Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 12th, 2012, 02:01 PM
nozzle nozzle is offline
Infrequent Poster
 
Join Date: Jul 2012
Location: San Diego, CA
Posts: 22
Default TDSS Prevention

I've looked for an antivirus that can prevent a TDSS infection and only found cleanup tools AFTER the infection. Is there an antivirus that actually prevents a TDSS infection?

Thanks
  #2  
Old August 12th, 2012, 02:12 PM
SLE's Avatar
SLE SLE is offline
Regular Poster
 
Join Date: Jun 2011
Posts: 175
Default Re: TDSS Prevention

First: TDSS is dead. There are no new samples of it itw since a long time.
Second: All AVs should detect exisiting samples and droppers per signature.
Third: Some AVs also proactive detect the methods known TDL samples used in the past. (f.e. EAM, KIS,...)
  #3  
Old August 12th, 2012, 02:41 PM
nosirrah nosirrah is offline
Malware Fighter
 
Join Date: Aug 2006
Location: Cummington MA USA
Posts: 477
Default Re: TDSS Prevention

"First: TDSS is dead. There are no new samples of it itw since a long time."

D0C23926925123071B143F717B7ADC7D
24CEA1FD12E4C9C99B6D0779DC923895

These both dropped from exploits this month and were undetected at 0hour. I just rechecked the newest one and it is up to about 40% detected.

ITW you will see MBAM logs containing Trojan.Agent.BRVGen.

Ping me if you want the samples.
__________________
Bruce Harrison
Malwarebytes Lead Researcher
  #4  
Old August 12th, 2012, 03:41 PM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: TDSS Prevention

Then look elsewhere.How about adding Sandboxie to your setup or AppGuard or both.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
  #5  
Old August 12th, 2012, 05:26 PM
Chiron Chiron is offline
Regular Poster
 
Join Date: Jun 2010
Posts: 173
Default Re: TDSS Prevention

Quote:
Originally Posted by nozzle
I've looked for an antivirus that can prevent a TDSS infection and only found cleanup tools AFTER the infection. Is there an antivirus that actually prevents a TDSS infection?

Thanks
Comodo Internet Security or Comodo Firewall will protect you. So will many others, as long as they don't rely entirely on detection in order to "protect" the user.
__________________
How to Stay Safe While Online
  #6  
Old August 12th, 2012, 05:46 PM
nozzle nozzle is offline
Infrequent Poster
 
Join Date: Jul 2012
Location: San Diego, CA
Posts: 22
Default Re: TDSS Prevention

Thanks Chiron. I'm already using Comodo Firewall and didn't know it had that capability. Learning new things everyday.

Keep safe
  #7  
Old August 12th, 2012, 05:58 PM
Chiron Chiron is offline
Regular Poster
 
Join Date: Jun 2010
Posts: 173
Default Re: TDSS Prevention

Quote:
Originally Posted by nozzle
Thanks Chiron. I'm already using Comodo Firewall and didn't know it had that capability. Learning new things everyday.

Keep safe
Yes, any files not verified as safe by Comodo analysts will be prevented from harming your system. Thus you are safe from malware whether it is detected as such or not.

Have you already read my guide here?
__________________
How to Stay Safe While Online
  #8  
Old August 12th, 2012, 06:19 PM
nozzle nozzle is offline
Infrequent Poster
 
Join Date: Jul 2012
Location: San Diego, CA
Posts: 22
Default Re: TDSS Prevention

Thanks again Chiron for the install manual. Nice and simple "how to" for Comodo Firewall. I followed your instructions and believe I am more secure for doing so.

Stay Safe
  #9  
Old August 13th, 2012, 03:41 PM
Noob's Avatar
Noob Noob is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 5,252
Default Re: TDSS Prevention

Most AV's should be able to detect the old TDSS variants.
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736
SRP - UAC - EMET

Browser: Google Chrome v25.xx

Windows 7 Ultimate x64
  #10  
Old August 14th, 2012, 01:02 AM
icr icr is offline
Very Frequent Poster
 
Join Date: Sep 2008
Location: Mumbai
Posts: 1,588
Default Re: TDSS Prevention

Run as a limited user

The infection comes from the usual dropper from P2P networks or by warez websites, and it needs admin rights to run its payload. If UAC is OFF(disabled) or the user manually gives admin rights, then TDSS can infect even Windows Vista and Windows 7. This is likely to be the usual scenario, where a user looks for specific cracks,patches,pornography and don't mind if UAC warns him, he gives admin privileges to the wanted file. And finally gets infected.


regards,
icr
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01101001 01100011 01110010

--->My Blog<---
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:23 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums