Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 23, 2013, 04:23:32 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663806
Posts
70589
Topics
145226
Members
Latest Member:
oldwiseowls
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Time Machine - CTM
News / Announcements / Feedback - CTM
does CTM protect against TDSS/TDL rootkits?
« previous
next »
Pages:
[
1
]
2
3
4
Author
Topic: does CTM protect against TDSS/TDL rootkits? (Read 22163 times)
taleblou
Comodo Family Member
Offline
Posts: 86
does CTM protect against TDSS/TDL rootkits?
«
on:
June 30, 2010, 08:22:25 PM »
Hi:
I would like to know does using CTM and make snapshot of clean computers and later during a tdss/tdl rootkit infection when trying to restore a clean snapshot get rid of the tdl/tdss rootkits? The reason is I used wondershare time-freeze virtualization and a tdl-3 rootkit by passed it and infected my pc forcing a format to make sure is clean and I have heard shadow defender also fails tdl/tdss rootkits. SO on my new formated pc I was wondering if I use CTM will it protect me against these rootkit or will the snapshots and CTM get infected as well?
Also anyone knows any protection against these rootkits? By the way I have CIS perimum and it failed to detect the rootkit. The only softwares detected was hitman pro 3.5 and GMER. Thanks in advance for your reply.
Logged
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: does CTM protect against TDSS/TDL rootkits?
«
Reply #1 on:
June 30, 2010, 08:29:00 PM »
Most probably yes. You can have a clean computer after restoring the clean snapshot.
But I'm not an expert on CTM (yet).
If GMER detects it, avast will do the same (as the full GMER technology is bundled into avast).
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
dax123
Comodo Loves me
Offline
Posts: 160
Big Clucker
Re: does CTM protect against TDSS/TDL rootkits?
«
Reply #2 on:
July 01, 2010, 09:36:16 AM »
I'll do the tests using my samples.
It can screw systems with returnil, shadow defender, deepfreeze, time freeze etc.
I'm installing xp in my vpc and will test it as soon as it finishes.
«
Last Edit: July 01, 2010, 09:54:41 AM by dax123
»
Logged
i cannot help but confess, dang I wanted to get that.
LOL
taleblou
Comodo Family Member
Offline
Posts: 86
Re: does CTM protect against TDSS/TDL rootkits?
«
Reply #3 on:
July 01, 2010, 09:56:03 AM »
Hii:
Thank you for testing it for me. Also could you test it on windows 7 home perimum 32bit as well please? SInce I formated my pc because of the tdl infection I have installed win 7 instead of xp. Thanks in advance.
Logged
dax123
Comodo Loves me
Offline
Posts: 160
Big Clucker
Re: does CTM protect against TDSS/TDL rootkits?
«
Reply #4 on:
July 01, 2010, 10:04:08 AM »
Quote from: taleblou on July 01, 2010, 09:56:03 AM
Hii:
Thank you for testing it for me. Also could you test it on windows 7 home perimum 32bit as well please? SInce I formated my pc because of the tdl infection I have installed win 7 instead of xp. Thanks in advance.
not sure but I'll try
(I'm downloading trial
)
I'm ready to perform the test.
my ENIAC is so slow you gotta have patience.
anyway Buster_BSA is doing similiar test.
http://www.wilderssecurity.com/showthread.php?t=276210
«
Last Edit: July 01, 2010, 12:22:20 PM by dax123
»
Logged
i cannot help but confess, dang I wanted to get that.
LOL
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: does CTM protect against TDSS/TDL rootkits?
«
Reply #5 on:
July 01, 2010, 10:08:59 AM »
Thanks for testing. I'm really interested in the results.
I'm putting a lot of hope in the CTM, but if the data could be screwed up... well...
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
dax123
Comodo Loves me
Offline
Posts: 160
Big Clucker
Re: does CTM protect against TDSS/TDL rootkits?
«
Reply #6 on:
July 01, 2010, 12:37:39 PM »
(Windows 7 used to have a internal sandbox) for thread optimization's sake
«
Last Edit: July 01, 2010, 03:01:23 PM by dax123
»
Logged
i cannot help but confess, dang I wanted to get that.
