Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
May 17, 2008, 12:12:07 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
155332
Posts
19194
Topics
47347
Members
Latest Member:
AlCzervik
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Anti Virus/Malware Products/Other Security products
Please feel free to ask any questions to learn all about Computer Security.
« previous
next »
Pages:
[
1
]
2
3
...
5
Author
Topic: Please feel free to ask any questions to learn all about Computer Security. (Read 11751 times)
Melih
Comodo's Hero
Administrator
Comodo's Hero
Online
Posts: 4752
Please feel free to ask any questions to learn all about Computer Security.
«
on:
December 30, 2006, 10:15:27 PM »
Here you will have access to the world's best security experts to help you learn all about Computer security!
feel free to ask!
Melih
Logged
pilger7
Newbie
Offline
Posts: 1
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #1 on:
January 04, 2007, 12:00:25 AM »
yeah ok i had some body hack my computer threw my space with something called malware,trogen and i guess they used my enternet exployer to monitor well i was going to report but they already wiped there activite from my personal e-mail i got all the software and firewalls and virus killers etc,etc, defraged scaned changed passwords but and removed old software but i still have this stupid window pop up about a networm-i.virus[ at ]fp and something about files and i'm getting these ad's to by software but there comeing from the same host but my new software says my computer is free from infection?can u help resolve this and help me report or catch this s.o.b. thanks Jay
Logged
Melih
Comodo's Hero
Administrator
Comodo's Hero
Online
Posts: 4752
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #2 on:
January 04, 2007, 01:37:56 PM »
Quote from: pilger7 on January 04, 2007, 12:00:25 AM
yeah ok i had some body hack my computer threw my space with something called malware,trogen and i guess they used my enternet exployer to monitor well i was going to report but they already wiped there activite from my personal e-mail i got all the software and firewalls and virus killers etc,etc, defraged scaned changed passwords but and removed old software but i still have this stupid window pop up about a networm-i.virus [ at ] fp and something about files and i'm getting these ad's to by software but there comeing from the same host but my new software says my computer is free from infection?can u help resolve this and help me report or catch this s.o.b. thanks Jay
Well it seems as if, your machine is still infected!
You can go to the Malware cleaning section of the Comodo Anti virus and put a post there and we'll help you there to get rid of this.
thanks
Melih
Logged
mal233
Newbie
Offline
Posts: 2
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #3 on:
March 17, 2007, 10:12:35 AM »
Melih,
I have the logmein.com problem as well. I will attach the log file to see if that helps you fix this problem. AVG 7.1 and 7.5 do not ID these files as a virus. They are two updates to best of my knowledge. Hope this helps.
Mark
Logged
kishork
Guest
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #4 on:
March 20, 2007, 12:07:19 AM »
Hi Mark,
These detected files are have capability of remote administration and hence these are detected. Other AVs are also detecting it. You can varify it by scanning the file from virustotal (virustotal.com)
If you want to use these files, you can exclude them from scanning
To exclude files/folders from scanning, do the followings
1.Go to main window->Settings->On Demand->Advanced->What items to exclude->Select. Then selects files/folders to exclude from scanning.
2.Go to main window->Settings->On Access->Advanced->What items to exclude->Select. Then selects files/folders to exclude from scanning.
Thanks & regards
Kishor
Logged
LeoniAquila
Forum Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2137
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #5 on:
March 23, 2007, 06:38:42 PM »
Thank you for this opportunity!
I would like to ask about rootkits, which I think are some very small programs hiding deep down in the system. But I don't know what they are capable of. Are these threats serious? Does Comodo (Firewall or AV perhaps) prevent from rootkits?
As I heard of a free anti-rootkit called Sophos Anti-Rootkit 1.2, I tried it and it has now searched through my system (XP with CPF and avast). Now I'm a bit concerned because it actually found a non-removable, hidden registry key: \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\d347prt\Cfg\0Jf40
Do you have any idea at all what this is about? My only idea is that I've used the Neowin UXTheme patch to open up for other Windows themes than just the original Microsoft theme "Luna". The patch makes changes to Windows system files, maybe this is the reason?
Logged
Windows XP SP3 nLite ··· CFP 3.0 ··· FF 3.0 β 5 ··· IE 6
Soyabeaner
VOLUNTEER
Global Moderator
Comodo's Hero
Offline
Posts: 5526
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #6 on:
March 23, 2007, 07:14:50 PM »
I'm not an expert, so ignore this post if you don't mind.
Quote from: LeoniAquila on March 23, 2007, 06:38:42 PM
I would like to ask about rootkits, which I think are some very small programs hiding deep down in the system. But I don't know what they are capable of. Are these threats serious? Does Comodo (Firewall or AV perhaps) prevent from rootkits?
Destructive? Potentially. Look at the
Sony deal
. CFP 3 will prevent it because of HIPS. CAV currently should because it already has HIPS.
