Malware Removal Instructions

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, 30 March 2013

False Positive: Ikarus and Comodo detecting TDSSKiller as a Trojan horse

Posted on 05:19 by Unknown
This awkward moment when you realize that your favorite rootkit removal utility is detected as malware. I probably wouldn't even have noticed, but I got an email from my reader Matt who apparently has been been having some problems with malicious software lately. He said, that TDSSKiller (the tool I like a lot and usually recommend to my readers) is actually a Trojan horse. Obviously, this can't be true, so I though maybe he downloaded an infected TDSSKiller variant from some naughty site, so that would explain everything. He then quickly replied to me that he downloaded TDSSKiller from Kaspersky's site and that's clearly not the case. Comodo antivirus blocked the file when Matt executed it. I had to see it for myself, so I downloaded TDSSKiller on my computer and then uploaded it to VirusTotal. Surprise, surprise, it's indeed a Trojan with detection ratio: 2/46. Since I was too lazy to install Comodo and Ikarus, I decided to use Hitman Pro. It uses Ikarus antivirus engine, so it should detect TDSSKiller. Yep, we have a false positive here. Matt was right.



Tdsskiller.exe was detected as Trojan.Crypt by Ikarus antivirus. Comodo detected it as Packed.Win32.MUPX.Gen. Software packaging issues or something like that I guess.



However, I can assure you guys that TDSSKiller is a genuine and safe utility. It's a false positive and it's just a matter of time when the issue will be resolved. So, don't worry. The funny think is, though, tdsskiller.exe has a valid certificate, just like it should be, signed by COMODO.



Yeah, COMODO, the one that detects it as Packed.Win32.MUPX.Gen a the moment. Well, what can I say, this is not the first time when antivirus companies are flagging each others tools as dangerous :) Unfortunately, such things happen from time to time.

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Security Advisories | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Remove Ask Search and Ask Toolbar (Uninstall Guide)
    Ask Search and Ask Toolbar are very often incorrectly classified as virus/spyware that may cause search redirects. The majority of us pref...
  • Facebook Security and Privacy Best Practices
    Facebook is the most popular social networking site. Nearly all of my friends have Facebook accounts. They log on to Facebook at least a cou...
  • What is wrtc.exe and how to remove it?
    wrtc.exe - by Perion Network Ltd. What is wrtc.exe? wrtc.exe is a part of IncrediMail software, digitally signed by Perion Network Ltd. This...
  • Smartphone Security: Using Your Mobile Phone Safely
    Smartphone is like a little copy of your computer with lots of personal information: photos, text messages, access to e-mail account and oth...
  • Remove ShopperReports (Uninstall Guide)
    ShopperReports is defined as adware or a potentially unwanted program that displays marketing related results in a side pane of the browser...
  • Antispyis.com and other Antivirus Scan related domains
    New additions of misleading websites which promote a rogue security application called Antivirus Scan. antispyis.com afantispy.net softwaree...
  • Trojan.MBRlock, Внимание! Ваш компьютер заблокирован
    Trojan.MBRlock is a very disturbing piece of malicious code which infects the master boot record (MBR) and prevents Windows from starting. ...
  • False Positive: Ikarus and Comodo detecting TDSSKiller as a Trojan horse
    This awkward moment when you realize that your favorite rootkit removal utility is detected as malware. I probably wouldn't even have no...
  • Antivired.com and other Antivirus Monitor Related Domains
    Just a short note about several malicious domains related to the Antivirus Monitor fraud. This rogue anti-virus program reports non-existent...
  • WebCake Adware Removal Guide
    If you’re reading this it is very likely that your computer is infected with WebCake adware which displays extremely obnoxious and intrusiv...

Categories

  • Adware
  • Answers
  • Antivirus software
  • Browser Hijackers
  • Cloud Computing
  • Fake Alerts
  • Giveaways
  • Hoax
  • How-To
  • IaaS
  • Internet
  • Malicious websites
  • Malware
  • PaaS
  • Parental Controls
  • Passwords
  • Phishing
  • Process Information
  • Ransomware
  • Rogue programs
  • Rootkits
  • SaaS
  • Security Advisories
  • Spam
  • Spyware
  • Trojans
  • Viruses
  • Web Browsers
  • Worms

Blog Archive

  • ▼  2013 (173)
    • ►  December (6)
    • ►  November (13)
    • ►  October (11)
    • ►  September (20)
    • ►  August (4)
    • ►  July (17)
    • ►  June (31)
    • ►  May (25)
    • ►  April (15)
    • ▼  March (17)
      • False Positive: Ikarus and Comodo detecting TDSSKi...
      • Remove Price Peep (Uninstall Guide)
      • Remove Solid Savings (Uninstall Guide)
      • Identity Theft Protection – How to Stop Your Life ...
      • Remove PC Fix Speed and 24x7 Help (Uninstall Guide)
      • This website has been blocked for you! removal ins...
      • Remove Why do I see this page? virus - Attention R...
      • AVASoft Professional Antivirus Firewall Alert remo...
      • Remove Ukash virus
      • Remove Department of Justice virus
      • How to Remove AVASoft Professional Antivirus – AV...
      • Remove System message - Error Seek popup and relat...
      • Remove Chitka pop up ads, removal instructions
      • Remove Win 7 Security Cleaner Pro, removal instruc...
      • How to Remove 22find
      • How to Remove Disk Antivirus Professional (Uninsta...
      • Know the Enemy – Identifying & Removing the FBI Virus
    • ►  February (7)
    • ►  January (7)
  • ►  2012 (86)
    • ►  November (2)
    • ►  October (4)
    • ►  September (6)
    • ►  August (6)
    • ►  July (11)
    • ►  June (1)
    • ►  May (5)
    • ►  April (7)
    • ►  March (7)
    • ►  February (17)
    • ►  January (20)
  • ►  2011 (239)
    • ►  December (8)
    • ►  November (18)
    • ►  October (21)
    • ►  September (24)
    • ►  August (28)
    • ►  July (32)
    • ►  June (16)
    • ►  May (23)
    • ►  April (15)
    • ►  March (16)
    • ►  February (9)
    • ►  January (29)
  • ►  2010 (2)
    • ►  December (2)
Powered by Blogger.

About Me

Unknown
View my complete profile