LOL
Apach
Comodo Loves me
Offline
Posts: 161
Re: does CTM protect against TDSS/TDL rootkits?
«
Reply #7 on:
July 01, 2010, 02:47:09 PM »
CTM has been tested already -
http://www.wilderssecurity.com/showpost.php?p=1704893&postcount=26
Logged
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: does CTM protect against TDSS/TDL rootkits?
«
Reply #8 on:
July 01, 2010, 02:54:33 PM »
Quote from: Apach on July 01, 2010, 02:47:09 PM
CTM has been tested already -
http://www.wilderssecurity.com/showpost.php?p=1704893&postcount=26
Many thanks... Seems that it fails and we need to find a way to have secure snapshots.
Hope any of the programmers could comment this.
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
dax123
Comodo Loves me
Offline
Posts: 160
Big Clucker
Re: does CTM protect against TDSS/TDL rootkits?
«
Reply #9 on:
July 01, 2010, 02:59:42 PM »
Bad News.
I couldn't properly tested on my Virtualbox VM
SafeSys worm just keeps making BSOD so I couldn't test it
and under a limited account it just removes self.
I think this virus is aware of virtual environment.
gotta test again with VPC 2007
Quote from: Apach on July 01, 2010, 02:47:09 PM
CTM has been tested already -
http://www.wilderssecurity.com/showpost.php?p=1704893&postcount=26
he just posted it several hours ago
that's a bad news again.
«
Last Edit: July 01, 2010, 03:04:53 PM by dax123
»
Logged
i cannot help but confess, dang I wanted to get that.
LOL
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: does CTM protect against TDSS/TDL rootkits?
«
Reply #10 on:
July 01, 2010, 08:38:20 PM »
Is there a way to safe the snapshots?
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
dax123
Comodo Loves me
Offline
Posts: 160
Big Clucker
Re: does CTM protect against TDSS/TDL rootkits?
«
Reply #11 on:
July 01, 2010, 09:22:43 PM »
( thread moved to
http://forums.comodo.com/news-announcements-feedback-ctm/light-virtualization-software-partial-sandbox-test-includes-ctmcisbox-t58848.0.html
)
CTM is vulnerable to several malware samples.
«
Last Edit: July 03, 2010, 02:40:02 PM by dax123
»
Logged
i cannot help but confess, dang I wanted to get that.
LOL
Flykite
Comodo Staff
Comodo's Hero
Offline
Posts: 290
Re: does CTM protect against TDSS/TDL rootkits?
«
Reply #12 on:
July 01, 2010, 09:50:36 PM »
Hi dax123:
Please use CIS to protect against TDSS/TDL rootkits.
Thanks a lot.
Best Regards!
«
Last Edit: July 01, 2010, 10:20:04 PM by Flykite
»
Logged
dax123
Comodo Loves me
Offline
Posts: 160
Big Clucker
Re: does CTM protect against TDSS/TDL rootkits?
«
Reply #13 on:
July 01, 2010, 10:31:27 PM »
Quote from: Flykite on July 01, 2010, 09:50:36 PM
Hi dax123:
Please use CIS to protect against TDSS/TDL rootkits.
Thanks a lot.
Best Regards!
so you've already tested with TDSS rootkits?
I have some kinds of TDSS rootkit and a SafeSys worm.
I can send you these samples right away
«
Last Edit: July 01, 2010, 10:33:52 PM by dax123
»
Logged
i cannot help but confess, dang I wanted to get that.
LOL
Josh™
Global Moderator
Comodo's Hero
Offline
Posts: 949
Re: does CTM protect against TDSS/TDL rootkits?
«
Reply #14 on:
July 01, 2010, 11:29:47 PM »
Quote from: dax123 on July 01, 2010, 10:31:27 PM
so you've already tested with TDSS rootkits?
I have some kinds of TDSS rootkit and a SafeSys worm.
I can send you these samples right away
Hey mate. Do you mind uploading and and PMing those samples to me (Just for testing purposes).
Josh
Logged
Think about this:
"The number one reason why people give up so fast is because they tend to look at how far they still have to go, instead of how far they have gotten."
Tags:
Pages:
[
1
]
2
3
4
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.05 seconds with 20 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com