Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 13, 2008, 04:33:08 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
199977
Posts
22956
Topics
55073
Members
Latest Member:
souravbarman
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Help for v2
Help: problem with Dragon Naturally Speaking DLL injection
« previous
next »
Pages:
[
1
]
Author
Topic: Help: problem with Dragon Naturally Speaking DLL injection (Read 906 times)
MKairys
Newbie
Offline
Posts: 7
Help: problem with Dragon Naturally Speaking DLL injection
«
on:
March 01, 2007, 10:38:56 AM »
I've been running CFP 2.4.18 for a few months now and seem to have a stable (quiet
) set of application rules. Then for the first time since installing CFP I ran Dragon Naturally Speaking (version 9 Standard). I was immediately beseiged with popups of the form:
C:\Program Files\Nuance\NaturallySpeaking\Program\dgniedct.dll has loaded ... dgniedct.dll into C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE using a global hook which could be used by keyloggers to steal private information.
This occured four times for Outlook every time it did Send/Receive, even though I told it to remember the action every time. I quieted it down for Outlook by editing my application rule and checking Skip Advanced Security Checks, but it happened for other programs as well, and finally I had to turn off DLL injection checking just so I could get some work done.
Now, I have no idea what Dragon is trying to do here (I've asked in their support forum) but I would like to make Comodo happy, or at least quieter, without compromising my overall security. Suggestions please.
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6017
Re: Help: problem with Dragon Naturally Speaking DLL injection
«
Reply #1 on:
March 01, 2007, 01:14:09 PM »
The Global Hook message, as you know, is part of CFP's Application Behavior Analysis; which in context, CFP cannot determine whether an action is a "safe" one or not. It's sole job there is to alert you of an action that is similar to actions used by malware, which could result in that application contacting the internet.
This doesn't mean that Dragon is contacting the internet; it is probably because its voice recognition is integrating with applications that are connected (ie, Outlook). It would be interesting to see what they say about its behavior in this respect.
A method I have used to stop some of the "false positive" ABA alerts is as follows:
Create a "block" rule in the application monitor for the offending application.
So in this case you would make a rule to block your *.exe (where the "*" is the name of the Dragon executable). So it would look like this:
Application: *.exe
Parent: Skip
Action: Block
Protocol: TCP/UDP
Direction: Out
Source: Any
Destination: Any
Miscellaneous: (leave it blank).
Click OK. Turn DLL Injection monitoring back on, OK. Reboot.
That should help with that issue for that application. Give it a whirl and let us know.
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
MKairys
Newbie
Offline
Posts: 7
Re: Help: problem with Dragon Naturally Speaking DLL injection
«
Reply #2 on:
March 01, 2007, 04:40:05 PM »
Thanks for your reply and your helpful suggestions.
In the Dragon forum I got this reply:
The DLL is necessary for NaturallySpeaking's Select-&-Say capability. If you are not familiar with Select-&-Say, search this forum for additional information but suffice it to say, you would be much better off having it.
If your Comodo 2.4 firewall doesn't include an option to allow this DLL to work without prompting you every time you use NaturallySpeaking then you need to get your money back on Comodo 2.4 because it's obviously not very well user-friendly.
... so I'm looking into getting a refund of my purchase price
Seriously, I did try making an application rule for natspeak.exe (since I didn't think I could make one for the dll) but I couldn't make it block since natspeak.exe wants to go out and check for updates (and who doesn't these days). So I gave it all the rope I could , including "skip advanced.." and so far CFP has been quiet.
I must say that I like CFP very much and am quite impressed in the functionality it includes, but it is rather too noisy for my taste and I seem to spend not a little time fiddling with rules to quiet it down. I would love to see more FAQ topics about how to, as you say, avoid false positives.
Logged
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 7455
Re: Help: problem with Dragon Naturally Speaking DLL injection
«
Reply #3 on:
March 01, 2007, 04:48:02 PM »
Here's your $0.00 money back.
These aren't necessarily false positives. Legitimate programs have their own "hooking" of dll's into others. CFP only alerts actions that it deems as suspicious (the potential possibility that malware can also do). I'm sure you as well as us users will enjoy
version 3
once HIPS is out as the architecture will be different (and hopefully less confusing).
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6017
Re: Help: problem with Dragon Naturally Speaking DLL injection
«
Reply #4 on:
March 01, 2007, 04:58:56 PM »
Okay, creating the rule with "skip advanced..." will turn off ABA for that application only, which should eliminate the DLL Injection popups (and any other in that category) for that application/executable only.
Should the program in general have any other .exe's (each with their own .dll access), that's a different story.
So the main executable is used for updates? There's not a separate executable for that? That seems odd...
You know, until I used Comodo FW, I rarely saw a FW alert. McAfee used to tell me that I was portscanned left & right (don't know how it determined that; I could never find out) while on dial-up. TrendMicro only alerted me when a new application tried to access the internet directly. ZA only told me it was stopping inbound stuff. And so on... I don't get too many alerts, really, any more, for CFP; it's really quite quiet. There was a lot more activity at first, and a lot of the ABA-related ones. I learned a lot about rules, and quieted things down. I think it would've been fine if I didn't really do anything with the computer, except use MS products to browse and do email. But using odd-ball programs and things...
All that said, Egemen (lead FW developer) has said that version 3 (which should reach public beta testing soon) should be a lot quieter; he says we shouldn't see very many (if any) of these ABA popups any more...
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
MKairys
Newbie
Offline
Posts: 7
Re: Help: problem with Dragon Naturally Speaking DLL injection
«
Reply #5 on:
March 01, 2007, 04:59:38 PM »
Thanks, I'll try not to spend it all in one place
Thanks also for the pointer to 3.0; I didn't realize I had joined up on the cusp of a new version. (I'm a glutton for betas
)
Logged
MKairys
Newbie
Offline
Posts: 7
Re: Help: problem with Dragon Naturally Speaking DLL injection
«
Reply #6 on:
March 01, 2007, 05:21:40 PM »
Quote from: Little Mac on March 01, 2007, 04:58:56 PM
So the main executable is used for updates? There's not a separate executable for that? That seems odd...
Yes, I may be wrong about that. I'll look in the log (one of these days
)
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6017
Re: Help: problem with Dragon Naturally Speaking DLL injection
«
Reply #7 on:
March 01, 2007, 05:24:52 PM »
Ah, yes, "one of these days." I'm familiar with that...
Well, you can do that. Certainly let us know when you've used it with the "skip advanced" in place, to see if that resolves that (as far as a "work-around" goes).
And, if you are the glutton you say you are, keep an eye on the Beta Corner for
http://forums.comodo.com/index.php/board,40.0.html
the public testing release of version 3...
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.156 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com