new options added... more to come
This is why paying for unlimited is worth it. Great work guys.
@tempnexus but whats the name of the process? -i already deleted the trainer with the trojan, and id been updating kaspersky all day long to see if it detects the trojan, i havent seen any suspicious process atm...
Well if you nuked the process and it was unable to call home since the servers were already down then you might be in the clear.
When I first ran the proggy early yesterday it was able to retrieve two files. AT that time the processes that it ran were:
ntsds.exe and javas.exe
Yep it appears that still only NOD32 can get it as a heuristic detection not a true positive:
www.virustotal.com/file-scan/report.html?id=f592d1f67bb8e60902d79e66980a8737c4ae09b0f929ec28951da41ce7b5e496-1285543049
OH an on the topic:
THANKS FOR THE TRAINER UPDATE!!! Do you guys ever sleep?
[Edited by tempnexus, 9/26/2010 4:19:31 PM]