Welcome, Guest. Please login or register.
Did you miss your activation email?
May 24, 2013, 10:39:12 PM

Login with username, password and session length

664012 Posts
70625 Topics
145257 Members

Latest Member: Алеся

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
| | |-+  News / Announcements / Feedback - CCE (Moderator: Yanghua Fang)
| | | |-+  I think COMODO Cleaning essentials needs a better repairing ability
« previous next »
Pages: [1] Go Down Print
Author Topic: I think COMODO Cleaning essentials needs a better repairing ability  (Read 5032 times)
ahmedhhw
Comodo Loves me
****
Offline Offline

Posts: 180



« on: February 28, 2012, 08:06:25 AM »

Hello COMODO, today I was watching this video in youtube where a virus infected a critical system file (System login file) and COMODO cleaning Essentials either damaged the files or quarantined it.

http://www.youtube.com/watch?v=JBHGxgOhs0c
Logged
Siketa
Comodo's Hero
*****
Offline Offline

Posts: 3161


ZIG ZAG


« Reply #1 on: February 28, 2012, 08:26:57 AM »

https://forums.comodo.com/news-announcements-feedback-cce/cce-test-t82113.0.html;msg588672#msg588672
Logged
Valentin N
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 2833


Usability Study Group


WWW
« Reply #2 on: February 28, 2012, 10:34:32 AM »

CCE is not a toy for normal use, detection or removal, for that you have malwarebytes, antispyware and others. This shows that if this tool is used reckless it will have great consequences. This also shows that people need to gain experience how to work with it, get to know its functionally and capabilities
Logged

Skype: comodohelper (Personal)

CEVPN: Valentin N

CIS 5.9

Keep CTM alive by voting

Siketa
Comodo's Hero
*****
Offline Offline

Posts: 3161


ZIG ZAG


« Reply #3 on: February 28, 2012, 10:36:26 AM »

Good point, Valentin!  Thumb Up
Logged
SivaSuresh
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 1336


Avert the danger that has not yet come


« Reply #4 on: February 28, 2012, 01:05:31 PM »

Today I came across a system infected by Sality.

I tried to clean it with CCE, started CCE in agressive mode, but by that time itself (just after extraction from zip) it was itself infected by Sality, therefore all it's detections were fake.

I ran Kaspersky "Salitykiller" and came to know that CCE.exe, Killswitch.exe and Autoruns.exe were all already infected by CCE.

After two or three attempts (re extracting), I could finally get them to work. But,

CCE found some infections, after clicking clean it took forever to clean them...(just 36 files, it was just a smart scan)(salitykiller is not running by this time fyi) Thumb Down

I copied the samples and tried to clean them with CIS (CIS on my system just for verification) it was the same issue, even CAV takes forever to clean them, even asks for a reboot, after reboot says that it failed to clean.

One more piece of surprise is that Killswitch showed absolutely no unknown/infected processes (I was in aggressive mode), but the "psfli.pif" file was being repeatedly created on my pendrive even after deleting them manually many times (I could not delete autorun.inf at all, they were actually spreading sality infection, I doubt that there is still something running in the background saving and hiding the infection)

I would like to see a better cleaning routine like that of kaspersky "TDSSKiller" and "Salitykiller" implemented in CCE at least if not is CAV.

In the end, of course I ended up with a mess and had to go with a full fresh re installation. Grin
« Last Edit: February 28, 2012, 01:07:41 PM by SivaSuresh » Logged

with love Siva Suresh
|| Windows8 x64 | CIS 6 | Waterfox | Comodo Dragon x86 | Thunderbird | CCleaner | Evernote | PStart | SuperCopier | Dropbox | TeamViewer | Screenshot Captor ||
|| AMD Phenom II x4 955B | ASUS M4A88TD | 8GB DDR3 RAM | 240GB Sandisk SSD  || 3TB SATA II HDD 6Gb/s
naren
Comodo's Hero
*****
Offline Offline

Posts: 3861


« Reply #5 on: February 29, 2012, 07:04:59 AM »

Today I came across a system infected by Sality.

I tried to clean it with CCE, started CCE in agressive mode, but by that time itself (just after extraction from zip) it was itself infected by Sality, therefore all it's detections were fake.

I ran Kaspersky "Salitykiller" and came to know that CCE.exe, Killswitch.exe and Autoruns.exe were all already infected by CCE.

After two or three attempts (re extracting), I could finally get them to work. But,

CCE found some infections, after clicking clean it took forever to clean them...(just 36 files, it was just a smart scan)(salitykiller is not running by this time fyi) Thumb Down

I copied the samples and tried to clean them with CIS (CIS on my system just for verification) it was the same issue, even CAV takes forever to clean them, even asks for a reboot, after reboot says that it failed to clean.

One more piece of surprise is that Killswitch showed absolutely no unknown/infected processes (I was in aggressive mode), but the "psfli.pif" file was being repeatedly created on my pendrive even after deleting them manually many times (I could not delete autorun.inf at all, they were actually spreading sality infection, I doubt that there is still something running in the background saving and hiding the infection)

I would like to see a better cleaning routine like that of kaspersky "TDSSKiller" and "Salitykiller" implemented in CCE at least if not is CAV.

In the end, of course I ended up with a mess and had to go with a full fresh re installation. Grin

Does it makes any difference if the system is infected & you run CCE which is already on the system or you use CCE from a pendrive?

Did you checked the process psfli.pif if it was treated safe for any reason?
Logged
SivaSuresh
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 1336


Avert the danger that has not yet come


« Reply #6 on: February 29, 2012, 07:10:27 AM »

Does it makes any difference if the system is infected & you run CCE which is already on the system or you use CCE from a pendrive?
I have been extracting CCE from a zip file (on Pendrive) on to a local drive everytime. By that time itself (immediately after inserting my Pendrive), all the executables on my pendrive were immediately infected.

The extracted files were also being immediately infected, for which I had to run Salitykiller and kill the existing sality infected threads and processes.

Did you checked the process psfli.pif if it was treated safe for any reason?
That was the file that was being created on pendrive, not a running process. By the way, I could not find any running infected/unknown processes in Killswitch. (I even killed all unknown processes twice from the menu)
Logged

with love Siva Suresh
|| Windows8 x64 | CIS 6 | Waterfox | Comodo Dragon x86 | Thunderbird | CCleaner | Evernote | PStart | SuperCopier | Dropbox | TeamViewer | Screenshot Captor ||
|| AMD Phenom II x4 955B | ASUS M4A88TD | 8GB DDR3 RAM | 240GB Sandisk SSD  || 3TB SATA II HDD 6Gb/s
naren
Comodo's Hero
*****
Offline Offline

Posts: 3861


« Reply #7 on: February 29, 2012, 07:33:31 AM »


That was the file that was being created on pendrive, not a running process. By the way, I could not find any running infected/unknown processes in Killswitch. (I even killed all unknown processes twice from the menu)

I dont know if this question is right, but does this file showed up with autorun analyzer?
Logged
SivaSuresh
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 1336


Avert the danger that has not yet come


« Reply #8 on: February 29, 2012, 07:55:37 AM »

I dont know if this question is right, but does this file showed up with autorun analyzer?
no
Logged

with love Siva Suresh
|| Windows8 x64 | CIS 6 | Waterfox | Comodo Dragon x86 | Thunderbird | CCleaner | Evernote | PStart | SuperCopier | Dropbox | TeamViewer | Screenshot Captor ||
|| AMD Phenom II x4 955B | ASUS M4A88TD | 8GB DDR3 RAM | 240GB Sandisk SSD  || 3TB SATA II HDD 6Gb/s
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.051 seconds with 21 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com