Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 23, 2013, 06:12:58 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663712
Posts
70576
Topics
145218
Members
Latest Member:
smith1989
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
News / Announcements / Feedback - CIS
Comodo 5.8 bypassed by trojan GPCODE
« previous
next »
Pages:
[
1
]
2
3
...
6
Author
Topic: Comodo 5.8 bypassed by trojan GPCODE (Read 25034 times)
acafacaa
Newbie
Offline
Posts: 16
Comodo 5.8 bypassed by trojan GPCODE
«
on:
October 17, 2011, 09:35:24 AM »
I made a test today and uploaded to youtube:
http://www.youtube.com/watch?v=fYM8f3HXAXk&feature=channel_video_title
I am a fun of Comodo,but it seems like sandbox and defense + had been bypassed by Trojan.Win32 Gpcode
Logged
RejZoR
Comodo's Hero
Offline
Posts: 1045
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #1 on:
October 17, 2011, 09:58:26 AM »
I've experienced the same thing with screen lock ransomwares. Aparently CIS 5.8 is not reliable at all. Something that's not exactly acceptable in security field...
Logged
Siketa
Comodo's Hero
Online
Posts: 3147
ZIG ZAG
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #2 on:
October 17, 2011, 10:02:33 AM »
Egemen, I think you should do something about those two threats...
Logged
a256886572008
Star Group
Comodo's Hero
Offline
Posts: 781
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #3 on:
October 17, 2011, 10:12:47 AM »
Quote from: siketa on October 17, 2011, 10:02:33 AM
Egemen, I think you should do something about those two threats...
Only the file system virtualization can protect against this malware.
Logged
Chiron
Global Moderator
Comodo's Hero
Online
Posts: 5578
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #4 on:
October 17, 2011, 10:47:43 AM »
Can you please set up CIS following these rules:
http://www.techsupportalert.com/content/how-install-comodo-firewall.htm
ignoring the antivirus and see if it's protected?
Thanks.
Logged
How To Install Comodo Firewall
How To Stay Safe While Online
a256886572008
Star Group
Comodo's Hero
Offline
Posts: 781
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #5 on:
October 17, 2011, 11:23:46 AM »
Quote from: Chiron on October 17, 2011, 10:47:43 AM
Can you please set up CIS following these rules:
http://www.techsupportalert.com/content/how-install-comodo-firewall.htm
ignoring the antivirus and see if it's protected?
Thanks.
CIS auto sandbox can block the malware by adding one rule to the protected files and folders.
?:\*
Logged
morphiusz
Star Group
Comodo's Hero
Offline
Posts: 2196
Comodo's śmieć :)
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #6 on:
October 17, 2011, 11:45:15 AM »
But it will cause many popups.
It's better to add "\Device\KsecDD"
I proposed it to Comodo but they didn't add that
«
Last Edit: October 17, 2011, 11:46:54 AM by morphiusz
»
Logged
kail
Mostly Benevolent
Global Moderator
Comodo's Hero
Offline
Posts: 10743
The future is much like the present, only longer.
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #7 on:
October 17, 2011, 11:53:36 AM »
Quote from: morphiusz on October 17, 2011, 11:45:15 AM
.. It's better to add "\Device\KsecDD"
I proposed it to Comodo but they didn't add that
Was any reason given?
edit: Never mind, I found his concern..
Quote from: egemen on August 30, 2011, 04:17:04 PM
It can be used by many legitimate apps frequently i.e. everytime they are executed. I am not sure.,
«
Last Edit: October 17, 2011, 11:57:56 AM by kail
»
Logged
System Details: W7x64U with CIS 6, Firefox 20, IceDragon 20 & Becky! 2.65
Forum Policy
.
____
I don't know what weapons countries might use to fight World War III, but wars after that will be fought with sticks and stones. Einstein
ComoJust
Comodo's Hero
Offline
Posts: 266
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #8 on:
October 17, 2011, 11:54:35 AM »
Hi the GPCODE is a known issue.
Here is what egemen said about this a while back. Unfortunately we will have to wait for v6 for a permanent fix.
Quote
Hi Guys,
Let me comment on this one more time. First of all, if configured, CIS can very well protect against this and any other threats proactively.
First lets see what this gpcode does: It gets to the users computer drive by download and searches for the files in users harddisk. It then encrypts all picture and text files i.e. damages some non-OS-essential files.
