Welcome, Guest. Please login or register.
Did you miss your activation email?
May 24, 2013, 04:32:53 PM

Login with username, password and session length

663993 Posts
70623 Topics
153560 Members

Latest Member: wsjdmydle

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
| | |-+  News / Announcements / Feedback - CCE (Moderator: Yanghua Fang)
| | | |-+  Stories of heroism and victory....against malware using KillSwitch :)
« previous next »
Pages: 1 2 3 [4] 5 6 Go Down Print
Author Topic: Stories of heroism and victory....against malware using KillSwitch :)  (Read 19157 times)
languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3943



« Reply #45 on: January 04, 2011, 04:01:51 PM »

simple, kill the malware with killswitch. Then do a custom scan with CCE and select everything other then scan memory ( so you don't require a restart) and don't scan for viruses ( because we want to scan for viruses). This should let you scan the system.
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
kagun
Left the Forums
Comodo's Hero
*****
Offline Offline

Posts: 1141



« Reply #46 on: January 04, 2011, 04:12:46 PM »

Well, too late for that now.... Embarrassed
simple, kill the malware with killswitch.
Solid copy
Then do a custom scan with CCE and select everything other then scan memory ( so you don't require a restart)
Lima Charlie
and don't scan for viruses( because we want to scan for viruses)
This part I don't understand well...
Logged
languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3943



« Reply #47 on: January 04, 2011, 04:17:38 PM »

check everything in custom scan except "scan memory" and "don't scan for viruses"
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
kagun
Left the Forums
Comodo's Hero
*****
Offline Offline

Posts: 1141



« Reply #48 on: January 04, 2011, 04:20:16 PM »

Got it....  Thumb Up Thumb Up Thumb Up
Logged
wj32
Comodo's Hero
*****
Offline Offline

Posts: 387



WWW
« Reply #49 on: January 04, 2011, 05:00:55 PM »

Yeah, but "technical" term is called patching ;-)

Well, I just wanted to know how the malware was actually doing it in your case, since your use of the term "patching" was quite vague. Wink
Logged

MCTS: Windows Internals
Process Hacker, a free and open source process viewer.
kagun
Left the Forums
Comodo's Hero
*****
Offline Offline

Posts: 1141



« Reply #50 on: January 04, 2011, 05:05:02 PM »

I'm not malware hunter, but I figure it is adding registry key to make EXE association with himself, makes a tie with it....
The fix could be here  Wink
http://www.dougknox.com/xp/file_assoc.htm
Logged
trscsaeg
Comodo's Hero
*****
Offline Offline

Posts: 1156


« Reply #51 on: January 28, 2011, 01:09:36 AM »

Not sure they have a whitelist like ours or have the ability to "show untrusted processes" only. (patented)..



http://www.anvir.com/ has a bad web of trust rating. it says this site distributes rougeware. please check out this company thoroughly  before whitelisting this company.

see the full raiting here:

http://www.mywot.com/en/scorecard/anvir.com#comment

click the long comments to extend them an show the full comment. if it's in another language hit the translate button under the comment. you will have to extend the long comments to see the translate button under the comment
Logged
HeffeD
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6573



« Reply #52 on: January 28, 2011, 11:17:19 AM »

http://www.anvir.com/ has a bad web of trust rating. it says this site distributes rougeware. please check out this company thoroughly  before whitelisting this company.

see the full raiting here:

http://www.mywot.com/en/scorecard/anvir.com#comment

click the long comments to extend them an show the full comment. if it's in another language hit the translate button under the comment. you will have to extend the long comments to see the translate button under the comment

Actually, the WOT rating is good...

Yes, a few users have negative comments, but like Wikipedia, since absolutely anyone can give input, you need to view WOT with a certain amount of skepticism.

URLVoid only shows 1 detection out of 16 scanners.
Logged

trscsaeg
Comodo's Hero
*****
Offline Offline

Posts: 1156


« Reply #53 on: February 03, 2011, 06:43:54 PM »

Actually, the WOT rating is good...

Yes, a few users have negative comments, but like Wikipedia, since absolutely anyone can give input, you need to view WOT with a certain amount of skepticism.

