3 New Notifications

New Badge Earned
Get 1K upvotes on your post
Life choices of my cat
Earned 210

Drag Images here or Browse from your computer.

Trending Posts
Sorted by Newest First
V
VITYA_KOLYADENKO 13.10.22 10:19 pm

TDSS

Maybe someone met? Creates malicious files C:WINDOWSsystem32[RANDOM].dll and C:WINDOWSSYSTEM32DRIVERS[RANDOM].sys, infects the MBR. There are several modifications, most are removed only by about three of the best antiviruses.
2 Comments
Sort by:
V
VITYA_KOLYADENKO 13.10.22

NorthSouth
This is exactly its feature. Not all antiviruses do a good job of infecting the MBR. At one time, AVG could catch 1 modification (only under WinXP 32, but not Win7 64), BitDefender - all versions for both axes, Avast! could catch another version, Dr.Web could not catch another version for both axes, and Kaspersky caught everything (not for nothing they have a separate utility).

Virus.Win32.Sality.aa, for example, also uses a driver, also uses autorun and disable safe mode, interferes with AVZ and CureIt! (sometimes it definitely interfered).

As for Conficker (Downup, Downadup, Kido), the following is known:
According to McAfee, the damage caused by the virus to the online community is estimated at $9.1 billion, second only to the damage caused by email worms like MyDoom ($38 billion). ) and I LOVE YOU ($15 billion).

V
VITYA_KOLYADENKO 13.10.22

By the way, the garbage came out on Win7 x64. I infected it for the test, then Windows did not start normally. I had to treat through LiveCD.