Welcome, Guest. Please login or register.
Did you miss your activation email?
May 22, 2013, 10:27:22 AM

Login with username, password and session length

663567 Posts
70558 Topics
145215 Members

Latest Member: d3v14n7

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  Help - CIS
| | | |-+  AntiVirus Help - CIS
| | | | |-+  CIS misses some samples often, a reinstall fixes it
« previous next »
Pages: 1 ... 3 4 [5] 6 Go Down Print
Author Topic: CIS misses some samples often, a reinstall fixes it  (Read 19862 times)
SivaSuresh
Star Group
Comodo's Hero
*****
Online Online

Posts: 1336


Avert the danger that has not yet come


« Reply #60 on: December 21, 2011, 01:16:26 AM »

I have made a new topic just explaining this. And, I have added a poll too to offer two check boxes separating executable and non executable archives scanning.

https://forums.comodo.com/wishlist-cis/separate-archive-scan-and-sfxruntime-packers-scans-t79672.0.html;msg571018#msg571018
Logged

with love Siva Suresh
|| Windows8 x64 | CIS 6 | Waterfox | Comodo Dragon x86 | Thunderbird | CCleaner | Evernote | PStart | SuperCopier | Dropbox | TeamViewer | Screenshot Captor ||
|| AMD Phenom II x4 955B | ASUS M4A88TD | 8GB DDR3 RAM | 240GB Sandisk SSD  || 3TB SATA II HDD 6Gb/s
naren
Comodo's Hero
*****
Offline Offline

Posts: 3860


« Reply #61 on: December 21, 2011, 06:08:21 AM »

I found the answer. All those detected files are actually self extracting archives/runtime packers as I can understand from the " | " symbol in the report. Since I disabled archive scanning in my CIS, they are not getting detected.

But, why are .exe files not scanned, if they are sfx files or runtime packers, they should not be excluded from from scanning when I uncheck "archive scanning".

I only want to exclude .zip, .rar, .7z etc from scanning as they are not executables and the scanning takes up too much of resources unnecessarily, but I certainly do not want to exclude .exe files (either SFX archives or runtime packers) from scanning.

May be we need a re thinking of this policy.

Anyway, thanks for the concern.



GR8 you found the answer.
Logged
SivaSuresh
Star Group
Comodo's Hero
*****
Online Online

Posts: 1336


Avert the danger that has not yet come


« Reply #62 on: February 12, 2012, 01:42:38 AM »

Hey guys... I am back with the same problem...

Two samples that I was trying to scan would show up as clean on my system, while when I scan them on Virustotal, Comodo detects them online. I tried to scan on another system (CIS 32 bit), they are detected.

I have not noticed any Def+ logs too... By the way I am using the latest CIS x64 build.

I will send the samples if anybody can test on another x64 system...

« Last Edit: February 12, 2012, 01:45:37 AM by SivaSuresh » Logged

with love Siva Suresh
|| Windows8 x64 | CIS 6 | Waterfox | Comodo Dragon x86 | Thunderbird | CCleaner | Evernote | PStart | SuperCopier | Dropbox | TeamViewer | Screenshot Captor ||
|| AMD Phenom II x4 955B | ASUS M4A88TD | 8GB DDR3 RAM | 240GB Sandisk SSD  || 3TB SATA II HDD 6Gb/s
SivaSuresh
Star Group
Comodo's Hero
*****
Online Online

Posts: 1336


Avert the danger that has not yet come


« Reply #63 on: February 15, 2012, 01:38:38 AM »

Hey guys... I am back with the same problem...

Two samples that I was trying to scan would show up as clean on my system, while when I scan them on Virustotal, Comodo detects them online. I tried to scan on another system (CIS 32 bit), they are detected.

I have not noticed any Def+ logs too... By the way I am using the latest CIS x64 build.

I will send the samples if anybody can test on another x64 system...



I have cleared all my "Trusted files" (A really long list indeed Sad Embarrassed Cry Cry Cry ) to get it to work. Anyway, after clearing the Trusted files list, the samples are now detected.

