Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
July 04, 2009, 03:20:14 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
297707
Posts
32958
Topics
74914
Members
Latest Member:
f22
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archive Boards
Comodo BOClean Anti-Malware
will Comodo BOClean delete my pr0n ???
« previous
next »
Pages:
[
1
]
2
Author
Topic: will Comodo BOClean delete my pr0n ??? (Read 4442 times)
frazzled
Comodo Member
Offline
Posts: 48
will Comodo BOClean delete my pr0n ???
«
on:
April 22, 2007, 07:36:36 PM »
I installed this app cuz I heard it has a tray icon, and I LOVE tray icons (I collect them!)
Seriously, I'm a bit confused about the extent of "scanning" BOClean performs.
After closing the "config" screen, the resulting popup window mentions scanning... and I see references to Windows, System32, ProgramFiles, etc. folders blinking in it.
Is BOClean just re-scanning the files related to the currently active processes?
If not, what path(s) should we expect will be scanned? I'm wondering the same (which paths?) with regard to the "resuming background scan" and "unattended" features also.
I had the impression that BOClean's operation(s) involved antihook and dll injection watchguarding + sandboxing. If it is actually going to scan through the entirety of my drives (what about mapped drives?) I won't be happy if it finds/deletes "stuff" which is on someone else's "bad" list.
The absence of an option provided to enumerate paths which should be excluded suggests BOClean does
not
scan the entire filesystem; I'm asking for confirmation that it doesn't.
Logged
~cat~
Global Moderator
Comodo's Hero
Offline
Posts: 969
CBO "...there is nothing better."
Re: will Comodo BOClean delete my pr0n ???
«
Reply #1 on:
April 22, 2007, 07:40:46 PM »
No, it's not scanning your files.
BOClean only scans active memory processes.
Logged
Parched dry and thirsty, knee deep in the river of life.
Kevin McAleavey
Administrator
Comodo's Hero
Offline
Posts: 367
Snag a nasty? NO problem! =)
Re: will Comodo BOClean delete my pr0n ???
«
Reply #2 on:
April 22, 2007, 07:44:32 PM »
BOClean doesn't scan files as its main course of action. It will examine files which are related to anything which starts to run to see if it can detect anything that way but over the years, I've been well known to heavily disrespect file scanners because everyone's got an antivirus or some other antivirus-like file scanner. We do things differently solely on that basis alone. We only look at what's actually trying to run, not what's sitting there. And while file-scanning is useful, doesn't do a lot of good until a system is so hosed up, the idea of "perhaps I should scan" is usually too late.
But we'll stand behind anyone else's scanner of your choice ...
Logged
"I reject your reality and substitute my own." - (Adam Savage, "MYTHBUSTERS" TV show)
frazzled
Comodo Member
Offline
Posts: 48
Re: will Comodo BOClean delete my pr0n ???
«
Reply #3 on:
April 24, 2007, 06:07:28 PM »
Geez, I expected the cutesy title of this thread would draw 'em like flies, but only 166 views so far! 166, compared to 1000+ views for a generic -titled ("Complaint!!!") thread someone started the same day.
Anyhow, now that I've had Comodo BOClean running on this PC for several days, it seems like a fine (stable, no-frills, dedicated purpose) app. I keep hearing (er, reading) how it's the best, bar none, at what it does... but "Where's The Beef?"(tm)
Same as with CyberHawk, after installing BOClean I'm sitting here thinking
"Yah. This is like installing those AS SEEN ON TV (tm)(probably another tm)
anti-
deer whistles on your car. I know them deers is out there somewheres, and I ain't hardly had none of 'em run inta my car since I installed them there whistles... so them gizmos
must
be workin' like they sez"
I think I've read through all the docs (both the marketing spiel and the support 'page') and nowhere have I found any meaty specifics, similar to those being touted by "competing brands", ala:
Quote
http://www.diamondcs.com.au/processguard/index.php?page=introduction
Main uses ...
