Welcome, Guest. Please login or register.
Did you miss your activation email?
May 16, 2012, 04:19:03 PM

Login with username, password and session length

594598 Posts
63097 Topics
134535 Members

Latest Member: huskyclaw

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  News / Announcements / Feedback - CIS
| | | |-+  bypass sandbox (partially limited)
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: bypass sandbox (partially limited)  (Read 7239 times)
a256886572008
Comodo's Hero
*****
Offline Offline

Posts: 371



« on: November 13, 2010, 03:06:48 AM »

System: XP SP3

Configuration: Internet Security

Mode: Safe mode

sandbox:enabled

Treat unrecognized files as: partially limited

Automatically quarantine threats found during scannig

GMER:



defense+  logs:

2010-11-13 15:47:45   C:\Documents and Settings\Roger\桌面\virus\1289589994\1289589994.exe   Sandboxed As   Partially Limited  

2010-11-13 15:47:46   C:\Documents and Settings\Roger\桌面\virus\1289589994\1289589994.exe   Modify File   C:\Documents and Settings\Roger\Local Settings\Temp\564.tmp  

2010-11-13 15:47:53   C:\Documents and Settings\Roger\桌面\virus\1289589994\1289589994.exe   Modify Key   HKLM\SYSTEM\ControlSet001\Control\Session Manager\PendingFileRenameOperations  

2010-11-13 15:49:01   C:\Documents and Settings\Roger\桌面\virus\1289589994\1289589994.exe   Scanned Online and Found Malicious      

-------------------------------------
antivirus logs:

2010-11-13 15:49:01   C:\Documents and Settings\Roger\桌面\virus\1289589994\1289589994.exe   CloudBehavior.Suspicious[at]1   Detect   Success  

2010-11-13 15:49:01   C:\Documents and Settings\Roger\桌面\virus\1289589994\1289589994.exe   CloudBehavior.Suspicious[at]1   Quarantine   Success

------------------------------------
CIMA:
http://camas.comodo.com/cgi-bin/submit?file=4f63010477941a57f8e2e997b7c40136fc7a16dc2a2eafe86e99986cbb89075f
« Last Edit: November 13, 2010, 04:07:21 AM by a256886572008 » Logged
a256886572008
Comodo's Hero
*****
Offline Offline

Posts: 371



« Reply #1 on: November 13, 2010, 03:15:19 AM »

OA block this action.

Logged
languy99
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 3931



« Reply #2 on: November 13, 2010, 03:22:47 AM »

You should have gotten a pop up from CIS regarding a com interface asking for spooler access. Can you give me the file to test.
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
a256886572008
Comodo's Hero
*****
Offline Offline

Posts: 371



« Reply #3 on: November 13, 2010, 03:26:03 AM »

You should have gotten a pop up from CIS regarding a com interface asking for spooler access. Can you give me the file to test.


The virus was  sandboxed automatically by COMODO.

There is no pop up from CIS.
Logged
languy99
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 3931



« Reply #4 on: November 13, 2010, 03:41:22 AM »

I just tested stock install. Got an alert from D+ for a pseudo-com interface wanting to access windows print spooler service. Clicked block.

Then I get a AV alert from the cloud.

Lastly and alert from the firewall stating an malicious item wants to access the internet. 
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
a256886572008
Comodo's Hero
*****
Offline Offline

Posts: 371



« Reply #5 on: November 13, 2010, 04:21:04 AM »

I just tested stock install. Got an alert from D+ for a pseudo-com interface wanting to access windows print spooler service. Clicked block.

Then I get a AV alert from the cloud.

Lastly and alert from the firewall stating an malicious item wants to access the internet.  

Does CIS sandbox the virus with partially limited in your computer?
Logged
a256886572008
Comodo's Hero
*****
Offline Offline

Posts: 371



« Reply #6 on: November 13, 2010, 04:32:38 AM »

I test the virus again.

double click on the virus

1.Treat unrecognized files as partially limited

failed to block the action of the virus





2.Treat unrecognized files as limited

block the action of the virus successfully





« Last Edit: November 13, 2010, 06:41:22 AM by a256886572008 » Logged
tommymacangel
Comodo Loves me
****
Offline Offline

Posts: 129


« Reply #7 on: November 13, 2010, 04:54:00 AM »

IMO maybe they must add an heuristic danger indice for unknown PE like KIS  Thumb Up

Exemple: indice less 15 => "autosandboxed" at "partially limited"
indice 15-35 => limited
etc
50-80=> unstrusted
80-100=> blocked

Executing all unknwon PE with the same limitations is not the best thing for me, bit it's only my opinion Wink
Logged
tommymacangel
Comodo Loves me
****
Offline Offline

Posts: 129


« Reply #8 on: November 13, 2010, 04:56:15 AM »

a256886572008, could you test this sample on x64? i'm curious Thumb Up
Logged
a256886572008
Comodo's Hero
*****
Offline Offline

Posts: 371



« Reply #9 on: November 13, 2010, 05:23:02 AM »

a256886572008, could you test this sample on x64? i'm curious Thumb Up

My computer is not a x64 system. Sad
Logged
Syl
Comodo's Hero
*****
Offline Offline

Posts: 509



« Reply #10 on: November 13, 2010, 06:03:41 AM »

seems like another problem with x64  ^^;
Logged

Router: WRT54GL with TomatoUSB k24 VPN with Adblock
Windows 7 x64: CIS 5, Quick Start Guide
Luc[y]
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 746



« Reply #11 on: November 13, 2010, 06:05:20 AM »

all can bypass comodo, it isnt a big issues  Roll Eyes
Logged
a256886572008
Comodo's Hero
*****
Offline Offline

Posts: 371



« Reply #12 on: November 13, 2010, 06:38:54 AM »

Treat unrecognized files as partially limited

1.right click on the virus



2.choose "Run in COMODO sandbox"

3.COMODO blocks the action of the virus successfully.

defense+  logs:
2010-11-13 19:27:24   C:\Documents and Settings\Roger\桌面\virus\1289589994\1289589994.exe   Direct Disk Access   physicaldrive0   

firewall logs:
2010-11-13 19:27:19   C:\Documents and Settings\Roger\桌面\virus\1289589994\1289589994.exe   Asked   Out   TCP   114.44.236.161   44807   95.143.193.138   20480   
Logged
languy99
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 3931



« Reply #13 on: November 13, 2010, 11:52:32 AM »

Does CIS sandbox the virus with partially limited in your computer?


yes it does. I don't know what you are doing but something is wrong with your install or settings. It is easily blocked in my computer with a stock install. I would check your D+ to make sure nothing is added to trusted lists and such.

Actually me and Egemen specifically worked on this issue to figure it out. What version of comodo are you running?
« Last Edit: November 13, 2010, 11:54:25 AM by languy99 » Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
Syl
Comodo's Hero
*****
Offline Offline

Posts: 509



« Reply #14 on: November 13, 2010, 12:28:17 PM »

languy99, do you use a 64 bits OS ?
Logged

Router: WRT54GL with TomatoUSB k24 VPN with Adblock
Windows 7 x64: CIS 5, Quick Start Guide
Tags:
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.07 seconds with 20 queries.
Powered by SMF 1.1.16 | SMF © 2006, Simple Machines Design by 7dana.com