Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 22, 2013, 11:19:18 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663637
Posts
70566
Topics
145225
Members
Latest Member:
KentonMcs
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
News / Announcements / Feedback - CCE
(Moderator:
Yanghua Fang
)
Stories of heroism and victory....against malware using KillSwitch :)
« previous
next »
Pages:
1
[
2
]
3
4
...
6
Author
Topic: Stories of heroism and victory....against malware using KillSwitch :) (Read 19070 times)
lordraiden
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 833
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #15 on:
December 29, 2010, 09:57:41 AM »
Quote from: Melih on December 29, 2010, 09:54:48 AM
two different things
1)Identify whats bad (works if you know the malware and its in your db etc)
2)Identify whats bad thru "elimination".
The way I would find a malware that AVs miss is thru this method.
So KillSwitch helps me identify by "reducing" the pool of processes I have to check by only showing "untrusted" processes..this, believe it or not, makes the whole process of fighting the malware much more managable and will (is) being appreciated by all the guys who clean malware day in day out.
Melih
Yes, ok but anvir do all those things they have a safe database and an AV database (bigger or little than comodo but the idea it's the same), take a look:
http://www.anvir.com/programs-overview-task-manager.htm
download the trial version and take a look, maybe you can take some ideas.
It has exactly the same features than KillSwitch and much more the only difference is that they use 1 engine and KillSwitch +20
This is why Comodo need to do a Market research before release any app, to know what is already in the market and how to improve it, in this case, would be Hitman Pro and Anvir. And in the case of KillSwitch for at least dont claim something that you didn't invented.
At least DACS is still out there, is not new but it's revolutionary.
«
Last Edit: December 29, 2010, 10:37:23 AM by lordraiden
»
Logged
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12914
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #16 on:
December 29, 2010, 11:06:38 AM »
Quote from: lordraiden on December 29, 2010, 09:57:41 AM
Yes, ok but anvir do all those things they have a safe database and an AV database (bigger or little than comodo but the idea it's the same), take a look:
http://www.anvir.com/programs-overview-task-manager.htm
download the trial version and take a look, maybe you can take some ideas.
It has exactly the same features than KillSwitch and much more the only difference is that they use 1 engine and KillSwitch +20
This is why Comodo need to do a Market research before release any app, to know what is already in the market and how to improve it, in this case, would be Hitman Pro and Anvir. And in the case of KillSwitch for at least dont claim something that you didn't invented.
At least DACS is still out there, is not new but it's revolutionary.
thanks for that lordraiden..very useful.
I can't find the feature where you can show "only the untrusted processes in memory".
can you pls point me to it...thank you for your help
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
lordraiden
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 833
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #17 on:
December 29, 2010, 11:28:46 AM »
Quote from: Melih on December 29, 2010, 11:06:38 AM
thanks for that lordraiden..very useful.
I can't find the feature where you can show "only the untrusted processes in memory".
can you pls point me to it...thank you for your help
Melih
They have the feature of plot with different colours depending on the file, and Killswitch doesn't
So this is the core of killswich? "show only the untrusted processes in memory" jajajaja are you telling me that this is the super revolutionary technology the only and most important thing?
I can tell you several REAL features that killswich does not have and anvir yes and are quite useful for malware cleaning but is better if you install the program and check it by yourself, or at least read the features list.
You asked this:
Quote
I didn't know other process managers have the ability to verdict a file?
Can you pls show me which Process Manager have this ability? thanks
And I told you anvir, so until you can prove the opposite like you rudely said to other forum member:
Shut up!
And don't change the topic to talk about a feature that nobody cares, at least nobody is talking about it, you are the only person metioning it over and over while you can simple order the process by verdict to get the same effect.
«
Last Edit: December 29, 2010, 11:42:03 AM by lordraiden
»
Logged
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12914
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #18 on:
December 29, 2010, 12:50:30 PM »
Quote from: lordraiden on December 29, 2010, 11:28:46 AM
They have the feature of plot with different colours depending on the file, and Killswitch doesn't
So this is the core of killswich? "show only the untrusted processes in memory" jajajaja are you telling me that this is the super revolutionary technology the only and most important thing?
I can tell you several REAL features that killswich does not have and anvir yes and are quite useful for malware cleaning but is better if you install the program and check it by yourself, or at least read the features list.
You asked this:And I told you anvir, so until you can prove the opposite like you rudely said to other forum member:
Shut up!
And don't change the topic to talk about a feature that nobody cares, at least nobody is talking about it, you are the only person metioning it over and over while you can simple order the process by verdict to get the same effect.
Ability to terminate all "untrusted processes"?
Anvir seems like a good task manager.