Quote from: LeoniAquila on March 23, 2007, 06:38:42 PM
\HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\d347prt\Cfg\0Jf40
Do you have any idea at all what this is about? My only idea is that I've used the Neowin UXTheme patch to open up for other Windows themes than just the original Microsoft theme "Luna". The patch makes changes to Windows system files, maybe this is the reason?
I also used Neowin patch for extended Windows themes, but I don't have this registry key (or maybe it's not visible with regedit.exe?). I discovered that it's
Daemon tools / Alcohol120%
, so you're off the "hook" lol.
Remember that with any security scanner there could be false positives. As with anti-rootkits, they could detect legitimate rootkits / hooks as well, so watch out for that.
«
Last Edit: March 23, 2007, 07:19:30 PM by Soya
»
Logged
Never argue with an idiot; they'll drag you down to their level and beat you with experience.
LeoniAquila
Forum Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2137
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #7 on:
March 24, 2007, 07:07:46 AM »
Thank you Soya for your answer. I've read something about the Sony stuff, will check it further!
You're right about DAEMON Tools, because this has been confirmed in another forum where I posted a message yesterday. And it should be harmless.
Now, more rootkits: After my message here yesterday, I scanned with Spybot. It only found some logs, of which one belonged to Media Player Classic from Gabest. I removed this, and "just for fun" I made another scan with Sophos Anti-Rootkit, which actually listed another rootkit that referred to this Gabest thing. Quite strange I think, but I suppose it's harmless too.
By the way, isn't the Neowin patch a very smart thing to make Windows look nicer?
Logged
Windows XP SP3 nLite ··· CFP 3.0 ··· FF 3.0 β 5 ··· IE 6
Soyabeaner
VOLUNTEER
Global Moderator
Comodo's Hero
Offline
Posts: 5526
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #8 on:
March 24, 2007, 07:18:45 AM »
Quote from: LeoniAquila on March 24, 2007, 07:07:46 AM
Now, more rootkits: After my message here yesterday, I scanned with Spybot. It only found some logs, of which one belonged to Media Player Classic from Gabest. I removed this, and "just for fun" I made another scan with Sophos Anti-Rootkit, which actually listed another rootkit that referred to this Gabest thing. Quite strange I think, but I suppose it's harmless too.
I think it's more false positives than strange. Don't rely on one anti-rootkit scanner. Rootkits are the newest breed of malware, so it's better to try more
anti-rootkits
if you're so interested. I also have
MPC
and
Gabest
is its developer
. You can also see associated files with MPC in CFP's Component Monitor.
Quote from: LeoniAquila on March 24, 2007, 07:07:46 AM
By the way, isn't the Neowin patch a very smart thing to make Windows look nicer?
Hopefully it isn't the cause of other "unexplained" issues with CFP, but no doubt it's necessary to ease the eyes
. Why Windows would limit to just a few themes (that isn't even beautiful) is beyond me.
Logged
Never argue with an idiot; they'll drag you down to their level and beat you with experience.
LeoniAquila
Forum Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2137
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #9 on:
March 24, 2007, 10:55:28 AM »
Ok, good to know that there is protection available
As for Windows styles and CPF problems, there is at least one issue: when resizing the title bar (well, you don't even need any patch to do this!), the UI title bar of CPF becomes black and the three buttons on the right disappears (but the functionality of the buttons remains). When maximizing the window, the title bar becomes transparent instead! However it becomes normal if you reboot (still with the new title bar size). Really not a big issue, but I've posted a ticket to Comodo anyway, which they have responded to. They will try to solve it for CPF version 3. Perhaps you have noticed this too, since you obviously change themes (and thereby probably also title bar size)?
/L
Logged
Windows XP SP3 nLite ··· CFP 3.0 ··· FF 3.0 β 5 ··· IE 6
Soyabeaner
VOLUNTEER
Global Moderator
Comodo's Hero
Offline
Posts: 5526
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #10 on:
March 24, 2007, 11:13:55 AM »
You're about the 5th user to report this, with myself included.
You did know that rebooting isn't necessary, didn't you? Just open Task Manager and end explorer.exe. Then go to File > New Task (Run...) > enter
explorer.exe
(in some environments the .exe extension isn't even needed when running known Windows commands). This is definitely a faster procedure because some programs are still running.
Logged
Never argue with an idiot; they'll drag you down to their level and beat you with experience.
LeoniAquila
Forum Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2137
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #11 on:
March 25, 2007, 03:51:24 AM »
I don't reboot anymore, the issue isn't serious enough I think! Just restarting Explorer seems like a simple method, I havn't tried it though.
/L
Logged
Windows XP SP3 nLite ··· CFP 3.0 ··· FF 3.0 β 5 ··· IE 6
jhunjhun
Newbie
Offline
Posts: 4
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #12 on:
April 08, 2007, 03:27:33 AM »
Hi , I'm just new to COMODO. I just installed COMODO firewall the other day. I quite feel safe and confident surfing the internet. And I really thank COMODO for this. As I study the different function of this software, under Activity>>>Log, there is a lot and continues of traffic going on. And the description said
Inbound Policy Violation, Access Denied(UDP or IGMP
). Most of the source come from
nbdgram
and some are
nbname
. I just want to know if this thing is
normal.
