Hi,
I downloaded The Dude from http://www.mikrotik.com/thedude.php/ at the recommendation of someone on the Spiceworks forum but virustotal.com shows it as the TDSS rootkit…
https://www.virustotal.com/file/1d8555dac23043dbbe30151f98f00565d522b06cb857a634e4f3371b4edf1fc4/analysis/
…Normally I would just think it was a false positive but I haven’t seen a lot of false positives that were for that root kit…
Can anyone comment?
This problem still exists, and I can’t find whether or not this is a false positive. One would think so as all the other scanners check out fine (except ClamAV but we all know that one loves to cough up False Positive packer results) and it’s bound to get some attention from scanners as this program does scan your network with possibly invasive methods.
virustotal.com [The Hacker] TDSS.bmdq
virusscan.jotti.org [ClamAV] PUA.Win32.Packer.MingwGcc-2