Welcome, Guest. Please login or register.
September 06, 2008, 02:07:13 PM

Login with username, password and session length

189110 Posts
22036 Topics
52847 Members

Latest Member: amwdrive

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Anti Virus/Malware Products/Other Security products
| | |-+  Superantispyware incorrectly reported as modifying memory ?
« previous next »
Pages: [1] Go Down Print
Author Topic: Superantispyware incorrectly reported as modifying memory ?  (Read 929 times)
poutnik
Newbie
*
Offline Offline

Posts: 22


« on: March 12, 2008, 01:34:49 AM »

SAS 4.0.1154 is reported by comodo 2.4 FW ( w2ksp4 ) as modifying other processes memory.

Just recently I have abandoned my loved Kerio Personal firewall 2.1.5  and tried on w2k comodo pro 2.4.
When I have launched SAS free to make quick scan as background task,
comodo soon realized something strange :



SAS was said to be modifying processes in momory. at picture it was maxthon.exe like my favorite browser frontend. It was later detected on explorer.exe and services.exe.

during comparative scan by ad-aware 2007, comodo did not report anything about ad-aware, scaniing processes too, but SAS was reported as changing memory of aawservice.

on SAS forum site I was told they just scan memory ( that is obvious to do)
and that CPF 2.4 is misreporting this. )

Links to superantispyware forum]

Where is the truth ?
« Last Edit: March 12, 2008, 05:17:42 AM by poutnik » Logged

C2D E4700 / Gigabyte G33 chipset / 2 GB / Vista Premium 64 SP1 / CPW 3 / Avast 4.8 Home / FireFox 2 - NoScript - Ad Block Plus
Matty_R
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 952


Nice to see you,to see you nice!


« Reply #1 on: March 12, 2008, 06:50:26 AM »

Hi Poutnik,i think here Comodo is doing its job as it should,did you have your browser open during the scan as for SAS to do its scan it must access/look at what is running in Memory,therefore it is taken that it is modifying  the memory by Comodo because unless Comodo knows to expect this it will warn you as it would for any rogue app.

So i dont think its doing any misreporting/to scan the memory it must modify it.

Cheers Matty
Logged

KYLE`S ALLRIGHT Smiley I love Aussies
CCleaner - Freeware Windows Optimization
poutnik
Newbie
*
Offline Offline

Posts: 22


« Reply #2 on: March 12, 2008, 07:14:26 AM »

So, could it be, that

Ad-Aware 2007 is for comodo 2.4 known trusted application, not to be reported ?
Because Ad-aware makes process can too.

SAS 4.x is far younger than CPF 2.4 and younger than ADAware,
so it can be suspicious for CPF 2.4.

does it make sense ?
Or things are even different ?

Logged

C2D E4700 / Gigabyte G33 chipset / 2 GB / Vista Premium 64 SP1 / CPW 3 / Avast 4.8 Home / FireFox 2 - NoScript - Ad Block Plus
Matty_R
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 952


Nice to see you,to see you nice!


« Reply #3 on: March 12, 2008, 10:16:34 AM »

Sorry poutnik just took a closer look at your pic,could it be SAS using your browser to check for an update?

Matty
Logged

KYLE`S ALLRIGHT Smiley I love Aussies
CCleaner - Freeware Windows Optimization
poutnik
Newbie
*
Offline Offline

Posts: 22


« Reply #4 on: March 12, 2008, 10:39:37 AM »

I suppose it could, maxthon is my default.
But what other mentioned processes ?
E.g:  I do not suppose SAS would use for update aawservice  ( service part of Ad-Aware 2007 )
Logged

C2D E4700 / Gigabyte G33 chipset / 2 GB / Vista Premium 64 SP1 / CPW 3 / Avast 4.8 Home / FireFox 2 - NoScript - Ad Block Plus
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.317 seconds with 18 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com