Results 1 to 2 of 2

Thread: Teatimer and Virtumonde

  1. #1
    Junior Member
    Join Date
    Aug 2007
    Posts
    14

    Default Teatimer and Virtumonde

    Hello!

    My question: Spybot SD can detect the Virtumonde type infection.
    The resident shield - teatimer- use the same definition base as the main scanner of SD.
    If SD can detect the Virtumonde-the Tematimer why can't in real time?


    Thanks

  2. #2
    Senior Member honda12's Avatar
    Join Date
    Nov 2007
    Location
    UK
    Posts
    682

    Smile

    Hi molngab

    From spybot faqs: What is the Resident TeaTimer?

    What is the Resident TeaTimer?

    The Resident TeaTimer is a tool of Spybot-S&D which perpetually monitors the processes called/initiated. It immediately detects known malicious processes wanting to start and terminates them giving you some options, how to deal with this process in the future. You can set TeaTimer to:

    * be informed, when the process tries to start again
    * automatically kill the process
    * or generally allow the process to run

    There is also an option to delete the file associated with this process.

    In addition, TeaTimer detects when something wants to change some critical registry keys. TeaTimer can protect you against such changes again giving you an option: You can either Allow or Deny the change.

    The TeaTimer is always running in the background.
    ***

    From: How Spybot-S&D protects against the installation of Spyware/Malware
    The third level of protection is the TeaTimer. TeaTimer is an active protection that monitors changes to certain system Registry keys such as System Startup, ActiveX Distribution Unit, Browser page and Browser Helper Object, etc. When any change is detected to these Registry keys a pop-up dialog is issued asking you to allow or deny the change and if you want TeaTimer to remember the decision. TeaTimer also monitors processes that are initiated in the system. If the process being initiated matches a list of processes in Spybot's detection files, the process is terminated and a dialog is issued to notify you and allow you to make choices as to how to handle the same process during future detections.



    According to this information it seems that teatimer does use Spybot's database to detect known malware
    Last edited by honda12; 2008-04-27 at 02:17.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •