Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 21, 2013, 01:31:26 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663320
Posts
70517
Topics
145182
Members
Latest Member:
danielcarpenter
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
News / Announcements / Feedback - CCE
(Moderator:
Yanghua Fang
)
Stories of heroism and victory....against malware using KillSwitch :)
« previous
next »
Pages:
1
2
3
[
4
]
5
6
Author
Topic: Stories of heroism and victory....against malware using KillSwitch :) (Read 18908 times)
languy99
Global Moderator
Comodo's Hero
Offline
Posts: 3943
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #45 on:
January 04, 2011, 04:01:51 PM »
simple, kill the malware with killswitch. Then do a custom scan with CCE and select everything other then scan memory ( so you don't require a restart) and don't scan for viruses ( because we want to scan for viruses). This should let you scan the system.
Logged
http://www.youtube.com/languy99
Software Reviews for all.
Follow me on Twitter
http://twitter.com/#!/languy99
kagun
Left the Forums
Comodo's Hero
Offline
Posts: 1141
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #46 on:
January 04, 2011, 04:12:46 PM »
Well, too late for that now....
Quote from: languy99 on January 04, 2011, 04:01:51 PM
simple, kill the malware with killswitch.
Solid copy
Quote from: languy99 on January 04, 2011, 04:01:51 PM
Then do a custom scan with CCE and select everything other then scan memory ( so you don't require a restart)
Lima Charlie
Quote from: languy99 on January 04, 2011, 04:01:51 PM
and don't scan for viruses( because we want to scan for viruses)
This part I don't understand well...
Logged
languy99
Global Moderator
Comodo's Hero
Offline
Posts: 3943
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #47 on:
January 04, 2011, 04:17:38 PM »
check everything in custom scan except "scan memory" and "don't scan for viruses"
Logged
http://www.youtube.com/languy99
Software Reviews for all.
Follow me on Twitter
http://twitter.com/#!/languy99
kagun
Left the Forums
Comodo's Hero
Offline
Posts: 1141
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #48 on:
January 04, 2011, 04:20:16 PM »
Got it....
Logged
wj32
Comodo's Hero
Offline
Posts: 387
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #49 on:
January 04, 2011, 05:00:55 PM »
Quote from: GakunGak on January 04, 2011, 03:53:55 PM
Yeah, but "technical" term is called patching ;-)
Well, I just wanted to know how the malware was actually doing it in your case, since your use of the term "patching" was quite vague.
Logged
MCTS: Windows Internals
Process Hacker
, a free and open source process viewer.
kagun
Left the Forums
Comodo's Hero
Offline
Posts: 1141
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #50 on:
January 04, 2011, 05:05:02 PM »
I'm not malware hunter, but I figure it is adding registry key to make EXE association with himself, makes a tie with it....
The fix could be here
http://www.dougknox.com/xp/file_assoc.htm
Logged
trscsaeg
Comodo's Hero
Offline
Posts: 1156
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #51 on:
January 28, 2011, 01:09:36 AM »
Quote from: Melih on December 29, 2010, 09:42:29 AM
Not sure they have a whitelist like ours or have the ability to "show untrusted processes" only. (patented)..
http://www.anvir.com/
has a bad web of trust rating. it says this site distributes rougeware. please check out this company thoroughly before whitelisting this company.
see the full raiting here:
http://www.mywot.com/en/scorecard/anvir.com#comment
click the long comments to extend them an show the full comment. if it's in another language hit the translate button under the comment. you will have to extend the long comments to see the translate button under the comment
Logged
HeffeD
Global Moderator
Comodo's Hero
Offline
Posts: 6568
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #52 on:
January 28, 2011, 11:17:19 AM »
Quote from: trscsaeg on January 28, 2011, 01:09:36 AM
http://www.anvir.com/
has a bad web of trust rating. it says this site distributes rougeware. please check out this company thoroughly before whitelisting this company.
see the full raiting here:
http://www.mywot.com/en/scorecard/anvir.com#comment
click the long comments to extend them an show the full comment. if it's in another language hit the translate button under the comment. you will have to extend the long comments to see the translate button under the comment
Actually, the WOT rating is good...
Yes, a few users have negative comments, but like Wikipedia, since absolutely anyone can give input, you need to view WOT with a certain amount of skepticism.
URLVoid only shows 1 detection out of 16 scanners.
Logged
Please read the
Forum Policy
!
