do?
  #12  
Old November 30th, 2010, 07:04 AM
Baz_kasp's Avatar
Baz_kasp Baz_kasp is offline
Frequent Poster
 
Join Date: May 2008
Location: London
Posts: 593
Default Re: My AntiTdl Software

Quote:
Originally Posted by richo
So what exactly is your software supposed to do?

Read the first post.....

Quote:
I would like to present my implementation of TDL3 Removal Tool.
  #13  
Old December 1st, 2010, 02:27 AM
Arin's Avatar
Arin Arin is offline
Frequent Poster
 
Join Date: May 2004
Location: India
Posts: 997
Default Re: My AntiTdl Software

Its the GW version, so has to employ paranoid heuristics.

Why would I be interested in an alpha version of TDL3 removal tool where there are stable versions from well known vendors?

Also this seems to be your first thread in this forum. How can I be sure that it is not a RK itself? You might have the best intention but I guess the approach could've been better.

If you really say who you are then you might want to put it in the KM forum which is administered by EP_X0FF. That is the ultimate destination for all ARK tools.

Thank you for the tool though. All the best.
__________________
If it was so, it might be; and if it were so, it would be; but as it isn't, it ain't. That's logic. ~ Twiddledee
  #14  
Old December 1st, 2010, 03:17 AM
AaLl86 AaLl86 is offline
Infrequent Poster
 
Join Date: Nov 2010
Location: Milan, Italy
Posts: 4
Default Re: My AntiTdl Software

http://www.kernelmode.info/forum/vie...php?f=11&t=504

I didn't know that forum before Meriadoc tell me of its existence....
Btw if you don't trust in this project you are free to not use it.... I'm not a malware writers, even if i think that TDL authors are the very very very good security devs....

Andrea

Quote:
Originally Posted by Arin
Its the GW version, so has to employ paranoid heuristics.

Why would I be interested in an alpha version of TDL3 removal tool where there are stable versions from well known vendors?

Also this seems to be your first thread in this forum. How can I be sure that it is not a RK itself? You might have the best intention but I guess the approach could've been better.

If you really say who you are then you might want to put it in the KM forum which is administered by EP_X0FF. That is the ultimate destination for all ARK tools.

Thank you for the tool though. All the best.
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:14 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums