Welcome, Guest. Please login or register.
December 25, 2009, 03:37:26 PM

Login with username, password and session length

345178 Posts
38110 Topics
86539 Members

Latest Member: vlavoile

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  D+ Engine could not able to intercept malware properly
« previous next »
Pages: 1 [2] Go Down Print
Author Topic: D+ Engine could not able to intercept malware properly  (Read 3812 times)
foxman
Comodo Loves me
****
Offline Offline

Posts: 148


« Reply #15 on: June 09, 2009, 01:41:25 PM »


It does, the problem is you hit allow on the first one!


There we go again.... hey man, this guy is LAUNCHING an INSTALLATION program! So what did you expect? wanna install something and then tell D+ to block it???  While I am using CIS3.9 and love it, still think Comodo could/should something about this kind of passing the ball back to user situation.... and my threatcast still not working... dang... Angry
Logged
foxman
Comodo Loves me
****
Offline Offline

Posts: 148


« Reply #16 on: June 09, 2009, 01:44:30 PM »

Yep. Thats our bug fixed version to be released soon. It will address some of the issues with antivirus engine.


UUH!!  Can't wait... hope it fixed the threatcast problem also! Shocked
Logged
egemen
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 2151



« Reply #17 on: June 09, 2009, 01:53:24 PM »


UUH!!  Can't wait... hope it fixed the threatcast problem also! Shocked

We are working on TC problem.
Logged
J2897
Comodo's Hero
*****
Offline Offline

Posts: 224


Limted User Account Enforcer


WWW
« Reply #18 on: June 09, 2009, 02:01:39 PM »

I think the problem could be very similar to this harsha_mic... (See Screenshot)

Though I wouldn't worry about your System (if you are that is), 'Sandboxie' is a great program!  Thumb Up
Logged

J2897
Comodo's Hero
*****
Offline Offline

Posts: 224


Limted User Account Enforcer


WWW
« Reply #19 on: June 09, 2009, 02:32:16 PM »

Quote
i'm using proactive internet security and more importantly i could able to see below entry under D+ --> My Protected Files = %windir%\system32\*. So, logically i guess an alert or entry should be blocked. or else am i missing some thing??

The install.exe did not try to access this Path...

%windir%\system32\

Because it was running in the Sandbox, it tried to access this Path instead...

C:\Sandbox\Harsha\DefaultBox\drive\C\WINDOWS\

It seems that 'Sandboxie' allows it to make changes INSIDE the Sandbox, and then Defense+ Stops it because it thinks its about to try to do something OUTSIDE of the Sandbox.

This would explain why you saw the Host File had changed INSIDE the Sandbox.

I could be wrong, I'm just guessing here...  Grin


Hope this helps. Smiley
Logged

EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 4273



« Reply #20 on: June 09, 2009, 06:32:26 PM »

Yep. Thats our bug fixed version to be released soon. It will address some of the issues with antivirus engine.
Soon? Bounce Clapping When? Grin
Logged

Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , Always the latest CIS or CIS Beta (too lazy to update my sig) Athlon XP 2600 1 GB RAM. Opera Browser always using the latest snapshots; Opera 10.10 as of now
harsha_mic
Computer Security Testing Group
Newbie
*****
Offline Offline

Posts: 16


« Reply #21 on: June 09, 2009, 09:25:49 PM »

Thanks Egemen and J2045 for your kind analysis and replys...

Good news is that CIS could able to intercept properly outside the sanboxie... But i still wanted to get clarifed on some questions -

1. Is that BO alert came from Antivirus or Image Exec Ctrl Settings --> Detect Shell Code? Bcoz i have disabled real time virus scanner and using NOD32 for real time.

The install.exe did not try to access this Path...
%windir%\system32\
Because it was running in the Sandbox, it tried to access this Path instead...
C:\Sandbox\Harsha\DefaultBox\drive\C\WINDOWS\
It seems that 'Sandboxie' allows it to make changes INSIDE the Sandbox, and then Defense+ Stops it because it thinks its about to try to do something OUTSIDE of the Sandbox.

This would explain why you saw the Host File had changed INSIDE the Sandbox.

2. If thats the case then how come it got alerted for sysgaurd.exe when it tried to create [at] c:\Sandbox\Harsha\DefaultBox\drive\C\...\.. path but not for host file changes

Thanks,
Harsha.
« Last Edit: June 09, 2009, 09:37:52 PM by harsha_mic » Logged
OmeletParty
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1689


The only thing i ask for are eggs.


WWW
« Reply #22 on: June 09, 2009, 09:31:56 PM »

1. Is that BO alert came from Antivirus or Image Exec Ctrl Settings --> Detect Shell Code? Bcoz i have disabled real time virus scanner and using NOD32 for real time.

It came from D+ Detect Shell Code

2. If thats the case then how come it got alerted for sysgaurd.exe when it tried to create [at] c:\Sandbox\Harsha\DefaultBox\drive\C\...\.. path

You could try adding Sandbox folder to My protected files/folders.
Also Detection for this rouge with CAV's has been added!
Logged

Happy New Year and Holidays
Please follow forum policy. Thank you.
harsha_mic
Computer Security Testing Group
Newbie
*****
Offline Offline

Posts: 16


« Reply #23 on: June 09, 2009, 09:42:36 PM »

Omletguy,

I believe you did not understand my 2nd question clearly i guess. i have updated it again....nywayz here it is --
Why CIS alerted only for file creation (sysguard.exe) but not for host file changes even though their path is same for the both C:\Sandbox\Harsha\DefaultBox\drive\C\WINDOWS\ which is not in the My Protected Files List. Or else am i missing something?

Thanks,
Harsha.
Logged
OmeletParty
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1689


The only thing i ask for are eggs.


WWW
« Reply #24 on: June 09, 2009, 09:50:01 PM »

That alert you get is the installer reading the real windows folder

you see sandboxie lets anything running in it read outside folders but cant change them all changes happen in sanboxie folder thats not protected.

Hope this explains it!
Logged

Happy New Year and Holidays
Please follow forum policy. Thank you.
harsha_mic
Computer Security Testing Group
Newbie
*****
Offline Offline

Posts: 16


« Reply #25 on: June 09, 2009, 10:20:01 PM »

Ok! Omletguy...ThanX for the explanation..
Logged
Tags:
Pages: 1 [2] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.049 seconds with 18 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com