Again, I do not understand how these malware samples are getting in to trusted list every time (they are not signed surely). I thought this problem was solved in 5.9 release... Sad
Logged

with love Siva Suresh
|| Windows8 x64 | CIS 6 | Waterfox | Comodo Dragon x86 | Thunderbird | CCleaner | Evernote | PStart | SuperCopier | Dropbox | TeamViewer | Screenshot Captor ||
|| AMD Phenom II x4 955B | ASUS M4A88TD | 8GB DDR3 RAM | 240GB Sandisk SSD  || 3TB SATA II HDD 6Gb/s
Ronny
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 13180


Volunteer Moderator


« Reply #64 on: February 15, 2012, 04:23:12 AM »

Please drop Egemen a PM on this.
Do you have any idea with what 'tools/software' you have touched these files?
Logged

Volunteer Moderator
Any concerns? Please send me a PM or review the Forum Policy -  update Jan 3rd 2013!
SivaSuresh
Star Group
Comodo's Hero
*****
Online Online

Posts: 1336


Avert the danger that has not yet come


« Reply #65 on: February 15, 2012, 04:40:30 AM »

Please drop Egemen a PM on this.
Do you have any idea with what 'tools/software' you have touched these files?

I have copied those samples from an external drive to my desktop. Besides, I have zipped them using 7zip and unzipped again too. so probably, explorer.exe and 7zfm.exe are the only two sw touching those files.

I think that both these are trusted.

I already waited for three days for someone to respond, but, Since now I cleared my trusted files list, I have to wait the issue reoccurs, so that I call EGEMEN for direct help.
Logged

with love Siva Suresh
|| Windows8 x64 | CIS 6 | Waterfox | Comodo Dragon x86 | Thunderbird | CCleaner | Evernote | PStart | SuperCopier | Dropbox | TeamViewer | Screenshot Captor ||
|| AMD Phenom II x4 955B | ASUS M4A88TD | 8GB DDR3 RAM | 240GB Sandisk SSD  || 3TB SATA II HDD 6Gb/s
naren
Comodo's Hero
*****
Offline Offline

Posts: 3860


« Reply #66 on: February 15, 2012, 04:50:31 AM »

Siva,

The samples are detected on 32 bits but not on 64 bits, right?

The samples are not detected on 64 bits with both manual & realtime?

Send me the samples I will try it on 64 bits later & post here the results.

I will try on win 7 64.

What 64 bits you are on?

And do you mean while extracting those samples they get into trusted files?
Logged
SivaSuresh
Star Group
Comodo's Hero
*****
Online Online

Posts: 1336


Avert the danger that has not yet come


« Reply #67 on: February 15, 2012, 04:58:13 AM »

Siva,

The samples are detected on 32 bits but not on 64 bits, right?

The samples are not detected on 64 bits with both manual & realtime?

Send me the samples I will try it on 64 bits later & post here the results.

I will try on win 7 64.

What 64 bits you are on?

And do you mean while extracting those samples they get into trusted files?

I am using Win7 x64.
I do not know when and how they are added to "Trusted files" list, I am investigating in to it.
Logged

with love Siva Suresh
|| Windows8 x64 | CIS 6 | Waterfox | Comodo Dragon x86 | Thunderbird | CCleaner | Evernote | PStart | SuperCopier | Dropbox | TeamViewer | Screenshot Captor ||
|| AMD Phenom II x4 955B | ASUS M4A88TD | 8GB DDR3 RAM | 240GB Sandisk SSD  || 3TB SATA II HDD 6Gb/s
naren
Comodo's Hero
*****
Offline Offline

Posts: 3860


« Reply #68 on: February 15, 2012, 05:01:53 AM »

I am using Win7 x64.
I do not know when and how they are added to "Trusted files" list, I am investigating in to it.

