Author Topic: Network shield and DCOM attacks  (Read 8150 times)

0 Members and 1 Guest are viewing this topic.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Network shield and DCOM attacks
« Reply #15 on: September 20, 2008, 02:31:02 PM »
Can I do an uninstall/reinstall while being offline or do I need to have an internet connection when doing this?
You can do it offline.

So in other words ... download and save Avast to my HD, go offline, uninstall avast, reboot, install, go online and then reboot.  Will that work?
Yes.
The best things in life are free.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: Network shield and DCOM attacks
« Reply #16 on: September 20, 2008, 04:04:57 PM »
Can I do an uninstall/reinstall while being offline or do I need to have an internet connection when doing this?  I continue to get a getting a flurry of these DCom Exploit attacks and while I hope that Comodo will catch them if I uninstall Avast, I always like to play it safe.  So in other words ... download and save Avast to my HD, go offline, uninstall avast, reboot, install, go online and then reboot.  Will that work?

Not only can you uninstall/reinstall avast off-line, but that is the recommended action. You don't have to go on-line between the reinstall and reboot.

This is why I suggested getting the new version before uninstalling the old version, so you 'don't' have to go on-line unprotected to get the new version.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

AverageJoe72

  • Guest
Re: Network shield and DCOM attacks
« Reply #17 on: September 21, 2008, 07:57:02 AM »
Thanks for the replies!

I did the uninstall/reinstall for Avast but that unfortunately did not resolve the issue.  I'm still getting the same DCOM Exploit warnings from Avast (port 135) as I did before.  The Comodo firewall continues to perform as intended and is stopping inbound violations including some at port 135.  For some reason Avast is getting to just a select few before the firewall.  I did a retest for firewall leaking and it checks out fine.  It's bewildering why Comodo stops the vast majority of inbound violations except for a few where Avast seems to beat it to the punch.

Is there anyway to know if those select few DCOM warnings from Avast have leaked past Comodo?

I've been trying to think of what has changed on my system that corresponded to timing of these Avast warnings for DCOM exploits that I've never had in the past.  Only thing I can think of is that I did an upgrade to SP3.  Could that have messed up the ordering of AV and Firewall?

The silver lining is that nothing is penetrating as far as I know but it's bewildering that Avast would stop some port 135 intrusions before the firewall.

As to the recommendation for installing a router, wouldn't that be overkill?  I have one computer with a direct link to DSL and don't need wireless.  Wouldn't the firewall in a wired router be superfluous to the Comodo firewall?  I'm not up to speed on what a router firewall would do that Comodo's firewall wouldn't?  Any suggestions in that regard?  I've also heard that routers can slow down connection speeds.

I suppose the next step is to upgrade to Comodo's version 3 to see if that will fix this issue but I really dread doing that.

Again, thanks for the assistance.  It's much appreciated.

YoKenny

  • Guest
Re: Network shield and DCOM attacks
« Reply #18 on: September 21, 2008, 11:06:55 AM »
Quote
As to the recommendation for installing a router, wouldn't that be overkill?  I have one computer with a direct link to DSL and don't need wireless.
Who is the manufacturer of the DSL modem and what is its model number?

My ISP supplied SpeedStream 6520 DSL modem has a built in firewall so I don't see any DCOM warnings from Avast.

Software based firewalls are a waste of system resources if you have a hardware based firewall according to MBAM developer 10 minute video:
http://www.besttechie.net/2008/08/20/malwarebytes-developer-interview

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Network shield and DCOM attacks
« Reply #19 on: September 21, 2008, 08:50:01 PM »
Is there anyway to know if those select few DCOM warnings from Avast have leaked past Comodo?
Good question. It's an egg/chicken problem between the antivirus and the firewall...

Only thing I can think of is that I did an upgrade to SP3.  Could that have messed up the ordering of AV and Firewall?
Can't you install both from the scratch (uninstall/boot/install again/boot)?

Wouldn't the firewall in a wired router be superfluous to the Comodo firewall?
Yes, the software firewall should do the work.

I suppose the next step is to upgrade to Comodo's version 3 to see if that will fix this issue but I really dread doing that.
It's a good idea...
The best things in life are free.