Each capability of ProcessGuard is powerful in its own right. For example, a program which simply blocked a rootkit trojan from installing would be very valuable in its own right, yet this is just one feature of ProcessGuard! Here is just a brief list of some of the main uses of ProcessGuard:
Securing processes from being attacked (terminated, suspended, modified)
Controlling which programs are/aren't allow to run
Blocking rootkit trojans and other malicious drivers from installing
Protecting physical memory from malicious modification
Blocking hooks and code injections
Determining which programs are being executed on your system
Determining which programs are attacking others on your system
Analysing the inter-process behaviors of programs
Keeping a log of all programs that execute (important for post-infection analysis)
Main attacks ProcessGuard blocks ...
ProcessGuard protects against so many different types of attacks that it's difficult to combine them all into one list (for example, although it protects against process termination it secures over a dozen different "termination vectors" in order to accomplish this, so really it's protecting you against a lot more than just one attack).
Here are the main classes of attacks that ProcessGuard can protect against:
Unwanted/unknown process execution
Process/service termination
Process/service suspension
Process/code modification
Process/service crashing
Rootkit trojan installation
Firewall leaktest bypass methods
Hooks and code injections
Physical memory malicious modifications
Windows File Protection attacks
User Imitation attacks
I wound up choosing the title for this thread upon realizating that in numerous posts I've been
*****-footing
around, trying to find specifics (features, functionality) AFTER having installed the app. Gently, gently, because the limited response my earlier, more pointed/challenging post, in the "BOClean vs ??" thread
http://forums.comodo.com/index.php/topic,7742.0.html
suggested that the ranks of happily enthusiastic users are similarly unenlightened.
Do ya get out much?
The marketspace shared by BOClean *
is
* is now occupied by DOZENS of competing brands. Each of them is claiming best-in-class functionality; to keep pace, Comodo needs to improve BOClean's "sales pitch" by providing details -- perhaps even to the extent of creating a feature comparison chart.
or not.
Don't worry about the details.
We don't explain them because you wouldn't understand them anyhow.
It's a black box. It's free. Trust us. Install it.
posted with sincere appreciation toward MrKevin and Comodo for bringing this much-needed app "to the masses"
Logged
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 7630
Re: will Comodo BOClean delete my pr0n ???
«
Reply #4 on:
April 25, 2007, 11:34:45 AM »
hi Frazzled
There is a big difference in hips like products (the one you are quoting on) and BOClean..
BOClean works with a blacklist and monitors the memory in real time to see if any of these nasties are there or not. So its like an AV but instead of scannig the hard disk to find nasties, we wait in memory and catch them there. Until they are in memory they can't cause any damage anyway.. and its more efficient to sit and where they feed
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
Arkangyal
"There is nothing impossible to him who will try." - Alexander The Great, ancient Greek King of Macedon, 356 BC-323 BC.
Global Moderator
Comodo's Hero
Offline
Posts: 935
[ Visit Hungary ] www.hungary.hu
Re: will Comodo BOClean delete my pr0n ???
«
Reply #5 on:
April 25, 2007, 12:29:20 PM »
Hello Kevin,
What is the difference between these cases:
1. I drag&drop the grc tester file into CBO's window and it's detected as MALWARE.
2. I drag&drop a Hungarian trojan into CBO's window and there's no result.
3. I drag&drop the old BO 1.2 there and it's recognised (also, is this a bug or a special "BO"Clean feature, why CBO asks me twice?)
4. I drag&drop Deep Throat 1 and it's also detected as MALWARE.
5. I also tried ****** (ask for) without results.
What's the problem here? Does case 2 and 5 means CBO can't save me from that malware? Can CBO save me if i actually run these threads in the memory?
Thanks in advance,
Geza Gabriel (nick: Arki)
«
Last Edit: April 25, 2007, 01:23:10 PM by Arkangyal
»
Logged
32bit XP Pro Hun SP3 NTFS, .NET 3.5, VB6SP6, Dx9c (Y08); Asrock mb., Intel 2,66GHz, Ati 1600 xt Pro 512MB, 2GB 400MHz DDR, 1280x1024[at]75Hz 32bit, realtek (built-in), belkin router (wi-fi). MSI Mega book, 64bit Vista Hun SP1, 2gb ram, wifi (n)
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6141
Re: will Comodo BOClean delete my pr0n ???
