Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 22, 2013, 10:27:22 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663567
Posts
70558
Topics
145215
Members
Latest Member:
d3v14n7
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
Help - CIS
AntiVirus Help - CIS
CIS misses some samples often, a reinstall fixes it
« previous
next »
Pages:
1
...
3
4
[
5
]
6
Author
Topic: CIS misses some samples often, a reinstall fixes it (Read 19862 times)
SivaSuresh
Star Group
Comodo's Hero
Online
Posts: 1336
Avert the danger that has not yet come
Re: CIS misses some samples often, a reinstall fixes it
«
Reply #60 on:
December 21, 2011, 01:16:26 AM »
I have made a new topic just explaining this. And, I have added a poll too to offer two check boxes separating executable and non executable archives scanning.
https://forums.comodo.com/wishlist-cis/separate-archive-scan-and-sfxruntime-packers-scans-t79672.0.html;msg571018#msg571018
Logged
with love
Siva Suresh
|| Windows8 x64 | CIS 6 | Waterfox | Comodo Dragon x86 | Thunderbird | CCleaner | Evernote | PStart | SuperCopier | Dropbox | TeamViewer | Screenshot Captor ||
|| AMD Phenom II x4 955B | ASUS M4A88TD | 8GB DDR3 RAM | 240GB Sandisk SSD || 3TB SATA II HDD 6Gb/s
naren
Comodo's Hero
Offline
Posts: 3860
Re: CIS misses some samples often, a reinstall fixes it
«
Reply #61 on:
December 21, 2011, 06:08:21 AM »
Quote from: SivaSuresh on December 20, 2011, 12:39:38 PM
I found the answer. All those detected files are actually self extracting archives/runtime packers as I can understand from the " | " symbol in the report. Since I disabled archive scanning in my CIS, they are not getting detected.
But, why are .exe files not scanned, if they are sfx files or runtime packers, they should not be excluded from from scanning when I uncheck "archive scanning".
I only want to exclude .zip, .rar, .7z etc from scanning as they are not executables and the scanning takes up too much of resources unnecessarily, but I certainly do not want to exclude .exe files (either SFX archives or runtime packers) from scanning.
May be we need a re thinking of this policy.
Anyway, thanks for the concern.
GR8 you found the answer.
Logged
SivaSuresh
Star Group
Comodo's Hero
Online
Posts: 1336
Avert the danger that has not yet come
Re: CIS misses some samples often, a reinstall fixes it
«
Reply #62 on:
February 12, 2012, 01:42:38 AM »
Hey guys... I am back with the same problem...
Two samples that I was trying to scan would show up as clean on my system, while when I scan them on Virustotal, Comodo detects them online. I tried to scan on another system (CIS 32 bit), they are detected.
I have not noticed any Def+ logs too... By the way I am using the latest CIS x64 build.
I will send the samples if anybody can test on another x64 system...
«
Last Edit: February 12, 2012, 01:45:37 AM by SivaSuresh
»
Logged
with love
Siva Suresh
|| Windows8 x64 | CIS 6 | Waterfox | Comodo Dragon x86 | Thunderbird | CCleaner | Evernote | PStart | SuperCopier | Dropbox | TeamViewer | Screenshot Captor ||
|| AMD Phenom II x4 955B | ASUS M4A88TD | 8GB DDR3 RAM | 240GB Sandisk SSD || 3TB SATA II HDD 6Gb/s
SivaSuresh
Star Group
Comodo's Hero
Online
Posts: 1336
Avert the danger that has not yet come
Re: CIS misses some samples often, a reinstall fixes it
«
Reply #63 on:
February 15, 2012, 01:38:38 AM »
Quote from: SivaSuresh on February 12, 2012, 01:42:38 AM
Hey guys... I am back with the same problem...
Two samples that I was trying to scan would show up as clean on my system, while when I scan them on Virustotal, Comodo detects them online. I tried to scan on another system (CIS 32 bit), they are detected.
I have not noticed any Def+ logs too... By the way I am using the latest CIS x64 build.
I will send the samples if anybody can test on another x64 system...
I have cleared all my "Trusted files" (A really long list indeed
) to get it to work. Anyway, after clearing the Trusted files list, the samples are now detected.
Again, I do not understand how these malware samples are getting in to trusted list every time (they are not signed surely). I thought this problem was solved in 5.9 release...
