Welcome, Guest. Please login or register.
November 22, 2009, 04:03:14 AM

Login with username, password and session length

336743 Posts
37260 Topics
84463 Members

Latest Member: Barfbag

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  D+ Give A Great Alert About DNS- Trojan Dropper Test
« previous next »
Pages: 1 [2] Go Down Print
Author Topic: D+ Give A Great Alert About DNS- Trojan Dropper Test  (Read 4683 times)
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 8244



WWW
« Reply #15 on: July 29, 2008, 04:52:20 AM »

thanks I will

Melih
Logged

aigle
Comodo's Hero
*****
Offline Offline

Posts: 504



« Reply #16 on: August 01, 2008, 01:28:08 AM »

Hi Vettetech, did u run the test with second sample- installer.exe?

Thanks
Logged
forcespawn
Comodo Member
**
Offline Offline

Posts: 42


« Reply #17 on: August 15, 2009, 11:58:55 PM »

I did this test to prove and make a point to Aigle. I had to shut off my trusty NOD32 to run this test but D+ kicked in and did its job by alerting me twice. Once for the explorer.exe alert and the other one about trying to modify a file. Screen shots don't lie.


to be honest, i'm not sure what point this proves, except that Defense+ stopped the execution of the file. aigle's screenshots show eqsecure detecting the installation or loading of drivers from the trojan. this behavior based blocking is completely different from not letting a file run at all. after all, the point is not to stop anything from running, but to know that something exhibits dangerous behavior when it is inadvertently allowed to run. the screenshots don't lie, but they also don't say much Smiley

your second set of screenshots show an attempt to "modify a protected file or directory", just like the second screenshot in your first set of screenshots. but doesn't modifying a directory just mean writing a file to it, deleting a file in it, or changing a file already in it? all these actions are completely different than allowing a driver to be loaded.

i can sense a lot of tension in this debate, but there need not be any. the real argument is not whether comodo+ can stop this trojan (it can easily by stopping it from running), but whether it can prevent the loading of the trojan's driver(s) IF allowed to run. all we have to do now is await Melih's response (or a response from someone who has done this test) Smiley
Logged
Dennis2
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 2187



« Reply #18 on: August 16, 2009, 02:22:43 AM »

Please do not post in topics which are outdated August 2008

Topic Locked

Dennis
Logged

Moderator: Aims to keep the forum a friendly place. Any concerns? Please PM me and/or review the NEW forum policy.
System: Windows 7 (UAC)x32, CIS 3.13,Sandboxie 3.40
Vista Home P. (UAC)x32 SP2, CIS 3.13, W.D.
Tags:
Pages: 1 [2] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.035 seconds with 19 queries.
Powered by SMF 1.1.10 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com