Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 21, 2013, 09:02:58 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663378
Posts
70526
Topics
145180
Members
Latest Member:
sarke
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
Help - CIS
Firewall Help - CIS
Need to make a firewall rule for Lexmark
« previous
next »
Pages:
[
1
]
Author
Topic: Need to make a firewall rule for Lexmark (Read 2554 times)
Xeolyte
Newbie
Offline
Posts: 21
Need to make a firewall rule for Lexmark
«
on:
March 18, 2012, 01:27:39 PM »
I just discovered that my new Lexmark all in one starts up on it's own and phones home once a month. I need to make a rule to block it but don't know how.
I couldn't find the executable that does this anywhere until I started sifting through the registry. It's LX_CATS.exe.
Here is pertinent info on Lexmark's Spyware:
https://oinkinkstore.wordpress.com/tag/lx_cats/
In order to remove Lexmark’s spyware from your system, delete the file (probably in your c:program directory) called “lx_cats.exe”, and also search for and remove a file called “lx_cats.ini” (and, for that matter, any other file including the term “lx_cats”).”
I'm a bit leery about deleting things from the registry so I figure I can just make a rule to stop it.
A million years ago when I was using AtGuard, rules were easy to make .. I can't seem to figure out how to do it with Comodo.
If someone could direct me to a step by step help section I'd appreciate it.
Thanks!
Xeolyte
Logged
Never do what you can't undo until you have considered what you can't do once you have done it.
Boris 3
Comodo's Hero
Offline
Posts: 1284
Re: Need to make a firewall rule for Lexmark
«
Reply #1 on:
March 18, 2012, 02:47:26 PM »
Hi Xeolyte,
If you want to prevent LX_CATS.exe to run and do a single move in your computer go to Defense+ > Computer Security Policy > Blocked files and add it there.
If you just want to prevent it from phoning home go to Firewall > Network Security Policy > Applications Rules > add > select > browse to LX_CATS.exe and then check "use a predefined policy" > Blocked Application
Don't forget to click on ok or apply in each window after making the rule.
Logged
Xeolyte
Newbie
Offline
Posts: 21
Re: Need to make a firewall rule for Lexmark
«
Reply #2 on:
March 18, 2012, 03:03:45 PM »
Thanks for the reply .. the thing is, LX_CATS.exe only shows up in the registry .. I imagine on the date it is scheduled to phone home it then goes into processes - otherwise it's not showing up so I can't give Comodo a path.
Logged
Never do what you can't undo until you have considered what you can't do once you have done it.
Boris 3
Comodo's Hero
Offline
Posts: 1284
Re: Need to make a firewall rule for Lexmark
«
Reply #3 on:
March 18, 2012, 03:41:17 PM »
Quote from: Xeolyte on March 18, 2012, 01:27:39 PM
Here is pertinent info on Lexmark's Spyware:
https://oinkinkstore.wordpress.com/tag/lx_cats/
In order to remove Lexmark’s spyware from your system, delete the file (
probably in your c:program directory
) called “lx_cats.exe”, and also search for and remove a file called “lx_cats.ini” (and, for that matter, any other file including the term “lx_cats”).”
I'm sorry, but reading the above in your post, I understood that you could in fact find it in the C:\Program Files directory.
Logged
Xeolyte
Newbie
Offline
Posts: 21
Re: Need to make a firewall rule for Lexmark
«
Reply #4 on:
March 18, 2012, 04:13:44 PM »
Sorry, I should have made myself more clear .. so I'm guessing there is no way to direct comodo to a registry entry with an executable in it. I was hoping that I could tell comodo to block LX_CATS.exe when it tried to phone home but the firewall apparently needs to know where it's coming from.
I've started a log of when the printer turns on by itself .. at the moment I'm only connecting it to the computer when I need to use it (gotta love USB front ports) and blocking internet access as well. I've also made all obvious logs about usage as read only so they can't be written to.
I'll ultimately need to figure out a way to block this as I bought it for the Fax part as well. Hopefully I start to notice a pattern with the log in a few months.
Thanks again for your reply .. at least I know how to make a rule now.
X
Logged
Never do what you can't undo until you have considered what you can't do once you have done it.
Boris 3
Comodo's Hero
Offline
Posts: 1284
Re: Need to make a firewall rule for Lexmark
«
Reply #5 on:
March 18, 2012, 06:34:35 PM »
If you go to the Folder Options in Control Panel > view > advanced settings and check "Show hidden files, folders and drives", maybe you will finally see the file in your drive C:\.
On the other hand, if you have found the file in the registry, are you sure the path is not mentioned there?
On reflection, if the file is connecting without triggering a reaction from CIS, it must be in the trusted files list of Defense+. You could check and if the file is there, move it to the blocked files
«
Last Edit: March 18, 2012, 06:43:25 PM by Boris 3
»
Logged
Xeolyte
Newbie
Offline
Posts: 21
Re: Need to make a firewall rule for Lexmark
«
Reply #6 on:
March 18, 2012, 09:09:00 PM »
Checking trusted files was one of the first things I did .. the thing is, I just happened to be sitting next to the printer the two times it came on by itself and immediately turned it back off so I'm thinking it may not have had a chance to phone home and trigger the firewall and that's why I can't find any trace of it in the firewall logs .. the 2nd time it happened, today, I did a quick search about lexmark turning on by itself thinking it was a bug and that's how I discovered the spyware thing.
I have all hidden files supposedly showing .. know that there are some really REALLY hidden files you can't see so I even checked both lexmark folders via DOSBOX - now there was a trip down memory lane - and couldn't find any lx_cat.* files - exe's or ini's.
Logged
Never do what you can't undo until you have considered what you can't do once you have done it.
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 16695
Re: Need to make a firewall rule for Lexmark
«
Reply #7 on:
March 23, 2012, 06:04:31 PM »
To what folder are the registry keys pointing to? Are they part of the Legacy keys?
The words cat and .ini seem to indicate drivers. Can you open Process Hacker and look under the Services tab. You will find all driver and services there. See if you can locate the Lexmark driver and stop it from starting; select the entry and right click.
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.044 seconds with 23 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com