Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
December 29, 2009, 02:16:20 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
346049
Posts
38230
Topics
86817
Members
Latest Member:
Tauren
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Instant Malware Analysis Online - CIMA
Result = "undetected" - what does this mean?
« previous
next »
Pages:
[
1
]
2
Author
Topic: Result = "undetected" - what does this mean? (Read 4348 times)
mouse1
Global Moderator
Comodo's Hero
Offline
Posts: 364
Result = "undetected" - what does this mean?
«
on:
July 18, 2009, 12:12:56 PM »
Many thanks
Mouse
Logged
mouse1
Global Moderator
Comodo's Hero
Offline
Posts: 364
Re: Result = "undetected" - what does this mean?
«
Reply #1 on:
July 23, 2009, 01:57:45 AM »
BUMP
Logged
Eric Cryptid
Global Moderator
Comodo's Hero
Offline
Posts: 1753
Security Saskquatch
Re: Result = "undetected" - what does this mean?
«
Reply #2 on:
August 23, 2009, 05:42:44 AM »
BUMP
Just got the same for c:\program files\launch manager\WisSvcCtrl.exe
CIS detected file as "TrojWare.Win32.TrojanProxy.Horst~A[at]25568489
When analysis of file on VirusTotal - Comodo was only one to detect it as suspicious
http://www.virustotal.com/analisis/5272216b439c663ae1dfb0c0069d88ecc3a5633740dfc719fb87bfe6157c2de5-1247331036
Whereas CAMAS detected it as "Undetected"
http://camas.comodo.com/cgi-bin/submit?file=5272216b439c663ae1dfb0c0069d88ecc3a5633740dfc719fb87bfe6157c2de5
Presumably Undetected means that it was a Missed Sample or it's presuming that CIS didn't detect it since your submitting the file?
E
Logged
Moderator:
forum policy
.
System:
32 bit Windows Vista SP3
Realtime Protection:
Comodo Internet Security 3.13
Internet Security
On Demand:
MBAM & SAS
Other:
CSC,CBU,CEVPN,CDragon.
mouse1
Global Moderator
Comodo's Hero
Offline
Posts: 364
Re: Result = "undetected" - what does this mean?
«
Reply #3 on:
August 24, 2009, 01:53:52 AM »
Yes this is puzzling. What is a missed sample?
I've now had 5-6 viruses flagged (probably incorrectly) by CIS. In each case CAMAS has said 'undetected', and given other results that suggest that CAMAS could not fully access the processes involved.
Before testing with CAMAS I have typically 'excluded' the files in CIS to prevent CIS popping up when CAMAS tries to access the files. However I wonder whether what is happening is that CAMAS is trying to access files or resources related to them which CIS is controlling?
Seems to me that this - checking CIS - is a key way people are going to want to use CAMS, so it would be good to ubnderstand what is happening.
Many thanks
Mouse
Logged
keXek
Newbie
Offline
Posts: 7
Re: Result = "undetected" - what does this mean?
«
Reply #4 on:
August 24, 2009, 06:03:40 AM »
I think it means that malware can bypass CAMAS with (simple) injecting into other processes
P.S i'm about malware in 3d post.
P.P.S And this is cmd.exe, signed by microsoft corp.
http://camas.comodo.com/cgi-bin/submit?file=c45a09fa5d6f9e58bc46e26bd1bfe9777fd7a513f692f5e6602bc751da8b4a7e
It seems "undected" means that file isnt suspicious or malware, IMHO
«
Last Edit: August 24, 2009, 06:13:21 AM by keXek
»
Logged
mouse1
Global Moderator
Comodo's Hero
Offline
Posts: 364
Re: Result = "undetected" - what does this mean?
«
Reply #5 on:
August 24, 2009, 07:37:56 AM »
Somehow I think we ought to know...
Could Melih or someone working on CIMA clarify please?
Many thanks in anticipation
Mouse
Logged
Eric Cryptid
Global Moderator
Comodo's Hero
Offline
Posts: 1753
Security Saskquatch
Re: Result = "undetected" - what does this mean?
«
Reply #6 on:
August 24, 2009, 07:59:01 AM »
I've posted in Malware Research Group so hopefully someone will shed some more light on things.
E
Logged
Moderator:
forum policy
.
System:
32 bit Windows Vista SP3
Realtime Protection:
Comodo Internet Security 3.13
Internet Security
On Demand:
MBAM & SAS
Other:
CSC,CBU,CEVPN,CDragon.
umesh
Global Moderator
Comodo's Hero
Offline
Posts: 566
Re: Result = "undetected" - what does this mean?
«
Reply #7 on:
August 24, 2009, 08:13:10 AM »
Hi,
When CAMAS gives verdict as 'undetected' it means, it didn't find any malware behavior upon it's execution as shown in complete report.
Both CAMAS URLs mentioned in this post give execution report where you can see nothing is suspicious as per report and therefore verdict is undetected.
Thanks
-umesh
Logged
mouse1
Global Moderator
Comodo's Hero
Offline
Posts: 364
Re: Result = "undetected" - what does this mean?
«
Reply #8 on:
August 24, 2009, 10:19:57 AM »
Thanks that's great.
Could it maybe say instead 'No malware behaviour detected, based on analysis above'?