URLVoid only shows 1 detection out of 16 scanners.

i'm not saying wot is accurate. i'm just saying it should be checked out thoroughly brfore being whitelisted. a while back something called safeapp llc got put on the whitelist and if you google that, you will see a lot of safeapp sites with different names distributing malware. i just want comodo to get more aggressive with it's whitelisting process
Logged
jay2007tech
Malware Research Group
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1795


« Reply #54 on: February 24, 2011, 03:41:05 PM »

Quote
I'm not malware hunter
I like to play with malware outside of a sandbox and virtual machine.  sandbox and virtual Aware malware got nothing against my machines.  Malware always show their face when I run it.  Shocked Grin
Logged

It's hard being a crooked Admin when the files won't pass an md5checksum test.  But like any other good crooked Admin it can be done, it just takes time(and lots of it) and a few aspirins
icr
Newbie
*
Offline Offline

Posts: 18


« Reply #55 on: March 06, 2011, 12:16:01 AM »

I was testing CCE and KillSwitch with some malware samples, I installed this rouge and after reboot it won't allow anything to be executed.
Hitman Pro : failed (renaming it also failed)

SAS Portable : failed (renaming did help me bypass the rogue but eventually it detected and abnormally terminated the process)

CCE : failed

GMER : partially failed coz sometimes it got caught by that rouge, after successful attempts I browsed through running processes but some how the target rogue process was not terminating.

KillSwitch : With name KillSwitch.exe it didn't get executed so I renamed with some random name and after some attempts it got executed and I swiftly executed the terminator option for the target rogue process and then I manually deleted the malware. Wink
Logged
Arkose
Comodo Member
**
Offline Offline

Posts: 43


« Reply #56 on: March 06, 2011, 01:53:26 AM »

I was testing CCE and KillSwitch with some malware samples, I installed this rouge and after reboot it won't allow anything to be executed.
Hitman Pro : failed (renaming it also failed)
To get around blocking with Hitman Pro you just need to launch it in Force Breach mode. To do this hold down left ctrl before starting Hitman Pro and keep it held down (including during the UAC prompt) until the Hitman Pro window appears. I have yet to find a sample that Force Breach can't get past.

Rogues usually don't run while in Safe Mode so performing the scan there is an option for the other products.
Logged
icr
Newbie
*
Offline Offline

Posts: 18


« Reply #57 on: March 06, 2011, 11:00:53 AM »

To get around blocking with Hitman Pro you just need to launch it in Force Breach mode. To do this hold down left ctrl before starting Hitman Pro and keep it held down (including during the UAC prompt) until the Hitman Pro window appears. I have yet to find a sample that Force Breach can't get past.

Rogues usually don't run while in Safe Mode so performing the scan there is an option for the other products.

Thanks I never tried the force breach mode though, and regarding that rogue it did got executed in safe mode also Wink
Logged
Graham1
Comodo's Hero
*****
Offline Offline

Posts: 1512



« Reply #58 on: April 27, 2011, 02:47:23 PM »

Finally got to see KillSwitch in action today Grin. Had a computer infected with "My Security Shield" (malware which prompts for payment to clean system, which isn't really infected Evil ).

So I thought I would give KS a go having previously done a full scan with McAfee VirusScan with up-to-date definitions which didn't detect anything embarassed. KS found and highlighted the rogue process in memory, I pressed delete and voila... no more malware Smiley. Thank you KillSwitch Thumb Up.

Smiley
Logged
Melih
CEO - Comodo
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 12914



WWW
« Reply #59 on: April 27, 2011, 09:56:58 PM »

Finally got to see KillSwitch in action today Grin. Had a computer infected with "My Security Shield" (malware which prompts for payment to clean system, which isn't really infected Evil ).

So I thought I would give KS a go having previously done a full scan with McAfee VirusScan with up-to-date definitions which didn't detect anything embarassed. KS found and highlighted the rogue process in memory, I pressed delete and voila... no more malware Smiley. Thank you KillSwitch Thumb Up.

Smiley

thats exactly why KillSwitch was designed Wink

thanks for sharing that.
Logged

Tags:
Pages: 1 2 3 [4] 5 6 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.558 seconds with 20 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com