Breast Cancer Awareness
American Cancer Society
trscsaeg
Comodo's Hero
Offline
Posts: 1156
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #53 on:
February 03, 2011, 06:43:54 PM »
Quote from: HeffeD on January 28, 2011, 11:17:19 AM
Actually, the WOT rating is good...
Yes, a few users have negative comments, but like Wikipedia, since absolutely anyone can give input, you need to view WOT with a certain amount of skepticism.
URLVoid only shows 1 detection out of 16 scanners.
i'm not saying wot is accurate. i'm just saying it should be checked out thoroughly brfore being whitelisted. a while back something called safeapp llc got put on the whitelist and if you google that, you will see a lot of safeapp sites with different names distributing malware. i just want comodo to get more aggressive with it's whitelisting process
Logged
jay2007tech
Malware Research Group
Global Moderator
Comodo's Hero
Offline
Posts: 1795
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #54 on:
February 24, 2011, 03:41:05 PM »
Quote
I'm not malware hunter
I like to play with malware outside of a sandbox and virtual machine. sandbox and virtual Aware malware got nothing against my machines. Malware always show their face when I run it.
Logged
It's hard being a crooked Admin when the files won't pass an md5checksum test. But like any other good crooked Admin it can be done, it just takes time(and lots of it) and a few aspirins
icr
Newbie
Offline
Posts: 18
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #55 on:
March 06, 2011, 12:16:01 AM »
I was testing CCE and KillSwitch with some malware samples, I installed this rouge and after reboot it won't allow anything to be executed.
Hitman Pro : failed (renaming it also failed)
SAS Portable : failed (renaming did help me bypass the rogue but eventually it detected and abnormally terminated the process)
CCE : failed
GMER : partially failed coz sometimes it got caught by that rouge, after successful attempts I browsed through running processes but some how the target rogue process was not terminating.
KillSwitch : With name KillSwitch.exe it didn't get executed so I renamed with some random name and after some attempts it got executed and I swiftly executed the terminator option for the target rogue process and then I manually deleted the malware.
Logged
Arkose
Comodo Member
Offline
Posts: 43
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #56 on:
March 06, 2011, 01:53:26 AM »
Quote from: icr on March 06, 2011, 12:16:01 AM
I was testing CCE and KillSwitch with some malware samples, I installed this rouge and after reboot it won't allow anything to be executed.
Hitman Pro : failed (renaming it also failed)
To get around blocking with Hitman Pro you just need to launch it in
Force Breach mode
. To do this hold down left ctrl before starting Hitman Pro and keep it held down (including during the UAC prompt) until the Hitman Pro window appears. I have yet to find a sample that Force Breach can't get past.
Rogues usually don't run while in Safe Mode so performing the scan there is an option for the other products.
Logged
icr
Newbie
Offline
Posts: 18
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #57 on:
March 06, 2011, 11:00:53 AM »
Quote from: Arkose on March 06, 2011, 01:53:26 AM
To get around blocking with Hitman Pro you just need to launch it in
Force Breach mode
. To do this hold down left ctrl before starting Hitman Pro and keep it held down (including during the UAC prompt) until the Hitman Pro window appears. I have yet to find a sample that Force Breach can't get past.
Rogues usually don't run while in Safe Mode so performing the scan there is an option for the other products.
Thanks I never tried the force breach mode though, and regarding that rogue it did got executed in safe mode also
Logged
Graham1
Comodo's Hero
Offline
Posts: 1511
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #58 on:
April 27, 2011, 02:47:23 PM »
Finally got to see KillSwitch in action today
. Had a computer infected with "My Security Shield" (malware which prompts for payment to clean system, which isn't really infected
).
So I thought I would give KS a go having previously done a full scan with McAfee VirusScan with up-to-date definitions which didn't detect anything
. KS found and highlighted the rogue process in memory, I pressed delete and voila... no more malware
. Thank you KillSwitch
.
Logged
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12913
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #59 on:
April 27, 2011, 09:56:58 PM »
Quote from: Graham1 on April 27, 2011, 02:47:23 PM
Finally got to see KillSwitch in action today
. Had a computer infected with "My Security Shield" (malware which prompts for payment to clean system, which isn't really infected
).
So I thought I would give KS a go having previously done a full scan with McAfee VirusScan with up-to-date definitions which didn't detect anything
. KS found and highlighted the rogue process in memory, I pressed delete and voila... no more malware
. Thank you KillSwitch
.
thats exactly why KillSwitch was designed
thanks for sharing that.
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
Tags:
Pages:
1
2
3
[
4
]
5
6
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.067 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com