Welcome, Guest. Please login or register.
November 22, 2009, 03:54:35 AM

Login with username, password and session length

336743 Posts
37260 Topics
84463 Members

Latest Member: Barfbag

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  Defence+ failed against malware
« previous next »
Pages: 1 2 [3] Go Down Print
Author Topic: Defence+ failed against malware  (Read 13967 times)
aigle
Comodo's Hero
*****
Offline Offline

Posts: 504



« Reply #30 on: March 04, 2008, 07:25:08 PM »

As egemen already said it is now part of direct disk access monitoring.

So they included it in Disk Access in latest version? I don,t see any such info from egemen. He just seemed referring to the meaning of \device\LanmanRedirector. Are u sure?

Thanks
Logged
adric
"Start every day with a smile and get it over with."
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 640


"I am not young enough to know everything. "


« Reply #31 on: March 04, 2008, 07:41:56 PM »

Is this info enough?  Grin

Al
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 494


COMODO Volunteer DEModerator


« Reply #32 on: March 04, 2008, 07:54:20 PM »

So they included it in Disk Access in latest version? I don,t see any such info from egemen. He just seemed referring to the meaning of \device\LanmanRedirector. Are u sure?

Thanks
Yes, It is here since 3.0.17 (thanks for linky adric) and some other improvements are added like additional reg. keys monitoring, also in that build.
« Last Edit: March 04, 2008, 07:58:15 PM by salmonela » Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
aigle
Comodo's Hero
*****
Offline Offline

Posts: 504



« Reply #33 on: March 05, 2008, 07:29:51 AM »

Thanks adric and salmonela.
Logged
obperryo
Newbie
*
Offline Offline

Posts: 1


« Reply #34 on: September 23, 2008, 08:43:49 AM »

Here is couple of registry tests which CFP doesnt completely pass by default (download in attachment)
BTW on regtest phase2 CFP crashes...
Note: for successful testing of regtest you need to allow: regtest.exe to execute regtest.exe and to regtest.exe access regtest.exe in memory, every other request should be denied.


Regtest.exe still crashes, was there ever a fix for this.  The test restarts your system, so I can't fill in the and send the problem box that CIS is giving.  Man, this sure drops my confidence in this software, failing the first test I try.
Logged
forcespawn
Comodo Member
**
Offline Offline

Posts: 42


« Reply #35 on: August 16, 2009, 12:14:37 AM »

Hi Guys,

As an update to this topic, the default configuration of CFP,  needs to be modified slightly to provide a complete defense against this type of rootkit. One should add \Device\LanmanRedirector to the my protected files in Defense+ to see the real harm that can be caused by this rootkit. Fortunately, CFP clearly warns the user with the heuristics before it is run. Experienced users may try adding this file and deny every single popup shown by the rootkit. Experinced users only! In a VM only!

We will be making the necessary changes and update the default configuration next week. But until that time, I strongly warn the novice users to avoid running this rootkit in their PCs.

Remember, this is not a harmless test. It is a real rootkit and without making the above changes, it can seriously damage your computer.


Egemen

egemen, you are right that once the driver is loaded, it is game over basically. my concern then, is over the method used to prevent the driver from loading. defense+ seems to rely on 3 different filters to prevent the driver from loading:

1. device driver
2. registry
3. protected files/folders

is it not possible to update defense+ to rely only on the first module? the number of registry entries that could be used to load drivers is vast! to include protection against every possible such entry would greatly increase the number of popups. the same is true of #3. plus, couldn't someone modify the trojan slightly and take advantage of another line in the registry or another vulnerable folder directory that hasn't yet been added? if the device driver filter was strengthened, wouldn't that stop such rootkits far more effectively?
« Last Edit: August 16, 2009, 01:09:39 AM by forcespawn » Logged
Dennis2
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 2187



« Reply #36 on: August 16, 2009, 02:26:49 AM »

Please do not post in topics which are outdated September 2008

Topic Locked

Dennis
Logged

Moderator: Aims to keep the forum a friendly place. Any concerns? Please PM me and/or review the NEW forum policy.
System: Windows 7 (UAC)x32, CIS 3.13,Sandboxie 3.40
Vista Home P. (UAC)x32 SP2, CIS 3.13, W.D.
Tags:
Pages: 1 2 [3] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.039 seconds with 19 queries.
Powered by SMF 1.1.10 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com