Welcome, Guest. Please login or register.
July 25, 2008, 05:14:45 PM

Login with username, password and session length

177071 Posts
20935 Topics
50761 Members

Latest Member: Touriste

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Anti Virus/Malware Products/Other Security products
| | |-+  Please feel free to ask any questions to learn all about Computer Security.
« previous next »
Pages: [1] 2 3 ... 5 Go Down Print
Author Topic: Please feel free to ask any questions to learn all about Computer Security.  (Read 15670 times)
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 5082



WWW
« on: December 30, 2006, 10:15:27 PM »

Here you will have access to the world's best security experts to help you learn all about Computer security!

feel free to ask!

Melih
 
Logged

pilger7
Newbie
*
Offline Offline

Posts: 1


« Reply #1 on: January 04, 2007, 12:00:25 AM »

yeah ok i had some body hack my computer threw my space with something called malware,trogen and i guess they used my enternet exployer to monitor well i was going to report but they already wiped there activite from my personal e-mail i got all the software and firewalls and virus killers etc,etc, defraged scaned changed passwords but and removed old software but i still have this stupid window pop up about a networm-i.virus[ at ]fp and something about  files and i'm getting these ad's to by software but there comeing from the same host but my new software says my computer is free from infection?can u help resolve this and help me report or catch this s.o.b. thanks Jay
Logged
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 5082



WWW
« Reply #2 on: January 04, 2007, 01:37:56 PM »

yeah ok i had some body hack my computer threw my space with something called malware,trogen and i guess they used my enternet exployer to monitor well i was going to report but they already wiped there activite from my personal e-mail i got all the software and firewalls and virus killers etc,etc, defraged scaned changed passwords but and removed old software but i still have this stupid window pop up about a networm-i.virus [ at ] fp and something about  files and i'm getting these ad's to by software but there comeing from the same host but my new software says my computer is free from infection?can u help resolve this and help me report or catch this s.o.b. thanks Jay

Well it seems as if, your machine is still infected!

You can go to the Malware cleaning section of the Comodo Anti virus and put a post there and we'll help you there to get rid of this.

thanks
Melih
Logged

mal233
Newbie
*
Offline Offline

Posts: 2


« Reply #3 on: March 17, 2007, 10:12:35 AM »

Melih,

I have the logmein.com problem as well. I will attach the log file to see if that helps you fix this problem. AVG 7.1 and 7.5 do not ID these files as a virus.  They are two updates to best of my knowledge. Hope this helps.

Mark
Logged
kishork
Guest
« Reply #4 on: March 20, 2007, 12:07:19 AM »

Hi Mark,
These detected files are have capability of remote administration and hence these are detected. Other AVs are also detecting it. You can varify it by scanning the file from virustotal (virustotal.com)

If you want to use these files, you can exclude them from scanning

To exclude files/folders from scanning, do the followings
1.Go to main window->Settings->On Demand->Advanced->What items to exclude->Select. Then selects files/folders to exclude from scanning.
2.Go to main window->Settings->On Access->Advanced->What items to exclude->Select. Then selects files/folders to exclude from scanning.


Thanks & regards
Kishor
Logged
LeoniAquila
Über Minimalist™ Defender of Resources Bloatware Fighter
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2884


Diesel in my veins


« Reply #5 on: March 23, 2007, 06:38:42 PM »

Thank you for this opportunity!

I would like to ask about rootkits, which I think are some very small programs hiding deep down in the system. But I don't know what they are capable of. Are these threats serious? Does Comodo (Firewall or AV perhaps) prevent from rootkits?

As I heard of a free anti-rootkit called Sophos Anti-Rootkit 1.2, I tried it and it has now searched through my system (XP with CPF and avast). Now I'm a bit concerned because it actually found a non-removable, hidden registry key: \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\d347prt\Cfg\0Jf40
Do you have any idea at all what this is about? My only idea is that I've used the Neowin UXTheme patch to open up for other Windows themes than just the original Microsoft theme "Luna". The patch makes changes to Windows system files, maybe this is the reason?  Huh
Logged

» User of Windows XP Home Edition SP3 on Acer Aspire
» Slave of COMODO Firewall Pro 3.0
Soyabeaner
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6621


Akagi


« Reply #6 on: March 23, 2007, 07:14:50 PM »

I'm not an expert, so ignore this post if you don't mind. Tongue

I would like to ask about rootkits, which I think are some very small programs hiding deep down in the system. But I don't know what they are capable of. Are these threats serious? Does Comodo (Firewall or AV perhaps) prevent from rootkits?
Destructive?  Potentially.  Look at the Sony deal.  CFP 3 will prevent it because of HIPS.  CAV currently should because it already has HIPS.

\HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\d347prt\Cfg\0Jf40
Do you have any idea at all what this is about? My only idea is that I've used the Neowin UXTheme patch to open up for other Windows themes than just the original Microsoft theme "Luna". The patch makes changes to Windows system files, maybe this is the reason?  Huh
I also used Neowin patch for extended Windows themes, but I don't have this registry key (or maybe it's not visible with regedit.exe?).  I discovered that it's Daemon tools / Alcohol120%, so you're off the "hook" lol.

