Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
June 19, 2013, 02:25:37 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
669004
Posts
71135
Topics
145744
Members
Latest Member:
Csicsó
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
AV False Positive/Negative Detection Reporting
Comodo doesn't stop S.M.A.R.T. Check & worse - DELETES SYSTEM FILES!!!!
« previous
next »
Pages:
[
1
]
Author
Topic: Comodo doesn't stop S.M.A.R.T. Check & worse - DELETES SYSTEM FILES!!!! (Read 3020 times)
permutations
Newbie
Offline
Posts: 1
Comodo doesn't stop S.M.A.R.T. Check & worse - DELETES SYSTEM FILES!!!!
«
on:
June 01, 2012, 05:18:06 PM »
The S.M.A.R.T. Check virus - very, very, vicious - is NOT stopped by Comodo. It's on my main computer now, I'm writing from another computer. This virus moves essential system files to the TEMP folder. When the virus started doing this, Comodo alerted me to viruses in the TEMP folder and advised me to delete these files WHICH I DID, so I'm totally screwed.
Comodo, you MUST fix this huge gap in your anti-virus program. I currently HATE you.
I've been trying to get this off my computer for hours now. It involves a rootkit, I can't boot into Safe Mode. It's a catastrophe.
http://www.bleepingcomputer.com/virus-removal/remove-smart-hdd
Logged
languy99
Global Moderator
Comodo's Hero
Online
Posts: 3943
Re: Comodo doesn't stop S.M.A.R.T. Check & worse - DELETES SYSTEM FILES!!!!
«
Reply #1 on:
June 01, 2012, 05:55:20 PM »
please provide me a sample for testing so that I can verify your claims.
Logged
http://www.youtube.com/languy99
Software Reviews for all.
Follow me on Twitter
http://twitter.com/#!/languy99
Seany007
Comodo's Hero
Offline
Posts: 1918
Comodo Commando
Re: Comodo doesn't stop S.M.A.R.T. Check & worse - DELETES SYSTEM FILES!!!!
«
Reply #2 on:
June 02, 2012, 07:11:05 AM »
Quote from: permutations on June 01, 2012, 05:18:06 PM
The S.M.A.R.T. Check virus - very, very, vicious - is NOT stopped by Comodo. It's on my main computer now, I'm writing from another computer. This virus moves essential system files to the TEMP folder. When the virus started doing this, Comodo alerted me to viruses in the TEMP folder and advised me to delete these files WHICH I DID, so I'm totally screwed.
Comodo, you MUST fix this huge gap in your anti-virus program. I currently HATE you.
I've been trying to get this off my computer for hours now. It involves a rootkit, I can't boot into Safe Mode. It's a catastrophe.
http://www.bleepingcomputer.com/virus-removal/remove-smart-hdd
LOL! If Comodo fails to stop it all other AV's will do much worse. What sites you visit to get infected with this?
Logged
Proud Comodo User (CIS, CD, CID and CMS)
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 16991
Re: Comodo doesn't stop S.M.A.R.T. Check & worse - DELETES SYSTEM FILES!!!!
«
Reply #3 on:
June 02, 2012, 12:10:08 PM »
Quote from: Seany007 on June 02, 2012, 07:11:05 AM
LOL! If Comodo fails to stop it all other AV's will do much worse.
Hoping topic starter can provide us with a sample so we can see how it is capable of bypassing or not.
Quote
What sites you visit to get infected with this?
That's not relevant if not a derogatory comment. Notice that infections also happen from compromised sites with no malicious intent. Since big corporation's sites are better protected hackers are now opting for compromising sites of small and medium sized businesses.
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
Seany007
Comodo's Hero
Offline
Posts: 1918
Comodo Commando
Re: Comodo doesn't stop S.M.A.R.T. Check & worse - DELETES SYSTEM FILES!!!!
«
Reply #4 on:
June 02, 2012, 04:46:36 PM »
Quote from: EricJH on June 02, 2012, 12:10:08 PM
Hoping topic starter can provide us with a sample so we can see how it is capable of bypassing or not.That's not relevant if not a derogatory comment. Notice that infections also happen from compromised sites with no malicious intent. Since big corporation's sites are better protected hackers are now opting for compromising sites of small and medium sized businesses.
Indeed. No I wanted to know the site! So I can block it! It is very relevant to me!
«
Last Edit: June 02, 2012, 04:58:25 PM by Seany007
»
Logged
Proud Comodo User (CIS, CD, CID and CMS)
Chiron
Global Moderator
Comodo's Hero
Offline
Posts: 5778
Re: Comodo doesn't stop S.M.A.R.T. Check & worse - DELETES SYSTEM FILES!!!!
«
Reply #5 on:
June 02, 2012, 05:01:07 PM »
If someone does find a sample I'd like it too.
Thanks.
Logged
How To Install Comodo Firewall
How To Stay Safe While Online
NSG001
Comodo's Hero
Offline
Posts: 371
malware .exe cutioner
Re: Comodo doesn't stop S.M.A.R.T. Check & worse - DELETES SYSTEM FILES!!!!
«
Reply #6 on:
June 03, 2012, 04:16:56 AM »
Quote from: Chiron on June 02, 2012, 05:01:07 PM
If someone does find a sample I'd like it too.
Thanks.
Chiron / Languy99 link sent via PM.
«
Last Edit: June 03, 2012, 04:53:07 AM by NSG001
»
Logged
languy99
Global Moderator
Comodo's Hero
Online
Posts: 3943
Re: Comodo doesn't stop S.M.A.R.T. Check & worse - DELETES SYSTEM FILES!!!!
«
Reply #7 on:
June 03, 2012, 08:27:41 AM »
thanks,
Ok initial analysis. AV detects it. I disable the av and cloud functions.
Second thing you see is that D+ heuristics identifies the threat. see first pic.
I select sandbox. Program fails to install. Reboot and all is clear. Verified with MBAM
The only way this bypasses CIS is if you select allow or have changed the settings in such a way that it was able to bypass. I I changed was the firewall setting so that it would ask me and turned off the cloud functions/AV.
dr..png
(33.62 KB, 391x458 - viewed 30 times.)
Logged
http://www.youtube.com/languy99
Software Reviews for all.
Follow me on Twitter
http://twitter.com/#!/languy99
Siketa
Comodo's Hero
Online
Posts: 3289
ZIG ZAG
Re: Comodo doesn't stop S.M.A.R.T. Check & worse - DELETES SYSTEM FILES!!!!
«
Reply #8 on:
June 03, 2012, 01:12:28 PM »
Good job, languy!
I had no doubts about CIS....
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.048 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com