Help - Search - Members - Calendar
Full Version: True Sword 4
Malwarebytes Forum > Research Center > Newest Rogue Threats
B-boy/StyLe/
Installer not flagged:

CODE
hxxp://www.securitystronghold.com/ download/gates/TrueSword4.exe


Mirror:

CODE
hxxp://rapidshare.com/files/179380732/truesword4.exe.html


VirusTotal:

A lot ot false positives, shareware licence, updates doesn't work...

A-squared:

QUOTE
TrueSword 4.2 is a rogue security program that shows false Warning messages. It also shows misleading scan Results. It can also install through Trojan exploits.


http://www.emsisoft.com/en/malware/?Adware...2.TrueSword+4.2

Official Site of True Sword was determined as dangerous by WoT (Web Of Trust) add-on for Mozilla Firefox.



MBAM doesn't hit it.





QUOTE
Malwarebytes' Anti-Malware 1.31
Database version: 1602
Windows 6.0.6001 Service Pack 1

1/3/2009 5:04:46 PM
mbam-log-2009-01-03 (17-04-46).txt

Scan type: Quick Scan
Objects scanned: 39722
Time elapsed: 1 minute(s), 30 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Uninstaller doesn't remove everything:

C:\Program Files (x86)\True Sword 4 =>

folder => backuped

files: =>

backups.ini
db_backup.db
options.ini

and some registry entries... rolleyes.gif
Sparsha
TrueSword was de-listed by spywarewarrior in 2006

http://www.spywarewarrior.com/de-listed.htm#tsword_note

In early 2007 the application was no longer flagged as Rogue by many products. Currently they don't offer True Sword 4 i think you need to check True Sword 5 version.
B-boy/StyLe/
QUOTE (Sparsha @ Jan 3 2009, 04:23 PM) *
TrueSword was de-listed by spywarewarrior in 2006

http://www.spywarewarrior.com/de-listed.htm#tsword_note

In early 2007 the application was no longer flagged as Rogue by many products. Currently they don't offer True Sword 4 i think you need to check True Sword 5 version.


You're right, but so many peoples have this crap installed on their computers when google it. (in hijackthis and combofix logs)
Adding this to defs in MBAM is a good idea i think.
I never trust software that was de-listed by spywarewarrior => Spy Emergency 2008, XoftSpy etc. Maybe only RemoveIt Pro... biggrin.gif
B-boy/StyLe/
I will try it, but i am pessimist for this vendor smile.gif

MysteryFCM
I've just re-tested this and it only produced 1 F/P (RSIT - detected it as "spyware/trojan"). However, it completely missed all of the malware samples I've got (funny considering it's previous incarnation did actually flag some of them).

Nevertheless, aslong as it's no longer being peddled by malware, I'd no longer consider it as "roguerific" as it once was, useless perhaps, but otherwise benign.
nosirrah
"roguerific"

I have been using roguetacular , I think I like yours better .
MysteryFCM
hehe smile.gif
B-boy/StyLe/
QUOTE (remixed @ Jan 4 2009, 02:20 AM) *


Ops. I do not see the topic.Sorry.

Clean scan for version 5. (nothing detected). => RSIT too... blink.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.