Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 26, 2013, 02:16:39 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
664102
Posts
70639
Topics
145273
Members
Latest Member:
Komododragon1
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
News / Announcements / Feedback - CCE
(Moderator:
Yanghua Fang
)
Stories of heroism and victory....against malware using KillSwitch :)
« previous
next »
Pages:
1
...
3
4
[
5
]
6
Author
Topic: Stories of heroism and victory....against malware using KillSwitch :) (Read 19229 times)
kagun
Left the Forums
Comodo's Hero
Offline
Posts: 1141
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #60 on:
May 16, 2011, 06:31:05 AM »
My colleague gave me his PC infected with trojan last night.
It disabled Task Manager, Registry Editor, Safe Mode and System Restore.
Tried HitmanPro with Force Breach. scanned but couldn't clean. Abort.
Tried to install Malwarebytes, get error during arround 50% install. Abort.
Started CCE, updated, full scan, found 125 threats, all related to problem. Cleaned, computer works.
Very old machine, XP SP2, 240MB Ram, 40ish GB HDD... Scan done of over 4 million files in 3 hours.
One false positive [heuristics high] for old printer driver file, submitted as false positive.
Verdict: Awesome!
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 11173
Linux is free only if your time is worthless.;-)
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #61 on:
May 16, 2011, 06:59:53 AM »
Quote from: GakunGak on May 16, 2011, 06:31:05 AM
My colleague gave me his PC infected with trojan last night.
It disabled Task Manager, Registry Editor, Safe Mode and System Restore.
Tried HitmanPro with Force Breach. scanned but couldn't clean. Abort.
Tried to install Malwarebytes, get error during arround 50% install. Abort.
Started CCE, updated, full scan, found 125 threats, all related to problem. Cleaned, computer works.
Very old machine, XP SP2, 240MB Ram, 40ish GB HDD... Scan done of over 4 million files in 3 hours.
One false positive [heuristics high] for old printer driver file, submitted as false positive.
Verdict: Awesome!
Nice!!
It's not half bad, is it?
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you can't conform, don't use the forum.
kagun
Left the Forums
Comodo's Hero
Offline
Posts: 1141
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #62 on:
May 16, 2011, 07:09:50 AM »
It did the job what was supposed to do
Logged
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12914
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #63 on:
May 16, 2011, 08:20:32 PM »
This is only the start of a one good cleaning product
we will continue to improve it!
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #64 on:
May 16, 2011, 08:47:40 PM »
Is there a way to test the capabilities of KillSwitch to kill running malware?
I mean, of course, something like disabling the resident antivirus and then running eicar test and kill it by KillSwitch? Is there any other way to test it?
Of course I can test KillSwitch with clean processes. But I can't kill protected processes for instance. KillSwitch does nothing against them.
I'm just thinking what will happen when I try to kill a resistant malware running :
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
kagun
Left the Forums
Comodo's Hero
Offline
Posts: 1141
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #65 on:
May 17, 2011, 12:48:47 AM »
Did you try right click>terminator option?
Logged
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #66 on:
May 17, 2011, 08:09:52 PM »
Quote from: GakunGak on May 17, 2011, 12:48:47 AM
Did you try right click>terminator option?
To what? A clean process? It will work for sure.
What can it do against a protected process?
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
kagun
Left the Forums
Comodo's Hero
Offline
Posts: 1141
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #67 on:
May 18, 2011, 12:47:25 AM »
Go to services and stop avast service....
Then delete service.
Then go to processes and if still running, try again to terminate it.
Logged
JoWa
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 2935
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #68 on:
May 18, 2011, 10:29:11 AM »
Quote from: Tech on May 17, 2011, 08:09:52 PM
What can it do against a protected process?
Terminate it, the driver is loaded.
Right-click on the process you want to terminate, select
Terminator
. Run all and post the result here.
Thanks.
Logged
Ubuntu 13.04, 64-bit | Chrome 27β | Asus P8Z77-M | Intel Core i5 2500K 3,3GHz | 2×4 GB RAM | SSD: OCZ Vertex3 60GB, HDD: 2TB Western Digital Caviar Black | Dell UltraSharp 24" U2410 IPS | Sony MDR-XB1000 | Philips SBC AH1000
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #69 on:
May 18, 2011, 08:23:59 PM »
Quote from: GakunGak on May 18, 2011, 12:47:25 AM
Go to services and stop avast service....
Then delete service.
Then go to processes and if still running, try again to terminate it.
Eh eh... It's not that easy... You can't terminate malware that easy... as you can't stop avast that easy...
Windows cannot stop avast service without user interaction. Malware can block this option...
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #70 on:
May 18, 2011, 08:32:37 PM »
Quote from: JoWa on May 18, 2011, 10:29:11 AM
Terminate it, the driver is loaded.
Right-click on the process you want to terminate, select
Terminator
. Run all and post the result here.
Thanks.
With driver loaded, you can't terminate any type of malware as you can't terminate the antivirus (that easy)...
I'm laughing on "process is terminated" message... The first run could only win at stage CH1. Then running each test individually get the "ok" status... But the process stays there, running, not a signal of being really killed.
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
languy99
Global Moderator
Comodo's Hero
Offline
Posts: 3943
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #71 on:
May 18, 2011, 09:03:19 PM »
I killed avast pretty easy. What I did is that I killed the UI first using terminator, then I used terminator to kill the service. It restarted a few times but after killing it two or three times it stopped restarting and it was gone for good.
Logged
http://www.youtube.com/languy99
Software Reviews for all.
Follow me on Twitter
http://twitter.com/#!/languy99
JoWa
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 2935
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #72 on:
May 18, 2011, 11:51:38 PM »
Thanks for the screenshot. Actually
(Not available)
for TP3 and TT3 indicates that the driver is
not
loaded.
From wj32, developer of Process Hacker:
Quote from: wj32 on March 08, 2011, 03:47:56 AM
You can clearly see "(Not available)" next to TP3 and TT3, which indicates the driver isn't loaded or can't be connected to.
Logged
Ubuntu 13.04, 64-bit | Chrome 27β | Asus P8Z77-M | Intel Core i5 2500K 3,3GHz | 2×4 GB RAM | SSD: OCZ Vertex3 60GB, HDD: 2TB Western Digital Caviar Black | Dell UltraSharp 24" U2410 IPS | Sony MDR-XB1000 | Philips SBC AH1000
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #73 on:
May 20, 2011, 01:56:25 PM »
Quote from: languy99 on May 18, 2011, 09:03:19 PM
I killed avast pretty easy. What I did is that I killed the UI first using terminator, then I used terminator to kill the service. It restarted a few times but after killing it two or three times it stopped restarting and it was gone for good.
Mine happened the same. avast indeed is being killed if you run more than once.
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
knk2006
Comodo's Hero
Offline
Posts: 539
Re: Stories of heroism and victory....against malware using KillSwitch :)
«
Reply #74 on:
May 22, 2011, 02:09:50 PM »
I haven't seen a better killer than the terminator in D+, I've killed kaspersky with it
, I would assume Avast! will fail easily...
Logged
Tags:
Pages:
1
...
3
4
[
5
]
6
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.052 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com