PDA

View Full Version : TDS-3 was tested again ...


ntl
September 27th, 2004, 05:17 PM
See here

http://www.vnunet.de/table.asp?ArticleID=20040826042&table_con_id=4

and here

http://www.vnunet.de/testticker/Security/article.asp?ArticleID=20040826042&Ref=pc-pro

Bowserman
September 27th, 2004, 09:13 PM
Hi ntl :).

Would you mind giving us an overview in english?

Regards,
Jade.

Starrob
September 27th, 2004, 09:38 PM
I used some language translation software on those links (it is written in German) and the basic gist of the links is that TDS3 rates the best out of those tested which are:

TDS3, Spionage-Abwehr, Anti-Trojan Shield 2.2, Ewido Security Suite Free, Trojan Hunter 3.9, A2 Personal 1.0, Digital Patrol Scanner 5.0, Tauscan 1.7, Swat It Pro 2.1, and Trojan Shield 2.2.



Starrob

Wayne - DiamondCS
September 27th, 2004, 10:32 PM
Nautilus,
Could you kindly drop me a private message when you get a spare moment?
(It's nothing related to trojans, tests or anything like that)

Cheers,
Wayne

Bowserman
September 28th, 2004, 01:33 AM
-{ Quote: "I used some language translation software on those links (it is written in German) and the basic gist of the links is that TDS3 rates the best out of those tested which are:

TDS3, Spionage-Abwehr, Anti-Trojan Shield 2.2, Ewido Security Suite Free, Trojan Hunter 3.9, A2 Personal 1.0, Digital Patrol Scanner 5.0, Tauscan 1.7, Swat It Pro 2.1, and Trojan Shield 2.2.
Starrob" }-

Yep, thanks Starrob :).


Here is a Google translation of the second link Nautilus provided:

-{ Quote: "Comparison test: Trojanerscanner


Aggressor in the PC
....................

Article from PC professionally expenditure 9/2004
Authors: Burkhard Mueller, Wolfgang Nefzger




Introduction

Zombies form Botnets

Increasingly kapern criminal elements of strange PC over the InterNet. The aggressors do not want to up-polish their Ego or impress to friends, them want to the large money. Stolen passwords and credit card data can be silvered. It, the remote controlled computers is still simpler to letting for the Spam dispatch. Or how waers with the extortion of an on-line enterprise? The internationally organized Mafia is inventive.

Sounds after a bad film, is however reality. Hundredthousands of PC world-wide are open like barn gates, as soon as the owners in the InterNet move. Meeting can do it everyone: According to a study of Web scythe ( www.websense.com/Web@Work/2004 ) each third firm computer with espionage programs is contaminated for example. The generic term for aggressors, that permit such attacks: Trojaner or also Backdoor (English back door). Behind these designations variety at parasits hides itself.

The trend with criminal attacks goes for some months into a new direction: Aggressors look for not only only one PC, but infect many thousand PCS by means of dangerous worms and viruses. Each of these PCS can be remote controlled then over a Backdoor, it the Zombie became figurativy spoken a jargon expression for compromised computers. The programs, which infect PC, are called Bots. A multiplicity at Bots, which become remote controlled from a computer, form a Botnet.




Automatic infection

Such Botnets can be abused for many purposes. Experts assume for example approximately 30 per cent of the Spam Mails dispatched world-wide over Botnets are distributed. Because the Spam messages thereby have many different sender IP addresses, are only difficult they to repel. Since with the dispatch by Spam money is actually made, is worthwhile oneself financially also for the operators of Botnets.

In recent past it gave besides some attempted blackmail opposite professional Websites, about offerers of sport bets. Do not pay their operator the demanded money, then the blackmailers start an Distributed Denial OF service attack (dd OS). They give the instruction to the Zombies in the Botnet to bombard the Web server of the victim with packets. This cannot master the multiplicity of inquiries, so that he is no longer attainable. Apart from the image damage a on-line Shop or an on-line office thereby loses also material conversion.

How does the Trojaner come on the non removable disk? The classical way leads across Downloads from the InterNet. Trojaner hang themselves Huckepack to unsuspected programs and install themselves with the program start unnoticed in the background. Exchange stock exchanges such as Kazaa are thereby a true breeding place for Trojaner and Backdoors.

Besides modern Trojaner uses the usual spreading techniques of viruses and worms: Mass enamel, approved Windows drive assemblies in LAN and InterNet as well as passing on with robbery-copied programs. Some Trojaner uses also aimed Backdoors, which opened other viruses and worms on an infected PC. Mydoom and Sasser spread automatically over Windows Sicherheitsluecken. They open Backdoors, over which an aggressor can transfer its Trojaner. Some Trojaner looks independently for such infectable systems.




Obligation: combined protection programs

As for viruses there are special scanners, which are to seek out and remove the parasits also for Trojaner. For this comparison test the PC professional testers infect a Windows XP system with 433 spread Trojanern and test among other things the recognition as well as the distance rate. As comparison Norton anti-virus is used 2004 as well-known representatives of the virus scanner parliamentary group. Do Trojanerscanner work actually better than virus scanners?

The result does not look good for the Trojanerscanner: The test winner Trojan Defence Suite had the best erkennungsrate of 93 per cent, is thus somewhat better than Norton anti-virus with 90 per cent. Digitally Patrol and Ewido follow with 82 per cent each. With the distance rate it looks still worse: The Norton product removes nevertheless 78 per cent, followed from digitally Patrol with only 63 per cent and Ewido with 60 per cent. Cannot even remove half of all parasits for filters of the eleven candidates.

Only the recognition of the 433 test Trojaner as file on the non removable disk controls Trojan Defence Suite as only scanners somewhat better than Norton an anti-virus. With cleaning the Registry some scanners are more successful than Norton, but delete Norton for it all Trojanerdateien, the Registry entries are ineffective thereby. For inexperienced users a good anti-virus program is therefore the better choice. Additionally a Desktop Firewall on each PC who belongs against it Trojanern and other harmful programs on process level to after-feel wants (see "know-how: Feeler gauges unmask ", page 126), seize to Trojan Defence Suite." }-

Not the best translation, but readable.

Regards,
Jade.

----
September 28th, 2004, 01:38 AM
@ Wayne: Sent you an e-mail. Regards, ntl

@ Starrob: Correct. TDS-3 came in first. As regards the table: The term "Leistung" means "performance", "Funktionen" means "features", and "Bedienung" means "(ease of) use".