TDSS Dynamic test -Tacitus Project by XCTeam

I have to go out right now. I will come back when I have time. But I am not the member of XCteam. I am a reader of XCTeam report from AVPClub site.

wow, thanks for your hard work :slight_smile:

完全通過測試的廠商數:9 家 (# of Vendors which Successful Protecting the system: 9)
部分通過測試的廠商數:3 家 (# of Vendors which partial protecting the system: 3)
未通過測試的廠商數:18 家 (# of Vendors which fail to protect the system: 18)

完全通過測試 (9 Vendors which protect infection from TDSS test)
BluePoint Security 2010
BufferZone Free 3.31
DefenseWall 3.06
Gentel Security GeSWall 2.9
Emsisoft Online Armor Free 4.0
Online Solution Security Suite 1.5
PC Tools ThreatFire 4.73
Sandboxie 3.48
Xacti Spyware Terminator 2.7.2

部分通過測試 (3 Vendors which providing SanBox that can protect the system, it is called partial protection)
avast! IS 5.0(SandBox)
COMODO Internet Security 4.1(SandBox)
Kaspersky Internet Security 2011(SandBox)

未通過測試(18 Vendors which fail to protect the system from TDSS test)
Avira AntiVir Premium 10
Agnitum Outpost Firewall 7.0
avast! Free 5.0
AVG Identity Protection 9
BitDefender AntiVirus Pro 2011
DriveSentry Desktop 3.4
Emsisoft Mamutu 3.0
F-Secure Internet Security 2010
Filseclab Twister AntiVirus V7 R3
GDATA AntiVirus 2011
Immunet Protect 2.0
Norman Security Suite Pro 2010
Panda AntiVirus Pro 2011
Privacyware Privatefirewall 7.0
SpyShelter 4.52
Trend Micro Titanium 3.0
Xacti System Protect
Zemana AntiLogger 1.9.2
Norton Power Eraser 1.5

版權聲明

  1. 本報告公開發表於AVPClub Security Forums。
  2. 本報告之內容文字、使用圖片所有權均屬於XC Team之Justin Chen
    與asusp4b533 所有。
  3. 本報告中測試圖片中的Logo 屬於原廠商所有,測試圖片本身屬於
    XC Team 所有。
  4. 本報告可以任意轉載,但不得用於任何商業用途。
  5. 本報告不得修改其中之內容,否則XC Team 不負任何法律責任。
  6. 其餘項目皆受 中華民國 之「修正【著作權法】」之保障。

Copyright announcement:

  1. This report is issued in AVPClub Security Forums.
  2. The copyright of all of the Contents and pictures in this report are blonging to Mr. Justin Chen of XC Team.
  3. Logo Copyright of the Testing Vendors are all belong to their Ventor, charts in the testing report are XCTeam’s copyright.
  4. Report can be re-post or re-used in noncommerical purpose only.
  5. Is is not allowed to modify any content when re-post or re-used the content, otherwise, XCTeam does not have any legal liability.
  6. Rest of the Other copyright issues are protected by Taiwan’s copyright law.

My translation is poor. Any translation against original report, shall be follow original verison.

WinBMY ,
Thanks a lot for responding to my post
You did a great job anyway, despite stating imperfections in your translation.
Sure there are some questions, but still that is laudable, when user is willing to help & spend his/here own time doing that

Few things to mention without any criticism intended whatsoever towards the translation?

  • the HIPS mentioning was ambiguous why would one want “always answer No” ???
    Rather disable the feature. 88)
  • why sandboxing was on/off and anyway tested in Virtual environment - that is weird
    -“Kaspersky TDSSKiller to scann for verifying if the PC affected or not…”
    well that was an on-demand scan for inactive malware, wasn’t it?
    therefore how Mamutu, for example, was tested - meaning it has to stop/block the active one … according to the answer, but then was it quarantined? … That is not clear
    Sure, another AV can find “inactive residue” if the above was not done
  • Realtime Anti-Virus detection function was disabled during this test.

This and testing pure Behavioural Blocker (BB) like Mamutu is close to some previous tests were BB was tested together with firewalls - that was less than funny :o

  • similarly, what is questionable - is testing pure keyloggers as Zemana amongst AVs and Firewalls

So there are still many questions regarding the methodology

As for the translations: what does it mean “SandBox(Unrestricted)”
“Unrestricted” in what sense ?
Allowed to be active without restrictions?
Probably you meant “Enabled”
or
maybe, since there is a a negative prefix that should be interpreted as “disabled”?
which changes the meaning completely… just guessing

Anyway, man thanks a lot again for the job done

The next step would be for the developers to clarify some points

My regards. Cheers! :-TU

SiberLynx,

Thanks. I do my best for translating the key part of this test. But I can not answer your qeustions. I don’t know, either.

Regards,

WinBMY

I think you already done a good enough translation. As this is only a kind of executive summary report, I don’t think it can answer too much test details from the report.

By the way, “unrestricted” is just one of the security level of Comodo 4.1 sandbox.