Is this a threat to the user ? YES!
Is this a real threat to be prevented ? YES!
Does CIS prevent against this now? YES!
Then how does COMODO protect against this BY DEFAULT. By default, antivirus detection is enough to detect gpcode and any of its variants. Lets not make false comments by saying CIS does not protect its users against gpcode. CIS DOES prevent against the REAL threat wih its antivirus right now.
Now lets talk about preventing this proactively.
Is there a way to configure CIS to prevent this proactively? YES.
Method 1: Add you sensitive files/folders to CIS protected files list and you are done. For example, you can add My Documents, My Pictures folders or *.doc, *.txt, *.jpg etc. to your protected files list and it can be protected.
Method 2: Always run your WEB browsers in COMODO Sandbox by adding them to Sandbox pemanently. And while doing this, make sure File system and registry virtualization are both enabled. If you do this and accidently get gpcode or something like gpcode or actually any virus from WEB, they will be running in a virtual file system and hence they can not acess your files or folders.
You can also directly run GPCODE with right-click menu in CIS sandbpx and you will see it cant do anything.
Ofcourse CIS is capable of preventing it proactively as of now. However, these settings are not configured by default.
So why is COMODO not making an immediate HACK to prevent this proactively. Some other products are preventing it already.
We do not need to make a HACK but offer you a proper solution which is proven to prevent this and any similar threat while not affecting your daily work with your computer.
The proper solution is the active file system virtualization of *SOME* automatically sandboxed applications by default. Yes, we are right now working on this kind of a ideal automatic sandbox which is going to be in CIS 6 and will work similar to method 2.
It is NOT a HACK but a properly engineered solution that *avreage joe* wont have problems when CIS is installed.
It takes 10 minutes to write a HACK which simply checks each applications right to enumerate files and folders and thats it. You are there. And what would be the cost? Joe's photo editor will create a popup asking him if he wants some application to list files. Or Marry, while his new MP3 player builds a playlist, it might conflict.
https://forums.comodo.com/leak-testingattacksvulnerability-research/weakness-of-the-gpcode-t65960.0.html;msg512678#msg512678
Logged
hkjoj
Comodo's Hero
Offline
Posts: 434
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #9 on:
October 17, 2011, 11:57:10 AM »
I think the | sign is needed because "partially limited' sandbox application is allowed to access the protect file without the | sign.
I've added protected folders like "*/documents|", "*/pictures|", etc
Logged
a256886572008
Star Group
Comodo's Hero
Offline
Posts: 781
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #10 on:
October 17, 2011, 12:00:36 PM »
Quote from: hkjoj on October 17, 2011, 11:57:10 AM
I think the | sign is needed because "partially limited' sandbox application is allowed to access the protect file without the | sign.
I've added protected folders like "*/documents|", "*/pictures|", etc
If you add the rules, then the sandboxed process can not create files to these folders.
The | sign is not essential.
Logged
morphiusz
Star Group
Comodo's Hero
Offline
Posts: 2196
Comodo's śmieć :)
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #11 on:
October 17, 2011, 12:01:56 PM »
"\Device\KsecDD" cuts access to Microsoft encryption tool. (gpcode cannot encrypt the files)
Also it's responsible for some kernel actions.
Only these 2.
Logged
hkjoj
Comodo's Hero
Offline
Posts: 434
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #12 on:
October 17, 2011, 12:10:20 PM »
Quote from: a256886572008 on October 17, 2011, 12:00:36 PM
If you add the rules, then the sandboxed process can not create files to these folders.
The | sign is not essential.
No. without the | sign, I find sandboxed apps still able to create files in the directories.
Logged
a256886572008
Star Group
Comodo's Hero
Offline
Posts: 781
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #13 on:
October 17, 2011, 12:14:11 PM »
Quote from: hkjoj on October 17, 2011, 12:10:20 PM
No. without the | sign, I find sandboxed apps still able to create files in the directories.
But they can not modify or delete files in the directories.
Logged
turnorburn
Comodo's Hero
Offline
Posts: 209
Saved by grace and grace alone
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #14 on:
October 17, 2011, 12:19:26 PM »
What about an application like Buffer Zone, our firewall is compatible the anti-virus I'm not sure of.
turnorburn
Logged
Jesus loves me this i know..
Tags:
Pages:
[
1
]
2
3
...
6
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.052 seconds with 20 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com