Welcome, Guest. Please login or register.
Did you miss your activation email?
May 21, 2013, 05:26:44 AM

Login with username, password and session length

663357 Posts
70523 Topics
145176 Members

Latest Member: jhon cena

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  AV False Positive/Negative Detection Reporting
| | | |-+  Comodo doesn't stop S.M.A.R.T. Check & worse - DELETES SYSTEM FILES!!!!
« previous next »
Pages: [1] Go Down Print
Author Topic: Comodo doesn't stop S.M.A.R.T. Check & worse - DELETES SYSTEM FILES!!!!  (Read 2919 times)
permutations
Newbie
*
Offline Offline

Posts: 1


« on: June 01, 2012, 05:18:06 PM »

The S.M.A.R.T. Check virus - very, very, vicious - is NOT stopped by Comodo. It's on my main computer now, I'm writing from another computer. This virus moves essential system files to the TEMP folder. When the virus started doing this, Comodo alerted me to viruses in the TEMP folder and advised me to delete these files WHICH I DID, so I'm totally screwed.

Comodo, you MUST fix this huge gap in your anti-virus program. I currently HATE you.

I've been trying to get this off my computer for hours now. It involves a rootkit, I can't boot into Safe Mode. It's a catastrophe.

http://www.bleepingcomputer.com/virus-removal/remove-smart-hdd
Logged
languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3943



« Reply #1 on: June 01, 2012, 05:55:20 PM »

please provide me a sample for testing so that I can verify your claims.
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
Seany007
Comodo's Hero
*****
Offline Offline

Posts: 1891


Comodo Commando


« Reply #2 on: June 02, 2012, 07:11:05 AM »

The S.M.A.R.T. Check virus - very, very, vicious - is NOT stopped by Comodo. It's on my main computer now, I'm writing from another computer. This virus moves essential system files to the TEMP folder. When the virus started doing this, Comodo alerted me to viruses in the TEMP folder and advised me to delete these files WHICH I DID, so I'm totally screwed.

Comodo, you MUST fix this huge gap in your anti-virus program. I currently HATE you.

I've been trying to get this off my computer for hours now. It involves a rootkit, I can't boot into Safe Mode. It's a catastrophe.

http://www.bleepingcomputer.com/virus-removal/remove-smart-hdd


LOL! If Comodo fails to stop it all other AV's will do much worse. What sites you visit to get infected with this?
Logged

Proud Comodo User (CIS, CD, CID and CMS)
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 16695



« Reply #3 on: June 02, 2012, 12:10:08 PM »

LOL! If Comodo fails to stop it all other AV's will do much worse.
Hoping topic starter can provide us with a sample so we can see how it is capable of bypassing or not.
Quote
What sites you visit to get infected with this?
That's not relevant if not a derogatory comment. Notice that infections also happen from compromised sites with no malicious intent. Since big corporation's sites are better protected hackers are now opting for compromising sites of small and medium sized businesses.
Logged

Seany007
Comodo's Hero
*****
Offline Offline

Posts: 1891


Comodo Commando


« Reply #4 on: June 02, 2012, 04:46:36 PM »

Hoping topic starter can provide us with a sample so we can see how it is capable of bypassing or not.That's not relevant if not a derogatory comment. Notice that infections also happen from compromised sites with no malicious intent. Since big corporation's sites are better protected hackers are now opting for compromising sites of small and medium sized businesses.

Indeed. No I wanted to know the site! So I can block it! It is very relevant to me!
« Last Edit: June 02, 2012, 04:58:25 PM by Seany007 » Logged

Proud Comodo User (CIS, CD, CID and CMS)
Chiron
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5570



« Reply #5 on: June 02, 2012, 05:01:07 PM »

If someone does find a sample I'd like it too.

Thanks.
Logged

NSG001
Comodo's Hero
*****
Offline Offline

Posts: 361


malware .exe cutioner


« Reply #6 on: June 03, 2012, 04:16:56 AM »

If someone does find a sample I'd like it too.

Thanks.

Chiron / Languy99 link sent via PM.
« Last Edit: June 03, 2012, 04:53:07 AM by NSG001 » Logged

languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3943



« Reply #7 on: June 03, 2012, 08:27:41 AM »

thanks,

Ok initial analysis. AV detects it. I disable the av and cloud functions.

Second thing you see is that D+ heuristics identifies the threat. see first pic.

I select sandbox. Program fails to install. Reboot and all is clear. Verified with MBAM

The only way this bypasses CIS is if you select allow or have changed the settings in such a way that it was able to bypass. I I changed was the firewall setting so that it would ask me and turned off the cloud functions/AV. 




* dr..png (33.62 KB, 391x458 - viewed 30 times.)
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
Siketa
Comodo's Hero
*****
Offline Offline

Posts: 3131


ZIG ZAG


« Reply #8 on: June 03, 2012, 01:12:28 PM »

Good job, languy!  Thumb Up
I had no doubts about CIS.... Wink
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.173 seconds with 22 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com