Welcome, Guest. Please login or register.
Did you miss your activation email?
May 23, 2013, 04:23:32 PM

Login with username, password and session length

663806 Posts
70589 Topics
145226 Members

Latest Member: oldwiseowls

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Time Machine - CTM
| | |-+  News / Announcements / Feedback - CTM
| | | |-+  does CTM protect against TDSS/TDL rootkits?
« previous next »
Pages: [1] 2 3 4 Go Down Print
Author Topic: does CTM protect against TDSS/TDL rootkits?  (Read 22163 times)
taleblou
Comodo Family Member
***
Offline Offline

Posts: 86


« on: June 30, 2010, 08:22:25 PM »

Hi:
I would like to know does using CTM and make snapshot of clean computers and later during a tdss/tdl rootkit infection when trying to restore a clean  snapshot get rid of the tdl/tdss rootkits? The reason is I used wondershare time-freeze virtualization and a tdl-3 rootkit by passed it and infected my pc forcing a format to make sure is clean and I have heard shadow defender also fails tdl/tdss rootkits. SO on my new formated pc I was wondering if I use CTM will it protect me against these rootkit or will the snapshots and CTM get infected as well?

Also anyone knows any protection against these rootkits? By the way I have CIS perimum and it failed to detect the rootkit. The only softwares detected was hitman pro 3.5 and GMER. Thanks in advance for your reply.
Logged
Tech
Usability Study Member
Comodo's Hero
*****
Offline Offline

Posts: 3024



« Reply #1 on: June 30, 2010, 08:29:00 PM »

Most probably yes. You can have a clean computer after restoring the clean snapshot.
But I'm not an expert on CTM (yet).
If GMER detects it, avast will do the same (as the full GMER technology is bundled into avast).
Logged

avast! team member
Save freeware snapshot technology of Comodo Time Machine. Vote!
dax123
Comodo Loves me
****
Offline Offline

Posts: 160


Big Clucker


« Reply #2 on: July 01, 2010, 09:36:16 AM »

I'll do the tests using my samples.
It can screw systems with returnil, shadow defender, deepfreeze, time freeze etc.

I'm installing xp in my vpc and will test it as soon as it finishes.
« Last Edit: July 01, 2010, 09:54:41 AM by dax123 » Logged

i cannot help but confess, dang I wanted to get that. LOL
taleblou
Comodo Family Member
***
Offline Offline

Posts: 86


« Reply #3 on: July 01, 2010, 09:56:03 AM »

Hii:

Thank you for testing it for me. Also could you test it on windows 7 home perimum 32bit as well please? SInce I formated my pc because of the tdl infection I have installed win 7 instead of xp. Thanks in advance.
Logged
dax123
Comodo Loves me
****
Offline Offline

Posts: 160


Big Clucker


« Reply #4 on: July 01, 2010, 10:04:08 AM »

Hii:

Thank you for testing it for me. Also could you test it on windows 7 home perimum 32bit as well please? SInce I formated my pc because of the tdl infection I have installed win 7 instead of xp. Thanks in advance.

not sure but I'll try Grin
(I'm downloading trial  Grin Grin)

I'm ready to perform the test.
my ENIAC is so slow you gotta have patience.
anyway Buster_BSA is doing similiar test.
http://www.wilderssecurity.com/showthread.php?t=276210
« Last Edit: July 01, 2010, 12:22:20 PM by dax123 » Logged

i cannot help but confess, dang I wanted to get that. LOL
Tech
Usability Study Member
Comodo's Hero
*****
Offline Offline

Posts: 3024



« Reply #5 on: July 01, 2010, 10:08:59 AM »

Thanks for testing. I'm really interested in the results.
I'm putting a lot of hope in the CTM, but if the data could be screwed up... well...
Logged

avast! team member
Save freeware snapshot technology of Comodo Time Machine. Vote!
dax123
Comodo Loves me
****
Offline Offline

