Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 12, 2008, 01:42:37 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
199671
Posts
22924
Topics
55009
Members
Latest Member:
vic6
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo BOClean Anti-Malware
Why use Boclean?
« previous
next »
Pages:
[
1
]
Author
Topic: Why use Boclean? (Read 2278 times)
LOFYmOkr
Newbie
Offline
Posts: 4
Why use Boclean?
«
on:
May 11, 2008, 10:40:33 PM »
I've been using boclean a couple of years. I've used kevin's software many years. Boclean seems to do nothing for me. I used the setup instructions as listed on the setup page. I've had several trojans (or what ZA Suite says are trojans. Boclean seems to sit in the traybar quietly blinking and has never found anything. It has never asked me about anything so i don't know if it works. I had one trojan (a keylogger) that ZA found so I went to the forum and the response was it was a commercial release so Boclean didn't cover it. Someone put a keylogger on my machine (!) and boclean decides I don't need to know? Do I have something set wrong? Am I not suppose to get some type of warnng at some point with Boclean?
I can't figure out what it's suppose to be doing. ZA is the only thing working?
Logged
SiberLynx
Comodo's Hero
Offline
Posts: 221
Re: Why use Boclean?
«
Reply #1 on:
May 12, 2008, 07:39:39 AM »
Quote from: LOFYmOkr on May 11, 2008, 10:40:33 PM
....I've had several trojans (or what ZA Suite says are trojans....
Hi LOFYmOkr,
Are you sure that those "trojans" were real "wooden horses" of just FPs by ZA?
and then I hope you don't believe in all ZA tells you... - it is not the best one (my personal opinion).
at least don't remove straight away all those declared infected by ZA be careful
Actually when BOClean is silent it is good sign.
When
rarely
something was not detect or detected but turned to be FP...well it happens to any security SW.
And finally is you want to "hear" from BOClean... just ran known and new tests from time to time.
My regards
«
Last Edit: May 12, 2008, 07:45:49 AM by SiberLynx
»
Logged
XP Pro, SP3; CFP v3, Defense+; CMF; BOClean; VE (currently out of order :-(
Kevin McAleavey
Administrator
Comodo's Hero
Offline
Posts: 313
Snag a nasty? NO problem! =)
Re: Why use Boclean?
«
Reply #2 on:
May 13, 2008, 05:56:51 AM »
Quote from: LOFYmOkr on May 11, 2008, 10:40:33 PM
I've been using boclean a couple of years. I've used kevin's software many years. Boclean seems to do nothing for me. I used the setup instructions as listed on the setup page. I've had several trojans (or what ZA Suite says are trojans. Boclean seems to sit in the traybar quietly blinking and has never found anything. It has never asked me about anything so i don't know if it works. I had one trojan (a keylogger) that ZA found so I went to the forum and the response was it was a commercial release so Boclean didn't cover it. Someone put a keylogger on my machine (!) and boclean decides I don't need to know? Do I have something set wrong? Am I not suppose to get some type of warnng at some point with Boclean?
I can't figure out what it's suppose to be doing. ZA is the only thing working?
Not so sure of what ZA's doing there ... there's only so many ways to do a kernel interrupt and intercept keystrokes before they're passed up the chain. Tell me a bit more about this, promised I'll be amused.
When my buddy Marcus was deep in it, we had a lot of great time together. I won't call FP here, but would like to hear a bit more in the details since pretty much every way of grabbing keystrokes from the kernel is well monitored. But if there's something I'm missing, I can certainly blame it on "old age." Heh.
Logged
"I reject your reality and substitute my own." - (Adam Savage, "MYTHBUSTERS" TV show)
LOFYmOkr
Newbie
Offline
Posts: 4
Re: Why use Boclean?
«
Reply #3 on:
May 14, 2008, 05:17:17 PM »
Hi guys,
Good to see I can still count on you guys for help!
Here is the last scan item from ZA Security Suite.
Decription Anti-spyware found one or more spyware packages
Date / Time 2008/05/02 15:43:44-4:00 GMT
Type Scan
Category Trojan
Name Win32.Trojan.Dropper.Agent.hl
Action Found
Mode Manual
I scan once a week for vir and troj. This is the second time in a few weeks ZA ran across something. The time before this I looked the item up on
this website
and it said that it was a commercial keylogger so was not included in Boclean protection. I didn't save the log file so can't give anymore info about that one. I had ZA delete both times and went on about my business. Then started wondering why Boclean never gave me information about either one in real time. That is the reason for the post. I never shut it down so was looking for more info about the program.
By the way, what is the best firewall software in your opinion? Not being a smart a**. I'd like to think I have the best protection I can.
Thanks
Logged
Rednose
Malware Research Group
Comodo's Hero
Offline
Posts: 1329
Ganda's sleepy ( in his wildest dreams )
Re: Why use Boclean?