«
Reply #6 on:
April 25, 2007, 12:41:23 PM »
As has been previously noted in another thread, Arkangyal, the drag&drop wasn't intended to be a public release feature (it escaped by accident). They were using it in-house for some specific reason (I forget what) as part of their testing stuff. It doesn't work the same way that the rest of it does, and shouldn't be used as an indicator of safety or danger.
Your results might be different if the malware was released onto the computer, to try to execute in memory. Time to sandbox and see what happens, sounds like...
LM
Logged
You read my sig block. That's enough personal interaction for one day.
Arkangyal
"There is nothing impossible to him who will try." - Alexander The Great, ancient Greek King of Macedon, 356 BC-323 BC.
Global Moderator
Comodo's Hero
Offline
Posts: 935
[ Visit Hungary ] www.hungary.hu
Re: will Comodo BOClean delete my pr0n ???
«
Reply #7 on:
April 25, 2007, 12:54:01 PM »
Hey LM, thanks for the infos/answer! Sandbox solution then... but i'm afraid i haven't got good news
What shall be the next step?
Logged
32bit XP Pro Hun SP3 NTFS, .NET 3.5, VB6SP6, Dx9c (Y08); Asrock mb., Intel 2,66GHz, Ati 1600 xt Pro 512MB, 2GB 400MHz DDR, 1280x1024[at]75Hz 32bit, realtek (built-in), belkin router (wi-fi). MSI Mega book, 64bit Vista Hun SP1, 2gb ram, wifi (n)
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6141
Re: will Comodo BOClean delete my pr0n ???
«
Reply #8 on:
April 25, 2007, 01:31:04 PM »
Quote from: Arkangyal on April 25, 2007, 12:54:01 PM
but i'm afraid i haven't got good news
What shall be the next step?
What do you mean?
When I said it was time for a sandbox, I was referring to your question
Quote from: Arkangyal
Can CBO save me if i actually run these threads in the memory?
. In other words, you will very likely get different results if you allow the malware to run (and I wouldn't allow it to run if it wasn't in some sort of virtual environment).
LM
Logged
You read my sig block. That's enough personal interaction for one day.
Arkangyal
"There is nothing impossible to him who will try." - Alexander The Great, ancient Greek King of Macedon, 356 BC-323 BC.
Global Moderator
Comodo's Hero
Offline
Posts: 935
[ Visit Hungary ] www.hungary.hu
Re: will Comodo BOClean delete my pr0n ???
«
Reply #9 on:
April 25, 2007, 01:36:42 PM »
For me, sandbox is somehow equal with a test computer (i think it doesn't matter what'll happen if you simply reformat it). (Also, it's a simple, old trojan, which isn't infecting other computers.) So i run the trojan and CBO didn't stop it: i only checked with taskmanager. Did i misunderstand something?
Logged
32bit XP Pro Hun SP3 NTFS, .NET 3.5, VB6SP6, Dx9c (Y08); Asrock mb., Intel 2,66GHz, Ati 1600 xt Pro 512MB, 2GB 400MHz DDR, 1280x1024[at]75Hz 32bit, realtek (built-in), belkin router (wi-fi). MSI Mega book, 64bit Vista Hun SP1, 2gb ram, wifi (n)
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6141
Re: will Comodo BOClean delete my pr0n ???
«
Reply #10 on:
April 25, 2007, 01:42:43 PM »
Woopsies! Maybe the trojan is so old all its teeth fell out and it needs a cane to help walk? Or a wheelchair, and it's blind?
Is the trojan list in CBO fully updated?
LM
Logged
You read my sig block. That's enough personal interaction for one day.
Arkangyal
"There is nothing impossible to him who will try." - Alexander The Great, ancient Greek King of Macedon, 356 BC-323 BC.
Global Moderator
Comodo's Hero
Offline
Posts: 935
[ Visit Hungary ] www.hungary.hu
Re: will Comodo BOClean delete my pr0n ???
