Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
July 24, 2008, 04:53:09 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
176781
Posts
20899
Topics
50701
Members
Latest Member:
toze
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Anti-Viruspyware (CAVS)
Feedback/Comments/Announcements/News about CAVS
Comodo let me down!
« previous
next »
Pages:
[
1
]
Author
Topic: Comodo let me down! (Read 1450 times)
Mythoz
Newbie
Offline
Posts: 3
Comodo let me down!
«
on:
April 16, 2008, 08:38:34 AM »
Ok my previous post was deleted with the following message:
>Hi Mythoz,
>Your post had some virus scanners detect a virus sample in it. I didn't see a problem in the links, Only the info on the virus it self, But I deleted your post for our users sake.
>Try to take extra caution when posting certain links
>
I am assuming the checkers detect a virus simply because of the html code appended to the html files which I included in my post. So to protect those of you who may be inclined to go running the code blindly I have reposted with the offending data Base64 encoded.
Hopefully this will protect you poor innocents.
Ironic really, comodo antivirus cannot detect the code yet the message board users can?
Foolishly I clicked an unknown program, no alert from Comodo. HD lit up and went nuts and comodo firewall popped a connection request which I blocked.
CTL+ALT+DEL popped the task manager window which instantly dissappeared again, and again .....
Hit the big button on the wall and killed everything.
Restarted and checked my startups found this:
HKCU \ run
svcshare = C:\WINDOWS\system32\drivers\spoclsv.exe
removed it and used spybot to kill the running process. Spybot reported it as an "FUJACKS-J" infection.
Looked it up and found this to be the most informative and comprehensive information:
LINKS REMOVED
This has some extra info too in the "more info" tab.:
LINKS REMOVED
Luckily I killed the machine in time to minimize the damage but even scanning a known infected file comodo does not recognize it.
This is extremely dissappointing as it is an old virus and not a very clever one.
It placed a "Desktop_.ini" file in every folder it visited.
It appended:
(Base64 encoded to protect the simpletons)
PGlmcmFtZSBzcmM9aHR0cDovL3d3dy5rcnZrci5jb20vd29ybS5odG0gd2lkdGg9MCBoZWlnaHQ9
MD48L2lmcmFtZT4=
To every html file it found. (probably would have done the asp,aspx etc too but it didnt find any)
It prepended 75kb of code to every exe it found (probably com etc too but it didnt find any)
Each time an infected file is run it reinstalls spoclsv.exe and the registry entry and attempts to connect to the net (didnt note where)
The pre infection program code is not infected just appended after the virus code.
The virus PE headers have the section names nsp0,nsp1,nsp2,vmp0
Come on comodo this is basic crap!!!! doesnt even infect programs in memory!!! I am a little pissed right now!
===============================================
To clean up the mess I used Uedit to find and replace in files:
(Base64 encoded to protect the simpletons)
PGlmcmFtZSBzcmM9aHR0cDovL3d3dy5rcnZrci5jb20vd29ybS5odG0gd2lkdGg9MCBoZWlnaHQ9
MD48L2lmcmFtZT4=
replacing with nothing.
then did a uedit find in files searching for nsp0 to locate all infected exe, scr files. Not sure if this would detect com files too as they dont have PE headers but suprisingly windows loads com files the same as exe files checking for the PE headers first (you learn something new everyday) so it probably prepends the same code to com files.
You can find the original code at 75269d (12605h) and deleteing the previous bytes using uedit removes the virus. I only had 35 files to do luckily.
(the virus only infects files which have an embedded icon oddly enough)
Not sure if this information helps anyone but it never hurts to have info.
Now I am clean again I have to look for a new virus checker.
Mod Edit: Some AV's Detected posted links as a Virus (Eg, Avast!), So links have been removed.
«
Last Edit: April 16, 2008, 08:45:56 AM by Josh123
»
Logged
unreliable = comodo in english
Eric Cryptid
Global Moderator
Comodo's Hero
Offline
Posts: 963
Security Saskquatch
Re: Comodo let me down!
«
Reply #1 on:
April 16, 2008, 10:24:51 AM »
Firstly, CAVS is in Beta at the moment and recent tests suggest only a 75% Detection rate. I'm currently using it myself along with Comodo BoClean to instantly stop malware.
I suggest you do a full scan with SuperAntispyware (Free Edition) which is particularly good ad removing any reminents of Viruses.
The new version of CAVS - CAVS3 is due to come out in the very near future. I suggest you run something like Script Defender and BoClean along with CAVS while we wait for the new version to come out.
Eric
Logged
Cryptid - Any animal or creature that has been reported to have existed, but has not been proven to.
Security Fanatic
Please Read Forum Policy Before Posting -
https://forums.comodo.com/new_member_information/forum_policy-t1516.0.html
Mythoz
Newbie
Offline
Posts: 3
Re: Comodo let me down!
«
Reply #2 on:
April 16, 2008, 05:25:21 PM »
Hello Eric
Alpha, Beta, Theta there is no excuse for missing this one. Granted a program in Beta is going to have issues, but to not detect a virus which was reported almost eighteen months ago? A virus which uses no encryption, no morphing, no advanced hiding techniques, it simply uses an open registry key to start it and perpends the same 75Kb to every file it infects, openly announces it has been in a folder with the ini file and makes more noise than a herd of elephants in a china shop. That is not an issue for a program which purports to call itself a virus checker, that’s a complete failure.
For goodness sake I have a text editor that can detect it, what’s more it can edit text files too, can Comodo?
People need to have confidence in their virus checker, Beta or not. In Beta stage you expect perhaps that it doesn’t detect some of the fancy intelligent viri, you expect that when you click a certain checkbox while you have minesweeper running, three windows open and the toaster making breakfast the whole thing may crash. You do not expect that the simplest of malware, written by some ignorant kid from China, could completely bypass the thing.
