Welcome, Guest. Please login or register.
Did you miss your activation email?
May 23, 2013, 07:15:21 AM

Login with username, password and session length

663724 Posts
70576 Topics
145218 Members

Latest Member: smith1989

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  Help - CIS
| | | |-+  Install / Setup / Configuration Help - CIS
| | | | |-+  Does CIS have self-protection?
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: Does CIS have self-protection?  (Read 5759 times)
alexo2003
Comodo Member
**
Offline Offline

Posts: 33


« on: March 06, 2011, 06:56:02 AM »

Hi!

The question concerning possibility to kill processes of Comodo. I have the latest version of CIS installed and KillSwitch utility from latest CCE. It is very simple to terminate both cfp.exe and cmdagent.exe, and CIS does not reload them. So, now we have no CIS, no protection, am I right?
Logged
Valentin N
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 2833


Usability Study Group


WWW
« Reply #1 on: March 06, 2011, 07:14:48 AM »

Hey and warm welcome to comodo forums Alex! Smiley

CIS has selfprotection. Keep in mind that CIS is not the nanny of the users decisions so if you decide to delete some file from CIS folder CIS won't stop you. BUT if a malware tires to do the same as you do, it won't succeed but fail.

Regards,
            Valentin N
« Last Edit: March 06, 2011, 07:17:25 AM by Valentin N » Logged

Skype: comodohelper (Personal)

CEVPN: Valentin N

CIS 5.9

Keep CTM alive by voting

alexo2003
Comodo Member
**
Offline Offline

Posts: 33


« Reply #2 on: March 06, 2011, 11:31:41 AM »

OK, I understand that termination using Killswitch is some artificial task. But let's imagine a malware having legitimate digital signature, so it is treated as trusted app by Comodo, and CIS won't stop such termination. I mean that if there exists some possibility of such killing, Comodo should increase its protection. There are some other products that give no chance to terminate them by Killswitch. Well it is only my apprehension and you say CIS is strong enough just "out of the box".

Thank you.
Logged
JoWa
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2934



« Reply #3 on: March 06, 2011, 11:53:49 AM »

There are some other products that give no chance to terminate them by Killswitch.
Which products? And are you sure they were not restarted (= new PID)? Are you sure that KillSwitch’s driver was loaded?

If an application successfully loads a well written kernel mode driver (such as the one KillSwitch/Process Hacker uses), it can terminate any process.
But let's imagine a malware having legitimate digital signature, so it is treated as trusted app by Comodo, and CIS won't stop such termination.
Trusted applications are not allowed to terminate cfp and cmdagent. There are exceptions though, as you can see in Protection settings.
Logged

Ubuntu 13.04, 64-bit | Chrome 27β | Asus P8Z77-M | Intel Core i5 2500K 3,3GHz | 2×4 GB RAM | SSD: OCZ Vertex3 60GB, HDD: 2TB Western Digital Caviar Black | Dell UltraSharp 24" U2410 IPS | Sony MDR-XB1000 | Philips SBC AH1000
alexo2003
Comodo Member
**
Offline Offline

Posts: 33


« Reply #4 on: March 06, 2011, 07:58:12 PM »

Which products? And are you sure they were not restarted (= new PID)? Are you sure that KillSwitch’s driver was loaded?

Bitdefender:

, .

This is from discussion here: http://www.kadets.info/showthread.php?t=78288, sorry it is in Russian. You are right, there is e.g. Ikarus, that restarts just killed process.
Logged
wj32
Comodo's Hero
*****
Offline Offline

Posts: 387



WWW
« Reply #5 on: March 07, 2011, 02:39:04 PM »

Please do not use an old version of Process Hacker (like KillSwitch). Upgrade to the latest version and retest.
Logged

MCTS: Windows Internals
Process Hacker, a free and open source process viewer.
alexo2003
Comodo Member
**
Offline Offline

Posts: 33


« Reply #6 on: March 07, 2011, 08:30:51 PM »

Please do not use an old version of Process Hacker (like KillSwitch). Upgrade to the latest version and retest.