«
Reply #4 on:
May 14, 2008, 08:36:33 PM »
Hi LOFYmOkr
Why use Boclean ? People who I recommand the little program to always ask me that, and the answer is very simple
Most malware executables today are packed or obfuscated, so that means they are very hard - or even not readable for virus scanners. But BOClean continuously scans the memory, and as soon the malware unveals it self BOClean jumps into action and kills it. That is why it is a great back up for any virus scanner
Greetz, Red.
Logged
XP 32x SP3 CFP 2.4 SSM 2.0 Free Avast! 4.8 Home CBOClean 4.27 CMF 2.0 SAS 4.21 Free MBAM 1.28
LeoniAquila
Über Minimalist™ Defender of Resources Bloatware Fighter
Global Moderator
Comodo's Hero
Offline
Posts: 3603
Leone & Aquila
Re: Why use Boclean?
«
Reply #5 on:
May 15, 2008, 04:22:05 AM »
Is there a simple way to explain the difference to a traditional AV? Why is the BOClean monitoring more accurate than the traditional monitoring? I thought AV monitoring was supposed to catch anything that revealed itself - just like BOClean is supposed to do.
Getting back to the original question, I guess one can say that BOClean is a great complement to AV software since not all programs can have all signatures. That's why I've recommended BOClean.
LA
Logged
» Windows XP Home Edition SP3 nLite
» COMODO Firewall Pro
Kevin McAleavey
Administrator
Comodo's Hero
Offline
Posts: 313
Snag a nasty? NO problem! =)
Re: Why use Boclean?
«
Reply #6 on:
May 15, 2008, 04:32:01 AM »
Quote from: LeoniAquila on May 15, 2008, 04:22:05 AM
Is there a simple way to explain the difference to a traditional AV? Why is the BOClean monitoring more accurate than the traditional monitoring? I thought AV monitoring was supposed to catch anything that revealed itself - just like BOClean is supposed to do.
Getting back to the original question, I guess one can say that BOClean is a great complement to AV software since not all programs can have all signatures. That's why I've recommended BOClean.
LA
Sorry that I'm a bit overloaded at the moment and don't have time for the nuances, but best way to explain it is that antiviruses are designed to work at the FILE level ... better antiviruses can examine files more deeply, have perhaps an "emulator" or other "heuristics" that may or may not help, but in the end EVERY AV (even ours) does its thing by stopping a file from loading, and then examining it in hopes of matching a signature of some sort TO that file before it is allowed to be loaded/run.
BOClean was always designed on a philosophy of "you already HAVE an antivirus" ... if the FILE wasn't detected as harmful, then BOClean will sit there like a bouncer inside the lobby and whatever gets past the front door is OURS. We do a MEMORY scan of a process which has already loaded and begun to execute. Once it's actually started up, all of those obfuscations at the file level are no longer in use since a computer can ONLY execute a valid program. And to BE valid, any obfuscations must be completely disarmed by the program to allow it to run. So BOClean goes in at THAT level and gives anything which runs a "second opinion." And yes, we also check associated files and connections after the fact as well ... in case the AV misses it. That was ALWAYS the purpose of BOClean, and why it's proven so useful for over ten years now.
Logged
"I reject your reality and substitute my own." - (Adam Savage, "MYTHBUSTERS" TV show)
LeoniAquila
Über Minimalist™ Defender of Resources Bloatware Fighter
Global Moderator
Comodo's Hero
Offline
Posts: 3603
Leone & Aquila
Re: Why use Boclean?
«
Reply #7 on:
May 15, 2008, 08:35:28 AM »
Thanks a lot Kevin, that's a summary even I can understand.
LA
Logged
» Windows XP Home Edition SP3 nLite
» COMODO Firewall Pro
Kevin McAleavey
Administrator
Comodo's Hero
Offline
Posts: 313
Snag a nasty? NO problem! =)
Re: Why use Boclean?
«
Reply #8 on:
May 16, 2008, 03:42:08 AM »
Quote from: LeoniAquila on May 15, 2008, 08:35:28 AM
Thanks a lot Kevin, that's a summary even I can understand.
LA
You're MOST welcome! That was easy! Heh.
But yeah, that was the basis of the original design, and surprised that after 10+ years now it's still needed.
Logged
"I reject your reality and substitute my own." - (Adam Savage, "MYTHBUSTERS" TV show)
Rednose
Malware Research Group
Comodo's Hero
Offline
Posts: 1329
Ganda's sleepy ( in his wildest dreams )
Re: Why use Boclean?
«
Reply #9 on:
May 17, 2008, 12:21:06 AM »
Kev, I am not surprised because I have seen the difference it made for peepz I recommended BOClean. Nowadays AV's are loosing the battle, and because HIPS solutions are not suitable for everyone, BOClean could make a difference
Greetz, Red
«
Last Edit: May 17, 2008, 12:24:57 AM by Rednose
»
Logged
XP 32x SP3 CFP 2.4 SSM 2.0 Free Avast! 4.8 Home CBOClean 4.27 CMF 2.0 SAS 4.21 Free MBAM 1.28
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.412 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com