Remember that with any security scanner there could be false positives.  As with anti-rootkits, they could detect legitimate rootkits / hooks as well, so watch out for that.
« Last Edit: March 23, 2007, 07:19:30 PM by Soya » Logged
LeoniAquila
Über Minimalist™ Defender of Resources Bloatware Fighter
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2884


Diesel in my veins


« Reply #7 on: March 24, 2007, 07:07:46 AM »

Thank you Soya for your answer. I've read something about the Sony stuff, will check it further!

You're right about DAEMON Tools, because this has been confirmed in another forum where I posted a message yesterday. And it should be harmless.

Now, more rootkits: After my message here yesterday, I scanned with Spybot. It only found some logs, of which one belonged to Media Player Classic from Gabest. I removed this, and "just for fun" I made another scan with Sophos Anti-Rootkit, which actually listed another rootkit that referred to this Gabest thing. Quite strange I think, but I suppose it's harmless too.

By the way, isn't the Neowin patch a very smart thing to make Windows look nicer? Smiley
Logged

» User of Windows XP Home Edition SP3 on Acer Aspire
» Slave of COMODO Firewall Pro 3.0
Soyabeaner
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6621


Akagi


« Reply #8 on: March 24, 2007, 07:18:45 AM »

Now, more rootkits: After my message here yesterday, I scanned with Spybot. It only found some logs, of which one belonged to Media Player Classic from Gabest. I removed this, and "just for fun" I made another scan with Sophos Anti-Rootkit, which actually listed another rootkit that referred to this Gabest thing. Quite strange I think, but I suppose it's harmless too.
I think it's more false positives than strange.  Don't rely on one anti-rootkit scanner.  Rootkits are the newest breed of malware, so it's better to try more anti-rootkits if you're so interested.  I also have MPC and Gabest is its developer Tongue.  You can also see associated files with MPC in CFP's Component Monitor.

By the way, isn't the Neowin patch a very smart thing to make Windows look nicer? Smiley
Hopefully it isn't the cause of other "unexplained" issues with CFP, but no doubt it's necessary to ease the eyes Shocked.  Why Windows would limit to just a few themes (that isn't even beautiful) is beyond me.
Logged
LeoniAquila
Über Minimalist™ Defender of Resources Bloatware Fighter
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2884


Diesel in my veins


« Reply #9 on: March 24, 2007, 10:55:28 AM »

Ok, good to know that there is protection available Smiley

As for Windows styles and CPF problems, there is at least one issue: when resizing the title bar (well, you don't even need any patch to do this!), the UI title bar of CPF becomes black and the three buttons on the right disappears (but the functionality of the buttons remains). When maximizing the window, the title bar becomes transparent instead! However it becomes normal if you reboot (still with the new title bar size). Really not a big issue, but I've posted a ticket to Comodo anyway, which they have responded to. They will try to solve it for CPF version 3. Perhaps you have noticed this too, since you obviously change themes (and thereby probably also title bar size)?

/L
Logged

» User of Windows XP Home Edition SP3 on Acer Aspire
» Slave of COMODO Firewall Pro 3.0
Soyabeaner
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6621


Akagi


« Reply #10 on: March 24, 2007, 11:13:55 AM »

You're about the 5th user to report this, with myself included.

You did know that rebooting isn't necessary, didn't you?  Just open Task Manager and end explorer.exe.  Then go to File > New Task (Run...) > enter explorer.exe (in some environments the .exe extension isn't even needed when running known Windows commands).  This is definitely a faster procedure because some programs are still running.
Logged
LeoniAquila
Über Minimalist™ Defender of Resources Bloatware Fighter
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2884


Diesel in my veins


« Reply #11 on: March 25, 2007, 03:51:24 AM »

I don't reboot anymore, the issue isn't serious enough I think! Just restarting Explorer seems like a simple method, I havn't tried it though.

/L
Logged

» User of Windows XP Home Edition SP3 on Acer Aspire
» Slave of COMODO Firewall Pro 3.0
jhunjhun
Newbie
*
Offline Offline

Posts: 4


« Reply #12 on: April 08, 2007, 03:27:33 AM »

Hi , I'm just new to COMODO. I just installed  COMODO firewall the other day. I quite feel safe and confident surfing the internet. And I really thank COMODO for this. As I study the different function of this software, under Activity>>>Log, there is a lot and continues of traffic going on. And the description said Inbound Policy Violation, Access Denied(UDP or IGMP). Most of the source come from nbdgram and some are nbname. I just want to know if this thing is normal.. Hoping for any answer.

Thank you,
Jhun

Logged
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5163


... and I say to myself, "What a wonderful world"


« Reply #13 on: April 08, 2007, 07:01:44 AM »

nbdgram and nbname are caused by Windows peer-to-peer networking. It's caused when a LAN workstation startsup and advertises its name and details across the LAN.

Providing you want to join the LAN, you 'll need to run the "add a trusted network" wizard (under SECURITY - TASKS). This will automatically create rules that allow LAN based comms to occur and your error messages will disappear.

Cheers,
Ewen :-)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
arjunpa
Comodo Family Member
***
Offline Offline

Posts: 63


Iam Cool


« Reply #14 on: April 10, 2007, 04:02:02 AM »

I like to know whether i can uninstall comodo antivirus beta 2 properly?
Logged
Tags:
Pages: [1] 2 3 ... 5 Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.476 seconds with 19 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com