Welcome, Guest. Please login or register.
Did you miss your activation email?
May 19, 2013, 01:18:04 PM

Login with username, password and session length

663045 Posts
70580 Topics
145158 Members

Latest Member: cyber33

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
| | |-+  News / Announcements / Feedback - CCE (Moderator: Yanghua Fang)
| | | |-+  Stories of heroism and victory....against malware using KillSwitch :)
« previous next »
Pages: 1 ... 3 4 [5] 6 Go Down Print
Author Topic: Stories of heroism and victory....against malware using KillSwitch :)  (Read 18858 times)
kagun
Left the Forums
Comodo's Hero
*****
Offline Offline

Posts: 1141



« Reply #60 on: May 16, 2011, 06:31:05 AM »

My colleague gave me his PC infected with trojan last night.
It disabled Task Manager, Registry Editor, Safe Mode and System Restore.
Tried HitmanPro with Force Breach. scanned but couldn't clean. Abort.
Tried to install Malwarebytes, get error during arround 50% install. Abort.
Started CCE, updated, full scan, found 125 threats, all related to problem. Cleaned, computer works.
Very old machine, XP SP2, 240MB Ram, 40ish GB HDD... Scan done of over 4 million files in 3 hours.
One false positive [heuristics high] for old printer driver file, submitted as false positive.
Verdict: Awesome!  Thumb Up
Logged
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 11173


Linux is free only if your time is worthless.;-)


« Reply #61 on: May 16, 2011, 06:59:53 AM »

My colleague gave me his PC infected with trojan last night.
It disabled Task Manager, Registry Editor, Safe Mode and System Restore.
Tried HitmanPro with Force Breach. scanned but couldn't clean. Abort.
Tried to install Malwarebytes, get error during arround 50% install. Abort.
Started CCE, updated, full scan, found 125 threats, all related to problem. Cleaned, computer works.
Very old machine, XP SP2, 240MB Ram, 40ish GB HDD... Scan done of over 4 million files in 3 hours.
One false positive [heuristics high] for old printer driver file, submitted as false positive.
Verdict: Awesome!  Thumb Up

Nice!!  Thumb Up Thumb Up Thumb Up It's not half bad, is it?  Wink

Ewen :-)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you can't conform, don't use the forum.
kagun
Left the Forums
Comodo's Hero
*****
Offline Offline

Posts: 1141



« Reply #62 on: May 16, 2011, 07:09:50 AM »

It did the job what was supposed to do  Cool
Logged
Melih
CEO - Comodo
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 12913



WWW
« Reply #63 on: May 16, 2011, 08:20:32 PM »

This is only the start of a one good cleaning product Wink

we will continue to improve it!

Melih
Logged

Tech
Usability Study Member
Comodo's Hero
*****
Offline Offline

Posts: 3024



« Reply #64 on: May 16, 2011, 08:47:40 PM »

Is there a way to test the capabilities of KillSwitch to kill running malware?
I mean, of course, something like disabling the resident antivirus and then running eicar test and kill it by KillSwitch? Is there any other way to test it?
Of course I can test KillSwitch with clean processes. But I can't kill protected processes for instance. KillSwitch does nothing against them.
I'm just thinking what will happen when I try to kill a resistant malware running :Smiley
Logged

avast! team member
Save freeware snapshot technology of Comodo Time Machine. Vote!
kagun
Left the Forums
Comodo's Hero
*****
Offline Offline

Posts: 1141



« Reply #65 on: May 17, 2011, 12:48:47 AM »

Did you try right click>terminator option?
Logged
Tech
Usability Study Member
Comodo's Hero
*****
Offline Offline

Posts: 3024



« Reply #66 on: May 17, 2011, 08:09:52 PM »

Did you try right click>terminator option?
To what? A clean process? It will work for sure.
What can it do against a protected process?
Logged

avast! team member
Save freeware snapshot technology of Comodo Time Machine. Vote!
kagun
Left the Forums
Comodo's Hero
*****
Offline Offline