Posts: 160


Big Clucker


« Reply #6 on: July 01, 2010, 12:37:39 PM »

(Windows 7 used to have a internal sandbox) for thread optimization's sake  Grin
« Last Edit: July 01, 2010, 03:01:23 PM by dax123 » Logged

i cannot help but confess, dang I wanted to get that. LOL
Apach
Comodo Loves me
****
Offline Offline

Posts: 161


« Reply #7 on: July 01, 2010, 02:47:09 PM »

CTM has been tested already - http://www.wilderssecurity.com/showpost.php?p=1704893&postcount=26
Logged
Tech
Usability Study Member
Comodo's Hero
*****
Offline Offline

Posts: 3024



« Reply #8 on: July 01, 2010, 02:54:33 PM »

Many thanks... Seems that it fails and we need to find a way to have secure snapshots.
Hope any of the programmers could comment this.
Logged

avast! team member
Save freeware snapshot technology of Comodo Time Machine. Vote!
dax123
Comodo Loves me
****
Offline Offline

Posts: 160


Big Clucker


« Reply #9 on: July 01, 2010, 02:59:42 PM »

Bad News.
I couldn't properly tested on my Virtualbox VM
SafeSys worm just keeps making BSOD so I couldn't test it Undecided
and under a limited account it just removes self.
I think this virus is aware of virtual environment.
gotta test again with VPC 2007



he just posted it several hours ago  Angel
that's a bad news again.
« Last Edit: July 01, 2010, 03:04:53 PM by dax123 » Logged

i cannot help but confess, dang I wanted to get that. LOL
Tech
Usability Study Member
Comodo's Hero
*****
Offline Offline

Posts: 3024



« Reply #10 on: July 01, 2010, 08:38:20 PM »

Is there a way to safe the snapshots?
Logged

avast! team member
Save freeware snapshot technology of Comodo Time Machine. Vote!
dax123
Comodo Loves me
****
Offline Offline

Posts: 160


Big Clucker


« Reply #11 on: July 01, 2010, 09:22:43 PM »

( thread moved to http://forums.comodo.com/news-announcements-feedback-ctm/light-virtualization-software-partial-sandbox-test-includes-ctmcisbox-t58848.0.html )

CTM is vulnerable to several malware samples.
« Last Edit: July 03, 2010, 02:40:02 PM by dax123 » Logged

i cannot help but confess, dang I wanted to get that. LOL
Flykite
Comodo Staff
Comodo's Hero
*****
Offline Offline

Posts: 290



« Reply #12 on: July 01, 2010, 09:50:36 PM »

Hi dax123:
    Please use CIS to protect against TDSS/TDL rootkits.
    Thanks a lot.
    Best Regards!
« Last Edit: July 01, 2010, 10:20:04 PM by Flykite » Logged
dax123
Comodo Loves me
****
Offline Offline

Posts: 160


Big Clucker


« Reply #13 on: July 01, 2010, 10:31:27 PM »

Hi dax123:
    Please use CIS to protect against TDSS/TDL rootkits.
    Thanks a lot.
    Best Regards!


so you've already tested with TDSS rootkits?
I have some kinds of TDSS rootkit and a SafeSys worm.
I can send you these samples right away  Grin
« Last Edit: July 01, 2010, 10:33:52 PM by dax123 » Logged

i cannot help but confess, dang I wanted to get that. LOL
Josh™
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 949



« Reply #14 on: July 01, 2010, 11:29:47 PM »

so you've already tested with TDSS rootkits?
I have some kinds of TDSS rootkit and a SafeSys worm.
I can send you these samples right away  Grin


Hey mate. Do you mind uploading and and PMing those samples to me (Just for testing purposes).

Josh
Logged

Think about this: "The number one reason why people give up so fast is because they tend to look at how far they still have to go, instead of how far they have gotten."
Tags:
Pages: [1] 2 3 4 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.05 seconds with 20 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com