. Hoping for any answer.
Thank you,
Jhun
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 4673
Life may suck, but contemplate the alternative.
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #13 on:
April 08, 2007, 07:01:44 AM »
nbdgram and nbname are caused by Windows peer-to-peer networking. It's caused when a LAN workstation startsup and advertises its name and details across the LAN.
Providing you want to join the LAN, you 'll need to run the "add a trusted network" wizard (under SECURITY - TASKS). This will automatically create rules that allow LAN based comms to occur and your error messages will disappear.
Cheers,
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
arjunpa
Comodo Family Member
Offline
Posts: 63
Iam Cool
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #14 on:
April 10, 2007, 04:02:02 AM »
I like to know whether i can uninstall comodo antivirus beta 2 properly?
Logged
Tags:
Pages:
[
1
]
2
3
...
5
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> General Discussion (off topic) Anything and everything...
-----------------------------
Desktop Security Products
-----------------------------
===> Help for v2
=> AntiSpam
=> Comodo Anti-Viruspyware (CAVS)
=> Backup
-----------------------------
Free Services for End Users
-----------------------------
=> Hacker Guardian
-----------------------------
Desktop Security Products
-----------------------------
=> i-Vault
=> Launch Pad
-----------------------------
Free Services for End Users
-----------------------------
=> Comodo Meet (Web Conferencing Product)
-----------------------------
Web Server Products
-----------------------------
=> Trustlogo
-----------------------------
Desktop Security Products
-----------------------------
=> Trusttoolbar
=> Verification Engine (allows you to verify what you see on the Internet)
-----------------------------
Digital Certificates
-----------------------------
=> SSL Certificate
=> Email Certificate
=> Content Verification Certificate
=> Code Signing Certificate
-----------------------------
Free Services for End Users
-----------------------------
=> Trustfax (free Trial) (online faxing)
-----------------------------
Infrastructure Products
-----------------------------
=> Trustix Enterprise Firewall
-----------------------------
Want to help Comodo?
-----------------------------
===> Help spread the word! (Please read and help)
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
-----------------------------
General Category
-----------------------------
=> Which Product do you want Comodo to develop next?
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> Italiano / Italian
===> ελληνικά / Greek
===> Turkce / Turkish
-----------------------------
Desktop Security Products
-----------------------------
===> Frequently Asked Questions (FAQ) for Comodo firewall
-----------------------------
Want to help Comodo?
-----------------------------
=> Please tell us your views and Vote here!
-----------------------------
Free Services for End Users
-----------------------------
=> User Anywhere (Remote Access product)
-----------------------------
International Comodo Forums
-----------------------------
===> Espanol / Spanish
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
-----------------------------
International Comodo Forums
-----------------------------
===> Português/Portuguese
-----------------------------
Want to help Comodo?
-----------------------------
=> How can you help Comodo? (Please we do need you!)
-----------------------------
International Comodo Forums
-----------------------------
===> Nihongo / Japanese
-----------------------------
Desktop Security Products
-----------------------------
===> FAQ for Comodo Anti-ViruSpyware
-----------------------------
Want to help Comodo?
-----------------------------
===> Comodo website issues for submitting website problems only
-----------------------------
General Category
-----------------------------
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Desktop Security Products
-----------------------------
===> Virus/Malware Removal Assistance
===> Comodo Firewall Translations
-----------------------------
International Comodo Forums
-----------------------------
===> Svenska / Swedish
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Anti Phishing solutions
=> HIPS (Host Intrusion Prevention Systems)
=> Digital Certificates, Encryption and Digital Signing
-----------------------------
International Comodo Forums
-----------------------------
===> Francais / French
===> По-русски / Russian
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Magyar / Hungarian
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
-----------------------------
International Comodo Forums
-----------------------------
===> Deutsch / German
===> Polski / Polish
===> Norsk / Norwegian
===> Українська / Ukrainian
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo BOClean Anti-Malware
===> Comodo BOClean Anti-Malware FAQ
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments (not product related)
-----------------------------
Desktop Security Products
-----------------------------
===> Help for Comodo AntiVirus
-----------------------------
International Comodo Forums
-----------------------------
===> tiếng Việt / Vietnamese
-----------------------------
Desktop Security Products
-----------------------------
===> Announcements
===> Feedback/Comments/Announcements/News about CAVS
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> FAQ for Comodo Backup
=> Comodo TrustConnect - Securing the Wireless world!
===> Help
===> Help for v3
===> Bug Reports
===> Feedback/Comments/Announcements/News
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Vulnerability Analyzer
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
Page created in 0.268 seconds with 18 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com