Posts: 1141



« Reply #67 on: May 18, 2011, 12:47:25 AM »

Go to services and stop avast service....
Then delete service.
Then go to processes and if still running, try again to terminate it.
Logged
JoWa
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2932



« Reply #68 on: May 18, 2011, 10:29:11 AM »

What can it do against a protected process?
Terminate it, the driver is loaded. Wink
Right-click on the process you want to terminate, select Terminator. Run all and post the result here.
Thanks. Smiley
Logged

Ubuntu 13.04, 64-bit | Chrome 27β | Asus P8Z77-M | Intel Core i5 2500K 3,3GHz | 2×4 GB RAM | SSD: OCZ Vertex3 60GB, HDD: 2TB Western Digital Caviar Black | Dell UltraSharp 24" U2410 IPS | Sony MDR-XB1000 | Philips SBC AH1000
Tech
Usability Study Member
Comodo's Hero
*****
Offline Offline

Posts: 3024



« Reply #69 on: May 18, 2011, 08:23:59 PM »

Go to services and stop avast service....
Then delete service.
Then go to processes and if still running, try again to terminate it.
Eh eh... It's not that easy... You can't terminate malware that easy... as you can't stop avast that easy...
Windows cannot stop avast service without user interaction. Malware can block this option...
Logged

avast! team member
Save freeware snapshot technology of Comodo Time Machine. Vote!
Tech
Usability Study Member
Comodo's Hero
*****
Offline Offline

Posts: 3024



« Reply #70 on: May 18, 2011, 08:32:37 PM »

Terminate it, the driver is loaded. Wink
Right-click on the process you want to terminate, select Terminator. Run all and post the result here.
Thanks. Smiley
With driver loaded, you can't terminate any type of malware as you can't terminate the antivirus (that easy)...
I'm laughing on "process is terminated" message... The first run could only win at stage CH1. Then running each test individually get the "ok" status... But the process stays there, running, not a signal of being really killed.
Logged

avast! team member
Save freeware snapshot technology of Comodo Time Machine. Vote!
languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3944



« Reply #71 on: May 18, 2011, 09:03:19 PM »

I killed avast pretty easy. What I did is that I killed the UI first using terminator, then I used terminator to kill the service. It restarted a few times but after killing it two or three times it stopped restarting and it was gone for good.
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
JoWa
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2932



« Reply #72 on: May 18, 2011, 11:51:38 PM »

Thanks for the screenshot. Actually (Not available) for TP3 and TT3 indicates that the driver is not loaded.
From wj32, developer of Process Hacker:
You can clearly see "(Not available)" next to TP3 and TT3, which indicates the driver isn't loaded or can't be connected to.
Logged

Ubuntu 13.04, 64-bit | Chrome 27β | Asus P8Z77-M | Intel Core i5 2500K 3,3GHz | 2×4 GB RAM | SSD: OCZ Vertex3 60GB, HDD: 2TB Western Digital Caviar Black | Dell UltraSharp 24" U2410 IPS | Sony MDR-XB1000 | Philips SBC AH1000
Tech
Usability Study Member
Comodo's Hero
*****
Offline Offline

Posts: 3024



« Reply #73 on: May 20, 2011, 01:56:25 PM »

I killed avast pretty easy. What I did is that I killed the UI first using terminator, then I used terminator to kill the service. It restarted a few times but after killing it two or three times it stopped restarting and it was gone for good.
Mine happened the same. avast indeed is being killed if you run more than once.
Logged

avast! team member
Save freeware snapshot technology of Comodo Time Machine. Vote!
knk2006
Comodo's Hero
*****
Offline Offline

Posts: 539


« Reply #74 on: May 22, 2011, 02:09:50 PM »

I haven't seen a better killer than the terminator in D+, I've killed kaspersky with it Smiley , I would assume Avast! will fail easily...
Logged
Tags:
Pages: 1 ... 3 4 [5] 6 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.05 seconds with 20 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com