Logged
with love
Siva Suresh
|| Windows8 x64 | CIS 6 | Waterfox | Comodo Dragon x86 | Thunderbird | CCleaner | Evernote | PStart | SuperCopier | Dropbox | TeamViewer | Screenshot Captor ||
|| AMD Phenom II x4 955B | ASUS M4A88TD | 8GB DDR3 RAM | 240GB Sandisk SSD || 3TB SATA II HDD 6Gb/s
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13180
Volunteer Moderator
Re: CIS misses some samples often, a reinstall fixes it
«
Reply #64 on:
February 15, 2012, 04:23:12 AM »
Please drop Egemen a PM on this.
Do you have any idea with what 'tools/software' you have touched these files?
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
SivaSuresh
Star Group
Comodo's Hero
Online
Posts: 1336
Avert the danger that has not yet come
Re: CIS misses some samples often, a reinstall fixes it
«
Reply #65 on:
February 15, 2012, 04:40:30 AM »
Quote from: Ronny on February 15, 2012, 04:23:12 AM
Please drop Egemen a PM on this.
Do you have any idea with what 'tools/software' you have touched these files?
I have copied those samples from an external drive to my desktop. Besides, I have zipped them using 7zip and unzipped again too. so probably, explorer.exe and 7zfm.exe are the only two sw touching those files.
I think that both these are trusted.
I already waited for three days for someone to respond, but, Since now I cleared my trusted files list, I have to wait the issue reoccurs, so that I call EGEMEN for direct help.
Logged
with love
Siva Suresh
|| Windows8 x64 | CIS 6 | Waterfox | Comodo Dragon x86 | Thunderbird | CCleaner | Evernote | PStart | SuperCopier | Dropbox | TeamViewer | Screenshot Captor ||
|| AMD Phenom II x4 955B | ASUS M4A88TD | 8GB DDR3 RAM | 240GB Sandisk SSD || 3TB SATA II HDD 6Gb/s
naren
Comodo's Hero
Offline
Posts: 3860
Re: CIS misses some samples often, a reinstall fixes it
«
Reply #66 on:
February 15, 2012, 04:50:31 AM »
Siva,
The samples are detected on 32 bits but not on 64 bits, right?
The samples are not detected on 64 bits with both manual & realtime?
Send me the samples I will try it on 64 bits later & post here the results.
I will try on win 7 64.
What 64 bits you are on?
And do you mean while extracting those samples they get into trusted files?
Logged
SivaSuresh
Star Group
Comodo's Hero
Online
Posts: 1336
Avert the danger that has not yet come
Re: CIS misses some samples often, a reinstall fixes it
«
Reply #67 on:
February 15, 2012, 04:58:13 AM »
Quote from: naren on February 15, 2012, 04:50:31 AM
Siva,
The samples are detected on 32 bits but not on 64 bits, right?
The samples are not detected on 64 bits with both manual & realtime?
Send me the samples I will try it on 64 bits later & post here the results.
I will try on win 7 64.
What 64 bits you are on?
And do you mean while extracting those samples they get into trusted files?
I am using Win7 x64.
I do not know when and how they are added to "Trusted files" list, I am investigating in to it.
Logged
with love
Siva Suresh
|| Windows8 x64 | CIS 6 | Waterfox | Comodo Dragon x86 | Thunderbird | CCleaner | Evernote | PStart | SuperCopier | Dropbox | TeamViewer | Screenshot Captor ||
|| AMD Phenom II x4 955B | ASUS M4A88TD | 8GB DDR3 RAM | 240GB Sandisk SSD || 3TB SATA II HDD 6Gb/s
naren
Comodo's Hero
Offline
Posts: 3860
Re: CIS misses some samples often, a reinstall fixes it
«
Reply #68 on:
February 15, 2012, 05:01:53 AM »
Quote from: SivaSuresh on February 15, 2012, 04:58:13 AM
I am using Win7 x64.
I do not know when and how they are added to "Trusted files" list, I am investigating in to it.
So they are added to trusted lists somehow, right?
Logged
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 16695
Re: CIS misses some samples often, a reinstall fixes it
«
Reply #69 on:
February 19, 2012, 11:44:26 AM »
May be malware gets installed by a trusted installer and will then end up in the TSV list.