So they are added to trusted lists somehow, right?
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 16695



« Reply #69 on: February 19, 2012, 11:44:26 AM »

May be malware gets installed by a trusted installer and will then end up in the TSV list.
Logged

SivaSuresh
Star Group
Comodo's Hero
*****
Online Online

Posts: 1336


Avert the danger that has not yet come


« Reply #70 on: February 21, 2012, 12:35:31 AM »

May be malware gets installed by a trusted installer and will then end up in the TSV list.

They are not installed, they are not in memory.

When ever I encounter a suspicious file in any of  my friends computers, I will copy those samples and keep them in a folder on my desktop for verification and confirmation. So, if any thing happens, it must happen during copy process or in zip/unzip process only.
Logged

with love Siva Suresh
|| Windows8 x64 | CIS 6 | Waterfox | Comodo Dragon x86 | Thunderbird | CCleaner | Evernote | PStart | SuperCopier | Dropbox | TeamViewer | Screenshot Captor ||
|| AMD Phenom II x4 955B | ASUS M4A88TD | 8GB DDR3 RAM | 240GB Sandisk SSD  || 3TB SATA II HDD 6Gb/s
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 16695



« Reply #71 on: February 21, 2012, 01:17:24 PM »

They are not installed, they are not in memory.

When ever I encounter a suspicious file in any of  my friends computers, I will copy those samples and keep them in a folder on my desktop for verification and confirmation. So, if any thing happens, it must happen during copy process or in zip/unzip process only.
Can you try the following. Remove one of thes file from the Trusted Files list then see if copying and/or zipping/unzipping it gets it on the list reproducibly.

Do you happen to have given your zip program the Installer/Updater policy?
Logged

SivaSuresh
Star Group
Comodo's Hero
*****
Online Online

Posts: 1336


Avert the danger that has not yet come


« Reply #72 on: February 21, 2012, 01:27:18 PM »

Can you try the following. Remove one of thes file from the Trusted Files list then see if copying and/or zipping/unzipping it gets it on the list reproducibly.

Do you happen to have given your zip program the Installer/Updater policy?

No program is added as Installer/Updater by me, no program other than those greyed defaults are there in the list too.

I tried to reproduce it after clearing the Trusted files list, but had no success. When ever I copy or unzip the files, they are detected by CAV scan now, although not always by Real time scanner (I don't know why ?)
Logged

with love Siva Suresh
|| Windows8 x64 | CIS 6 | Waterfox | Comodo Dragon x86 | Thunderbird | CCleaner | Evernote | PStart | SuperCopier | Dropbox | TeamViewer | Screenshot Captor ||
|| AMD Phenom II x4 955B | ASUS M4A88TD | 8GB DDR3 RAM | 240GB Sandisk SSD  || 3TB SATA II HDD 6Gb/s
Ronny
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 13180


Volunteer Moderator


« Reply #73 on: February 22, 2012, 01:52:57 PM »

, although not always by Real time scanner (I don't know why ?)
Those are probably packed, if the .exe extracts and tries to write the real malware .exe to disk real-time should kick-in.
Logged

Volunteer Moderator
Any concerns? Please send me a PM or review the Forum Policy -  update Jan 3rd 2013!
SivaSuresh
Star Group
Comodo's Hero
*****
Online Online

Posts: 1336


Avert the danger that has not yet come


« Reply #74 on: February 23, 2012, 12:06:24 PM »

Those are probably packed, if the .exe extracts and tries to write the real malware .exe to disk real-time should kick-in.
I do not think so...

Since, they are sometimes detected as soon as they are extracted, sometimes only detected during a manual scan.
Logged

with love Siva Suresh
|| Windows8 x64 | CIS 6 | Waterfox | Comodo Dragon x86 | Thunderbird | CCleaner | Evernote | PStart | SuperCopier | Dropbox | TeamViewer | Screenshot Captor ||
|| AMD Phenom II x4 955B | ASUS M4A88TD | 8GB DDR3 RAM | 240GB Sandisk SSD  || 3TB SATA II HDD 6Gb/s
Tags: CIS misses samples  bases.cav corrupt 
Pages: 1 ... 3 4 [5] 6 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.07 seconds with 22 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com