Also wondered what 'process is active' meant. Does it mean 'Cannot do much analysis because the process is currently running on your computer?' When it says this it seems not to give much information. Alternatively maybe no info means 'have run this test and it passed'?
Many thanks in anticipation
Mouse
Logged
umesh
Global Moderator
Comodo's Hero
Offline
Posts: 566
Re: Result = "undetected" - what does this mean?
«
Reply #9 on:
August 24, 2009, 10:48:40 AM »
Hi Mouse,
Quote
Could it maybe say instead 'No malware behaviour detected, based on analysis above'?
Yes, that's actually undetected means. We will change to this.
Quote
Also wondered what 'process is active' meant. Does it mean 'Cannot do much analysis because the process is currently running on your computer?' When it says this it seems not to give much information. Alternatively maybe no info means 'have run this test and it passed'?
CIMA has pre-defined period till which analyzes a file, a process may remain active till the end of this period or may have exited.
Thanks
-umesh
Logged
knk2006
Comodo Member
Offline
Posts: 41
Re: Result = "undetected" - what does this mean?
«
Reply #10 on:
August 25, 2009, 12:37:48 PM »
No stop here for a moment guyz .. that doesn't mean that the file is not a malware .. take this analysis for example ..
http://camas.comodo.com/cgi-bin/submit?file=e28140f5208e5131369a2cfb70bc1c52c7029737642f2b242c34b6f37738ddf2
it says undetected ..However .. because i know what this file does ..i can surly say it's a trojan Downloader ...
... in conclusion , be careful ...
Logged
mouse1
Global Moderator
Comodo's Hero
Offline
Posts: 364
Re: Result = "undetected" - what does this mean?
«
Reply #11 on:
August 25, 2009, 03:45:50 PM »
Quote from: umesh on August 24, 2009, 10:48:40 AM
Hi Mouse,Yes, that's actually undetected means. We will change to this.CIMA has pre-defined period till which analyzes a file, a process may remain active till the end of this period or may have exited.
Thanks
-umesh
Re 'undetected', thanks that's great & very clear. Re other posters comment I think 'based on the analysis above' is a sufficient qualification. (I guess at the level of precision that CIMA operates - its what is downloded, not the downloder that's the malware?).
Sorry to be dense but still don't understand the explanation regarding active processes - what process exits (or does not) and what is the significance of it exiting (or not?). Hope you can help I'm not a malware expert unfortunately.
Many thanks in anticipation. Really realising the value of CIMA now I am coming to understand it! Just need a bit better explanation for mere mortals :-)
Mouse
Logged
umesh
Global Moderator
Comodo's Hero
Offline
Posts: 566
Re: Result = "undetected" - what does this mean?
«
Reply #12 on:
August 25, 2009, 03:53:36 PM »
Hi mouse1,
Quote from: mouse1 on August 25, 2009, 03:45:50 PM
Re 'undetected', thanks that's great & very clear. Re other posters comment I think 'based on the analysis above' is a sufficient qualification. (I guess at the level of precision that CIMA operates - its what is downloded, not the downloder that's the malware?).
Sorry to be dense but still don't understand the explanation regarding active processes - what process exits (or does not) and what is the significance of it exiting (or not?). Hope you can help I'm not a malware expert unfortunately.
Many thanks in anticipation. Really realising the value of CIMA now I am coming to understand it! Just need a bit better explanation for mere mortals :-)
Mouse
As CIMA executes a malware in virtual environment and notices all changes in system, it analyzes all changes after a given time period, you can call it time out period. When it times out, process it executed may be running (active) or may have completed (exited).
Regarding verdict, it analyzes all activities and depending on impact malware executioon made on system it gives verdict. So it can be downloader as well as downloaded application.
Thanks
-umesh
Logged
knk2006
Comodo Member
Offline
Posts: 41
Re: Result = "undetected" - what does this mean?
«
Reply #13 on:
August 25, 2009, 04:00:59 PM »
Quote from: umesh on August 25, 2009, 03:53:36 PM
Hi mouse1,
As CIMA executes a malware in virtual environment and notices all changes in system, it analyzes all changes after a given time period, you can call it time out period. When it times out, process it executed may be running (active) or may have completed (exited).
Regarding verdict, it analyzes all activities and depending on impact malware executioon made on system it gives verdict. So it can be downloader as well as downloaded application.
Thanks
-umesh
thanks for the clarification ...However with coco << that's how i like to call CIS .. i shall not worry
Logged
mouse1
Global Moderator
Comodo's Hero
Offline
Posts: 364
Re: Result = "undetected" - what does this mean?
«
Reply #14 on:
August 26, 2009, 02:23:54 AM »
Quote from: umesh on August 25, 2009, 03:53:36 PM
Hi mouse1,
As CIMA executes a malware in virtual environment and notices all changes in system, it analyzes all changes after a given time period, you can call it time out period. When it times out, process it executed may be running (active) or may have completed (exited).
Regarding verdict, it analyzes all activities and depending on impact malware executioon made on system it gives verdict. So it can be downloader as well as downloaded application.
Thanks
-umesh
OK thanks can now use CIMA with more confidence.
So maybe say - 'Some malicious activity may have been missed since CIMA timed out before submitted file had stopped running.'
Best wishes
Mouse
Logged
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.045 seconds with 16 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com