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
SivaSuresh
Star Group
Comodo's Hero
Online
Posts: 1336
Avert the danger that has not yet come
Re: CIS misses some samples often, a reinstall fixes it
«
Reply #70 on:
February 21, 2012, 12:35:31 AM »
Quote from: EricJH on February 19, 2012, 11:44:26 AM
May be malware gets installed by a trusted installer and will then end up in the TSV list.
They are not installed, they are not in memory.
When ever I encounter a suspicious file in any of my friends computers, I will copy those samples and keep them in a folder on my desktop for verification and confirmation. So, if any thing happens, it must happen during copy process or in zip/unzip process only.
Logged
with love
Siva Suresh
|| Windows8 x64 | CIS 6 | Waterfox | Comodo Dragon x86 | Thunderbird | CCleaner | Evernote | PStart | SuperCopier | Dropbox | TeamViewer | Screenshot Captor ||
|| AMD Phenom II x4 955B | ASUS M4A88TD | 8GB DDR3 RAM | 240GB Sandisk SSD || 3TB SATA II HDD 6Gb/s
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 16695
Re: CIS misses some samples often, a reinstall fixes it
«
Reply #71 on:
February 21, 2012, 01:17:24 PM »
Quote from: SivaSuresh on February 21, 2012, 12:35:31 AM
They are not installed, they are not in memory.
When ever I encounter a suspicious file in any of my friends computers, I will copy those samples and keep them in a folder on my desktop for verification and confirmation. So, if any thing happens, it must happen during copy process or in zip/unzip process only.
Can you try the following. Remove one of thes file from the Trusted Files list then see if copying and/or zipping/unzipping it gets it on the list reproducibly.
Do you happen to have given your zip program the Installer/Updater policy?
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
SivaSuresh
Star Group
Comodo's Hero
Online
Posts: 1336
Avert the danger that has not yet come
Re: CIS misses some samples often, a reinstall fixes it
«
Reply #72 on:
February 21, 2012, 01:27:18 PM »
Quote from: EricJH on February 21, 2012, 01:17:24 PM
Can you try the following. Remove one of thes file from the Trusted Files list then see if copying and/or zipping/unzipping it gets it on the list reproducibly.
Do you happen to have given your zip program the Installer/Updater policy?
No program is added as Installer/Updater by me, no program other than those greyed defaults are there in the list too.
I tried to reproduce it after clearing the Trusted files list, but had no success. When ever I copy or unzip the files, they are detected by CAV scan now, although not always by Real time scanner (I don't know why ?)
Logged
with love
Siva Suresh
|| Windows8 x64 | CIS 6 | Waterfox | Comodo Dragon x86 | Thunderbird | CCleaner | Evernote | PStart | SuperCopier | Dropbox | TeamViewer | Screenshot Captor ||
|| AMD Phenom II x4 955B | ASUS M4A88TD | 8GB DDR3 RAM | 240GB Sandisk SSD || 3TB SATA II HDD 6Gb/s
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13180
Volunteer Moderator
Re: CIS misses some samples often, a reinstall fixes it
«
Reply #73 on:
February 22, 2012, 01:52:57 PM »
Quote from: SivaSuresh on February 21, 2012, 01:27:18 PM
, although not always by Real time scanner (I don't know why ?)
Those are probably packed, if the .exe extracts and tries to write the real malware .exe to disk real-time should kick-in.
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
SivaSuresh
Star Group
Comodo's Hero
Online
Posts: 1336
Avert the danger that has not yet come
Re: CIS misses some samples often, a reinstall fixes it
«
Reply #74 on:
February 23, 2012, 12:06:24 PM »
Quote from: Ronny on February 22, 2012, 01:52:57 PM
Those are probably packed, if the .exe extracts and tries to write the real malware .exe to disk real-time should kick-in.
I do not think so...
Since, they are sometimes detected as soon as they are extracted, sometimes only detected during a manual scan.
Logged
with love
Siva Suresh
|| Windows8 x64 | CIS 6 | Waterfox | Comodo Dragon x86 | Thunderbird | CCleaner | Evernote | PStart | SuperCopier | Dropbox | TeamViewer | Screenshot Captor ||
|| AMD Phenom II x4 955B | ASUS M4A88TD | 8GB DDR3 RAM | 240GB Sandisk SSD || 3TB SATA II HDD 6Gb/s
Tags:
CIS misses samples
bases.cav corrupt
Pages:
1
...
3
4
[
5
]
6
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.07 seconds with 22 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com