To me: ability to kill all "unknown" processes as long as you have a good whitelist offers a great feature.
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
lordraiden
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 833
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #19 on:
December 29, 2010, 12:54:16 PM »
Quote from: Melih on December 29, 2010, 12:50:30 PM
Ability to terminate all "untrusted processes"?
Anvir seems like a good task manager.
To me: ability to kill all "unknown" processes as long as you have a good whitelist offers a great feature.
Melih
Why I would want to kill any unknown process? very stupid option, maybe kill all the dangerous process option would be useful, and would be more intelligent, and maybe you can save a couple of seconds compared with anvir functionality, but thats all.
Logged
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12914
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #20 on:
December 29, 2010, 01:06:08 PM »
First of all, pls allow me to stat again, thy coder for anvir has done an excellent job and built a very good task manager.
Here is a small test i did on a VM machine with not much stuff in it...
Check the screenshots....
Killswitch showed Zero untrusted process (this shows the power of whitelisting)
vs
Anvir showed many files as it didn't know the verdict on them (thats my understanding of course I could be wrong)..
So, If i was hunting a malware on this PC, KillSwitch would have made my life much easier as I didn't have to go thru many files to "deduct" what could be malware.
Like I said, this is how I removed malware (day zero)...you just want to know what is untrusted...and let me find amongst whats untrusted which one is really untrusted.
Again, anvir coder has done a good job and welldone to him for a nice and sophisticated task manager.
thanks
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12914
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #21 on:
December 29, 2010, 01:08:46 PM »
Quote from: lordraiden on December 29, 2010, 12:54:16 PM
Why I would want to kill any unknown process? very stupid option, maybe kill all the dangerous process option would be useful, and would be more intelligent, and maybe you can save a couple of seconds compared with anvir functionality, but thats all.
If you have a good whitelist which includes all the critical files for OS etc...then its ok to fight malware by killing all unknown processes....this gives you a chance to work out where the problems are..gives you a breathing room..again these are my own experiences for malware cleaning. We are more than happy to improve with our users suggestions.
thanks
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
lordraiden
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 833
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #22 on:
December 29, 2010, 01:21:10 PM »
Quote from: Melih on December 29, 2010, 01:06:08 PM
First of all, pls allow me to stat again, thy coder for anvir has done an excellent job and built a very good task manager.
Here is a small test i did on a VM machine with not much stuff in it...
Check the screenshots....
Killswitch showed Zero untrusted process (this shows the power of whitelisting)
vs
Anvir showed many files as it didn't know the verdict on them (thats my understanding of course I could be wrong)..
So, If i was hunting a malware on this PC, KillSwitch would have made my life much easier as I didn't have to go thru many files to "deduct" what could be malware.
Like I said, this is how I removed malware (day zero)...you just want to know what is untrusted...and let me find amongst whats untrusted which one is really untrusted.
Again, anvir coder has done a good job and welldone to him for a nice and sophisticated task manager.
thanks
Melih
I was not saying which one is better, bigger white/black list. I was answering this question:
Quote
Quote from: Melih on Today at 08:07:53 AM
I didn't know other process managers have the ability to verdict a file?
Can you pls show me which Process Manager have this ability? thanks
Here:
http://www.anvir.com/
Of course anvir does not have the same resources than Comodo to get a huge white/black list.
All your shourcuts are ok, but still you can do the same with anvir, process hacker or any other.
Show only untrusted with Comodo requires 2 clicks
Order the files by veredict (same visual effect) for anvir/KillSwitch : 1 click
Instead kill all the untrusted (2 clicks) you can select holding the "cap" key the first untrusted app and the last one, right click terminate (4clicks).
Ok you save a couple of clicks to the world.
Logged
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12914
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #23 on:
December 29, 2010, 01:58:45 PM »
Quote from: lordraiden on December 29, 2010, 01:21:10 PM
I was not saying which one is better, bigger white/black list. I was answering this question:
Of course anvir does not have the same resources than Comodo to get a huge white/black list.
All your shourcuts are ok, but still you can do the same with anvir, process hacker or any other.
Show only untrusted with Comodo requires 2 clicks
Order the files by veredict (same visual effect) for anvir/KillSwitch : 1 click
Instead kill all the untrusted (2 clicks) you can select holding the "cap" key the first untrusted app and the last one, right click terminate (4clicks).
Ok you save a couple of clicks to the world.
But having a tool combined with a huge whitelisting will create an ability that doesn't exist in other task managers.
