Malware Removal Instructions

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, 30 March 2013

False Positive: Ikarus and Comodo detecting TDSSKiller as a Trojan horse

Posted on 05:19 by Unknown
This awkward moment when you realize that your favorite rootkit removal utility is detected as malware. I probably wouldn't even have noticed, but I got an email from my reader Matt who apparently has been been having some problems with malicious software lately. He said, that TDSSKiller (the tool I like a lot and usually recommend to my readers) is actually a Trojan horse. Obviously, this can't be true, so I though maybe he downloaded an infected TDSSKiller variant from some naughty site, so that would explain everything. He then quickly replied to me that he downloaded TDSSKiller from Kaspersky's site and that's clearly not the case. Comodo antivirus blocked the file when Matt executed it. I had to see it for myself, so I downloaded TDSSKiller on my computer and then uploaded it to VirusTotal. Surprise, surprise, it's indeed a Trojan with detection ratio: 2/46. Since I was too lazy to install Comodo and Ikarus, I decided to use Hitman Pro. It uses Ikarus antivirus engine, so it should detect TDSSKiller. Yep, we have a false positive here. Matt was right.



Tdsskiller.exe was detected as Trojan.Crypt by Ikarus antivirus. Comodo detected it as Packed.Win32.MUPX.Gen. Software packaging issues or something like that I guess.



However, I can assure you guys that TDSSKiller is a genuine and safe utility. It's a false positive and it's just a matter of time when the issue will be resolved. So, don't worry. The funny think is, though, tdsskiller.exe has a valid certificate, just like it should be, signed by COMODO.



Yeah, COMODO, the one that detects it as Packed.Win32.MUPX.Gen a the moment. Well, what can I say, this is not the first time when antivirus companies are flagging each others tools as dangerous :) Unfortunately, such things happen from time to time.

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Security Advisories | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • What is wrtc.exe and how to remove it?
    wrtc.exe - by Perion Network Ltd. What is wrtc.exe? wrtc.exe is a part of IncrediMail software, digitally signed by Perion Network Ltd. This...
  • Remove ShopperReports (Uninstall Guide)
    ShopperReports is defined as adware or a potentially unwanted program that displays marketing related results in a side pane of the browser...
  • Trojan.MBRlock, Внимание! Ваш компьютер заблокирован
    Trojan.MBRlock is a very disturbing piece of malicious code which infects the master boot record (MBR) and prevents Windows from starting. ...
  • False Positive: Ikarus and Comodo detecting TDSSKiller as a Trojan horse
    This awkward moment when you realize that your favorite rootkit removal utility is detected as malware. I probably wouldn't even have no...
  • Remove RiskTool.Win32.BitCoinMiner (Uninstall Guide)
    RiskTool.Win32.BitCoinMiner is a risk tool or potentially unwanted application that may use your computer's resources to generate bitco...
  • Remove Rattlingsearchsystem.com (Uninstall Guide)
    Rattlingsearchsystem.com is a ZeroAccess/Sirefef rootkit-related browser hijacker that redirects users to shady websites while searching on...
  • Remove TR/ATRAPS.Gen2, removal instructions
    Cyber crooks and third parties that buy stolen data are increasingly using more and more sophisticated techniques, in a variety of different...
  • Remove Ask Search and Ask Toolbar (Uninstall Guide)
    Ask Search and Ask Toolbar are very often incorrectly classified as virus/spyware that may cause search redirects. The majority of us pref...
  • How to remove 'TidyNetwork' adware virus from your computer
    As internet users most of us have seen those irritating little pop-up windows that are advertising something that we normally have little or...
  • Remove Windows Attention Utility (Uninstall Guide)
    Windows Attention Utility is a rogue security application that generates misleading warnings about nonexistent viruses and attempts to lure...

Categories

  • Adware
  • Answers
  • Antivirus software
  • Browser Hijackers
  • Cloud Computing
  • Fake Alerts
  • Giveaways
  • Hoax
  • How-To
  • IaaS
  • Internet
  • Malicious websites
  • Malware
  • PaaS
  • Parental Controls
  • Passwords
  • Phishing
  • Process Information
  • Ransomware
  • Rogue programs
  • Rootkits
  • SaaS
  • Security Advisories
  • Spam
  • Spyware
  • Trojans
  • Viruses
  • Web Browsers
  • Worms

Blog Archive

  • ▼  2013 (173)
    • ►  December (6)
    • ►  November (13)
    • ►  October (11)
    • ►  September (20)
    • ►  August (4)
    • ►  July (17)
    • ►  June (31)
    • ►  May (25)
    • ►  April (15)
    • ▼  March (17)
      • False Positive: Ikarus and Comodo detecting TDSSKi...
      • Remove Price Peep (Uninstall Guide)
      • Remove Solid Savings (Uninstall Guide)
      • Identity Theft Protection – How to Stop Your Life ...
      • Remove PC Fix Speed and 24x7 Help (Uninstall Guide)
      • This website has been blocked for you! removal ins...
      • Remove Why do I see this page? virus - Attention R...
      • AVASoft Professional Antivirus Firewall Alert remo...
      • Remove Ukash virus
      • Remove Department of Justice virus
      • How to Remove AVASoft Professional Antivirus – AV...
      • Remove System message - Error Seek popup and relat...
      • Remove Chitka pop up ads, removal instructions
      • Remove Win 7 Security Cleaner Pro, removal instruc...
      • How to Remove 22find
      • How to Remove Disk Antivirus Professional (Uninsta...
      • Know the Enemy – Identifying & Removing the FBI Virus
    • ►  February (7)
    • ►  January (7)
  • ►  2012 (86)
    • ►  November (2)
    • ►  October (4)
    • ►  September (6)
    • ►  August (6)
    • ►  July (11)
    • ►  June (1)
    • ►  May (5)
    • ►  April (7)
    • ►  March (7)
    • ►  February (17)
    • ►  January (20)
  • ►  2011 (239)
    • ►  December (8)
    • ►  November (18)
    • ►  October (21)
    • ►  September (24)
    • ►  August (28)
    • ►  July (32)
    • ►  June (16)
    • ►  May (23)
    • ►  April (15)
    • ►  March (16)
    • ►  February (9)
    • ►  January (29)
  • ►  2010 (2)
    • ►  December (2)
Powered by Blogger.

About Me

Unknown
View my complete profile