«
Reply #11 on:
April 25, 2007, 01:52:25 PM »
I've updated it today, i think that should be correct. Old? I wouldn't find any problem with your statement IF CBO wouldn't recognise the older Back Orifice v1.2
.
«
Last Edit: April 25, 2007, 05:31:48 PM by Arkangyal
»
Logged
32bit XP Pro Hun SP3 NTFS, .NET 3.5, VB6SP6, Dx9c (Y08); Asrock mb., Intel 2,66GHz, Ati 1600 xt Pro 512MB, 2GB 400MHz DDR, 1280x1024[at]75Hz 32bit, realtek (built-in), belkin router (wi-fi). MSI Mega book, 64bit Vista Hun SP1, 2gb ram, wifi (n)
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6141
Re: will Comodo BOClean delete my pr0n ???
«
Reply #12 on:
April 25, 2007, 02:05:35 PM »
Quote from: Arkangyal on April 25, 2007, 01:52:25 PM
I've updated it today, i think that should be correct. Old? I would find any problem with your statement IF CBO wouldn't recognise the older Back Orifice v1.2
.
Ooh, that would be problematic, wouldn't it?!
Next question is, is the trojan in the list?
Logged
You read my sig block. That's enough personal interaction for one day.
Arkangyal
"There is nothing impossible to him who will try." - Alexander The Great, ancient Greek King of Macedon, 356 BC-323 BC.
Global Moderator
Comodo's Hero
Offline
Posts: 935
[ Visit Hungary ] www.hungary.hu
Re: will Comodo BOClean delete my pr0n ???
«
Reply #13 on:
April 25, 2007, 02:31:06 PM »
Correct me if i'm wrong but CBO should stop the malware code by BEHAVIOR, what ever is it's kind. So i mean even if the trojan got a new version CBO should recognise it's malware behavior, no?
I had another test with a newer *** trojan, which isn't on the list (there's only 1 sub-version difference, so instead of 1.00, it's 1.01, etc.).
Logged
32bit XP Pro Hun SP3 NTFS, .NET 3.5, VB6SP6, Dx9c (Y08); Asrock mb., Intel 2,66GHz, Ati 1600 xt Pro 512MB, 2GB 400MHz DDR, 1280x1024[at]75Hz 32bit, realtek (built-in), belkin router (wi-fi). MSI Mega book, 64bit Vista Hun SP1, 2gb ram, wifi (n)
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6141
Re: will Comodo BOClean delete my pr0n ???
«
Reply #14 on:
April 25, 2007, 02:47:08 PM »
No, you're
wrong
, so I must do as you request, and correct you...
CBO's not a behavior-blocker. It works strictly from definitions. The differences come in as far as where it looks for those malware (in memory only) and how (based on the "core" of the malware; the "naked" version).
Basically, rather than take time and resources to scan the filesystem, CBO monitors the memory, where a malware will be unpacked to execute. This is where the other difference comes in. I've seen the count of detectable malware (I don't remember the specific number) and it's huge; this is due to the way it sees the malware.
CBO is programmed to see malware as (Melih's term) a naked lady. When she's all packaged up (with clothes on to disguise) she's not recognized; when she gets unpacked (undressed) to run, Wham! CBO knows who she is. Basically (as I understand it), malware is able to evade detection by modern AVs due to the way they're packed. At the core, the code is still the same. This is why there's only some 24,000 definitions in CBO, but with detection in the multi 100,000 range. Kevin has stated that there are very few "original" trojans written any more; they're all the same, just packed in new ways. But the trojan still has to unpack to run; the instant it does, CBO pounces. But the AV won't twitch coz it's all confused by the package.
Hope that helps clarify...
LM
Logged
You read my sig block. That's enough personal interaction for one day.
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS (Firewall, AV and Defense+)
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo Time Machine
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Safesurf
=> Comodo Online Backup
=> Comodo Backup
===> FAQ for Comodo Backup
===> Help
===> Beta Corner - Comodo Backup
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
Page created in 0.141 seconds with 18 queries.
Powered by SMF 1.1.9
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com