I am sorry, while I appreciate the hard work done at Comodo providing these products for free I find this absolutely unacceptable. Wether a program is free or costs hundreds of dollars it is equally as useful if it fails in the basics. If it were some exotic viri I may be tempted to stick by Comodo but to miss something this simple begs the questions, what does it check for? Just how protected am I really?
I shall continue to use the Comodo firewall which I have found to be pretty good to date but I cannot continue to run your antivirus with confidence either in Beta or version 2k if you can allow something so trivial to circumvent you.
On another side issue and something you may expect from a Beta.
The first thing I did when the virus hit was disconnect the computer from the internet and the network, isolating it completely. Now while I was sitting cursing and removing the infection I noticed on the computer next to me a window saying comodo antivirus had found an update on the web would I like to download it. I clicked yes and to my amazement it downloaded it and reported that I was now up to date and protected.
This was an incredible feat as the infected computer was the internet gateway and without it on the network none of the others have any access whatsoever to the outside world.
So either you have developed technology which far surpasses anything I have seen before or the update mechanism is nothing much more than window dressing. Which also answers the question I had about why when I do a manual update does it download lots of data when I have auto update apparently updating constantly?
Oh and apparently the link from my original post still report a virus in Avast hence they were removed.
As the post is incomplete without them I post them again here this time Base64 encoded. Be warned if you are using a virus checker other than Comodo then following the links may cause an alert.
However since both links are to reputable virus reporting sites you can take that as you may. If you are using Comodo you have no worries, it wont detect anything on the sites false or otherwise.
aHR0cDovL3d3dy5jZXJ0LWluLm9yZy5pbi92aXJ1cy9GaWxlSW5mZWN0b3JGVUpBQ0tTLmh0bQ==
aHR0cDovL3d3dy5zb3Bob3MuY29tL3NlY3VyaXR5L2FuYWx5c2VzL3ZpcnVzZXMtYW5kLXNweXdh
cmUvdzMyZnVqYWNrc2ouaHRtbA==
Logged
unreliable = comodo in english
Josh123
Guest
Re: Comodo let me down!
«
Reply #3 on:
April 16, 2008, 11:46:19 PM »
Quote from: Mythoz on April 16, 2008, 05:25:21 PM
Hello Eric
Alpha, Beta, Theta there is no excuse for missing this one. Granted a program in Beta is going to have issues, but to not detect a virus which was reported almost eighteen months ago? A virus which uses no encryption, no morphing, no advanced hiding techniques, it simply uses an open registry key to start it and perpends the same 75Kb to every file it infects, openly announces it has been in a folder with the ini file and makes more noise than a herd of elephants in a china shop. That is not an issue for a program which purports to call itself a virus checker, that’s a complete failure.
For goodness sake I have a text editor that can detect it, what’s more it can edit text files too, can Comodo?
People need to have confidence in their virus checker, Beta or not. In Beta stage you expect perhaps that it doesn’t detect some of the fancy intelligent viri, you expect that when you click a certain checkbox while you have minesweeper running, three windows open and the toaster making breakfast the whole thing may crash. You do not expect that the simplest of malware, written by some ignorant kid from China, could completely bypass the thing.
I am sorry, while I appreciate the hard work done at Comodo providing these products for free I find this absolutely unacceptable. Wether a program is free or costs hundreds of dollars it is equally as useful if it fails in the basics. If it were some exotic viri I may be tempted to stick by Comodo but to miss something this simple begs the questions, what does it check for? Just how protected am I really?
I shall continue to use the Comodo firewall which I have found to be pretty good to date but I cannot continue to run your antivirus with confidence either in Beta or version 2k if you can allow something so trivial to circumvent you.
On another side issue and something you may expect from a Beta.
The first thing I did when the virus hit was disconnect the computer from the internet and the network, isolating it completely. Now while I was sitting cursing and removing the infection I noticed on the computer next to me a window saying comodo antivirus had found an update on the web would I like to download it. I clicked yes and to my amazement it downloaded it and reported that I was now up to date and protected.
This was an incredible feat as the infected computer was the internet gateway and without it on the network none of the others have any access whatsoever to the outside world.
So either you have developed technology which far surpasses anything I have seen before or the update mechanism is nothing much more than window dressing. Which also answers the question I had about why when I do a manual update does it download lots of data when I have auto update apparently updating constantly?
Oh and apparently the link from my original post still report a virus in Avast hence they were removed.
As the post is incomplete without them I post them again here this time Base64 encoded. Be warned if you are using a virus checker other than Comodo then following the links may cause an alert.
However since both links are to reputable virus reporting sites you can take that as you may. If you are using Comodo you have no worries, it wont detect anything on the sites false or otherwise.
aHR0cDovL3d3dy5jZXJ0LWluLm9yZy5pbi92aXJ1cy9GaWxlSW5mZWN0b3JGVUpBQ0tTLmh0bQ==
aHR0cDovL3d3dy5zb3Bob3MuY29tL3NlY3VyaXR5L2FuYWx5c2VzL3ZpcnVzZXMtYW5kLXNweXdh
cmUvdzMyZnVqYWNrc2ouaHRtbA==
We do appreciate your concern. CAVS 2 isn't that effective, Just wait for CAVS 3 please
Josh
Logged
Josh123
Guest
Re: Comodo let me down!
«
Reply #4 on:
April 19, 2008, 11:02:29 PM »
Bump. Thread locked. If you need this Thread reopened please PM myself or another Mod with a link to this thread.
Josh
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.132 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com