![]() |
|
#1
|
|||
|
|||
|
I've looked for an antivirus that can prevent a TDSS infection and only found cleanup tools AFTER the infection. Is there an antivirus that actually prevents a TDSS infection?
Thanks |
|
#2
|
||||
|
||||
|
First: TDSS is dead. There are no new samples of it itw since a long time.
Second: All AVs should detect exisiting samples and droppers per signature. Third: Some AVs also proactive detect the methods known TDL samples used in the past. (f.e. EAM, KIS,...) |
|
#3
|
|||
|
|||
|
"First: TDSS is dead. There are no new samples of it itw since a long time."
D0C23926925123071B143F717B7ADC7D 24CEA1FD12E4C9C99B6D0779DC923895 These both dropped from exploits this month and were undetected at 0hour. I just rechecked the newest one and it is up to about 40% detected. ITW you will see MBAM logs containing Trojan.Agent.BRVGen. Ping me if you want the samples.
__________________
Bruce Harrison Malwarebytes Lead Researcher |
|
#4
|
||||
|
||||
|
Then look elsewhere.How about adding Sandboxie to your setup or AppGuard or both.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB. |
|
#5
|
|||
|
|||
|
Quote:
__________________
How to Stay Safe While Online |
|
#6
|
|||
|
|||
|
Thanks Chiron. I'm already using Comodo Firewall and didn't know it had that capability. Learning new things everyday.
Keep safe |
|
#7
|
|||
|
|||
|
Quote:
Have you already read my guide here?
__________________
How to Stay Safe While Online |
|
#8
|
|||
|
|||
|
Thanks again Chiron for the install manual. Nice and simple "how to" for Comodo Firewall. I followed your instructions and believe I am more secure for doing so.
Stay Safe |
|
#9
|
||||
|
||||
|
Most AV's should be able to detect the old TDSS variants.
![]()
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736 SRP - UAC - EMET Browser: Google Chrome v25.xx Windows 7 Ultimate x64 |
|
#10
|
|||
|
|||
|
Run as a limited user
The infection comes from the usual dropper from P2P networks or by warez websites, and it needs admin rights to run its payload. If UAC is OFF(disabled) or the user manually gives admin rights, then TDSS can infect even Windows Vista and Windows 7. This is likely to be the usual scenario, where a user looks for specific cracks,patches,pornography and don't mind if UAC warns him, he gives admin privileges to the wanted file. And finally gets infected. regards, icr ![]()
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01101001 01100011 01110010 --->My Blog<--- |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|