That ability is to terminate unknown files. You see, if you have a good whitelist, you can easily terminate unknown files. If you don't have this whitelist, then terminating all unknown will cause you a lot of problem. You can do that will Killswitch much easier than you can with other task managers. that was my point. Its not about the task manager..its about the combination of Comodo's infrastructure into this task manager that makes the product so unique.
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
wj32
Comodo's Hero
Offline
Posts: 387
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #24 on:
December 29, 2010, 03:21:45 PM »
Quote from: lordraiden on December 29, 2010, 09:57:41 AM
It has exactly the same features than KillSwitch and much more the only difference is that they use 1 engine and KillSwitch +20
The only feature in my biased view that AnVir has over KillSwitch/PH is the bloated and ugly UI. Look at how many icons and custom menus they use. And just like all the other process viewers (aside from Process Explorer) the author of AnVir Task Manager doesn't actually know what he's doing, and thus fails all basic tests like not being fooled when a process tries to fake its own file name in its RTL_USER_PROCESS_PARAMETERS block (although PE fails this as well).
Logged
MCTS: Windows Internals
Process Hacker
, a free and open source process viewer.
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12914
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #25 on:
December 29, 2010, 04:14:06 PM »
Quote from: wj32 on December 29, 2010, 03:21:45 PM
The only feature in my biased view that AnVir has over KillSwitch/PH is the bloated and ugly UI. Look at how many icons and custom menus they use. And just like all the other process viewers (aside from Process Explorer) the author of AnVir Task Manager doesn't actually know what he's doing, and thus fails all basic tests like not being fooled when a process tries to fake its own file name in its RTL_USER_PROCESS_PARAMETERS block (although PE fails this as well).
Process Hacker has been written someone who "gets" security! And Comodo's usage of Process Hacker is a testament to that. It is important to understand that KillSwitch is based on a very sound and well architected platform - Process Hacker!
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
wj32
Comodo's Hero
Offline
Posts: 387
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #26 on:
December 29, 2010, 05:17:13 PM »
Well, I'm not really a security person, and I'm not a fan of the "security" industry at all or even the existence of it. Anyway, hope you enjoyed reading my small rant about AnVir. IMHO it's one of the worst process viewers out there, just for its horrible UI.
Logged
MCTS: Windows Internals
Process Hacker
, a free and open source process viewer.
salaficall
Comodo Loves me
Offline
Posts: 192
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #27 on:
December 29, 2010, 05:21:22 PM »
Quote from: Melih on December 29, 2010, 12:50:30 PM
To me: ability to kill all "unknown" processes as long as you have a good whitelist offers a great feature.
Melih
indeed , I totally agree.
comodo's whitelist is superior and it makes the cleaning process with KillSwitch very convenient rather than other task managers that I have to go through all the running processes to find this nasty piece of malware that is compromising the system !!.
On heavily infected systems you can get dozens of evil malware processes running , and sometimes it looks like legitimate processes exactly !!.
so without the comodo's whitelist ( like in anvir ! ) it will be just like searching for a needle in a haystack !!
and above all these features , It has DACS ! built in so u can also check for the unknown processes before terminating them and ruin your system ! , and this is awesome !!
and let me tell u something , it's totally free !
many thanks to melih and the developers team. you guys rock !
Logged
An ounce of prevention is better than a pound of cure
That's why I like Comodo !
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12914
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #28 on:
December 29, 2010, 05:29:53 PM »
Quote from: salaficall on December 29, 2010, 05:21:22 PM
indeed , I totally agree.
comodo's whitelist is superior and it makes the cleaning process with KillSwitch very convenient rather than other task managers that I have to go through all the running processes to find this nasty piece of malware that is compromising the system !!.
On heavily infected systems you can get dozens of evil malware processes running , and sometimes it looks like legitimate processes exactly !!.
so without the comodo's whitelist ( like in anvir ! ) it will be just like searching for a needle in a haystack !!
and above all these features , It has DACS ! built in so u can also check for the unknown processes before terminating them and ruin your system ! , and this is awesome !!
and let me tell u something , it's totally free !
many thanks to melih and the developers team. you guys rock !
Indeed you are very welcome..
I bet you hunt for malware regularly..you understand the pain points like I do
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
arjunpa
Comodo's Hero
Offline
Posts: 392
Iam Cool
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #29 on:
December 29, 2010, 08:47:41 PM »
Melih, It would be nice if u include some tweaks in Killswitch like the ability to 'Enable Task manager', 'Enable access to registry editing tools' etc.. when they are disabled due to malware infection.
Logged
Core i5 750 [at] 2.66 GHz
MSI GD65 Motherboard
2 GB RAM
Sapphire HD 5770 1 GB
Tags:
Pages:
1
[
2
]
3
4
...
6
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.054 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com