Well, I downloaded latest Process Hacker 2.12, installed just Comodo Firewall with maximal proactive security and tested again on XP SP3. Nothing changed.

First I terminated cmdagent.exe at TP1 (!!!), then cfp.exe was successfully terminated at TT2. I made find in Process Hacker and it shows no "comodo" in Handless or DLLs.

In addition. After termination all Comodo processes I can't start any program from shortcut on the Desktop. System reboot fixes normal behavior of Comodo and XP.
« Last Edit: March 07, 2011, 08:56:25 PM by alexo2003 » Logged
wj32
Comodo's Hero
*****
Offline Offline

Posts: 387



WWW
« Reply #7 on: March 08, 2011, 12:40:37 AM »

Well, I downloaded latest Process Hacker 2.12, installed just Comodo Firewall with maximal proactive security and tested again on XP SP3. Nothing changed.

I meant with BitDefender... (Why would a newer version of PH remove the ability to terminate Comodo processes?)
Logged

MCTS: Windows Internals
Process Hacker, a free and open source process viewer.
OldRampant
Newbie
*
Offline Offline

Posts: 8


« Reply #8 on: March 08, 2011, 12:48:35 AM »

BitDefender 2011 Win 7 32 bit real

http://www.youtube.com/watch?v=Ryh_zdDWoac
Logged
languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3943



« Reply #9 on: March 08, 2011, 01:06:32 AM »

I cannot terminate cmdagent using killswitch at all.
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
wj32
Comodo's Hero
*****
Offline Offline

Posts: 387



WWW
« Reply #10 on: March 08, 2011, 01:07:15 AM »

BitDefender 2011 Win 7 32 bit real

http://www.youtube.com/watch?v=Ryh_zdDWoac

1. Why are you using an old version of Process Hacker?
2. KProcessHacker (the driver) does not appear to be loaded. I have had some reports of AVs blocking KPH from loading.

EDIT: I just tested PH on Windows 7 64-bit, and it terminates BitDefender processes just fine.
« Last Edit: March 08, 2011, 01:51:01 AM by wj32 » Logged

MCTS: Windows Internals
Process Hacker, a free and open source process viewer.
military
Comodo's Hero
*****
Offline Offline

Posts: 607



WWW
« Reply #11 on: March 08, 2011, 01:54:18 AM »

windows xp sp3 / process hacker 2.12 ( killswitch are same results)

« Last Edit: March 08, 2011, 03:40:25 AM by military1 » Logged

Мужество, спокойствие и доверие.
wj32
Comodo's Hero
*****
Offline Offline

Posts: 387



WWW
« Reply #12 on: March 08, 2011, 01:57:16 AM »

The original topic has been discussed at length a few times before. You cannot protect against kernel-mode termination.
Logged

MCTS: Windows Internals
Process Hacker, a free and open source process viewer.
OldRampant
Newbie
*
Offline Offline

Posts: 8


« Reply #13 on: March 08, 2011, 02:30:11 AM »

1. Why are you using an old version of Process Hacker?
2. KProcessHacker (the driver) does not appear to be loaded. I have had some reports of AVs blocking KPH from loading.

EDIT: I just tested PH on Windows 7 64-bit, and it terminates BitDefender processes just fine.
Win 7 64 bit real PH 2.12
http://www.youtube.com/watch?v=VnBAJq4O8QU
Logged
wj32
Comodo's Hero
*****
Offline Offline

Posts: 387



WWW
« Reply #14 on: March 08, 2011, 02:59:01 AM »


KProcessHacker is not loaded. You must load it, as I already explained.
Logged

MCTS: Windows Internals
Process Hacker, a free and open source process viewer.
Tags:
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.047 seconds with 22 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com