Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
June 20, 2013, 04:29:16 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
669229
Posts
71157
Topics
145763
Members
Latest Member:
steigfus80
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
News / Announcements / Feedback - CIS
Comodo 5.8 bypassed by trojan GPCODE
« previous
next »
Pages:
1
[
2
]
3
4
...
6
Author
Topic: Comodo 5.8 bypassed by trojan GPCODE (Read 25589 times)
Szadout
Comodo's Hero
Offline
Posts: 258
Keeper of the Eternal Sun
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #15 on:
October 17, 2011, 12:32:43 PM »
Quote from: kail on October 17, 2011, 11:53:36 AM
Quote from: morphiusz on October 17, 2011, 11:45:15 AM
It's better to add "\Device\KsecDD"
I proposed it to Comodo but they didn't add that
Was any reason given?
edit: Never mind, I found his concern..
Quote from: egemen on August 30, 2011, 04:17:04 PM
It can be used by many legitimate apps frequently i.e. everytime they are executed. I am not sure.,
for example, Windows Socket Interface is also used by many legitimate programs, and yet are in the protected files, and it does not create problems
«
Last Edit: October 17, 2011, 12:34:59 PM by Szadout
»
Logged
If you have nothing to hide, you still have something to fear.
morphiusz
Star Group
Comodo's Hero
Offline
Posts: 2218
Comodo's śmieć :)
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #16 on:
October 17, 2011, 12:34:22 PM »
Quote from: Szadout on October 17, 2011, 12:32:43 PM
for example, Windows Socket Interface is also used by many legitimate programs, and yet are in the protected files, and it does not create problems
+1
It is used by almost all application which are supposed to connect to the net..
So, there is a little misunderstanding.
Logged
loveboy_lion
Comodo's Hero
Offline
Posts: 465
COMODO Is Good Hope We Make it The BEST !
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #17 on:
October 17, 2011, 03:40:41 PM »
I too was bypassed my one malware and tis was on my personal laptop while testing some malware and it infected me so badly that i had to format i pinged egemen and he asked me for samples submitted to him now lets see what he does hope he fixes it
http://forums.comodo.com/bug-reports-cis/cis-58-bug-that-crashed-cis-and-windows-t77531.0.html
Logged
MALWARE TIPS
HeffeD
Global Moderator
Comodo's Hero
Offline
Posts: 6624
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #18 on:
October 17, 2011, 04:00:40 PM »
Loveboy_lion,
This thread has nothing to do with your issue. Please stop post poisoning/thread jacking/cross posting as this behavior is a violation of forum policy.
You really don't need to post links to your threads in every post that seems remotely similar.
Thanks for your understanding.
-HeffeD
Logged
Please read the
Forum Policy
!
Breast Cancer Awareness
American Cancer Society
AyeAyeCaptain
Usability Study Member
Comodo's Hero
Offline
Posts: 619
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #19 on:
October 17, 2011, 04:34:01 PM »
Quote from: HeffeD on October 17, 2011, 04:00:40 PM
Loveboy_lion,
This thread has nothing to do with your issue. Please stop post poisoning/thread jacking/cross posting as this behavior is a violation of forum policy.
You really don't need to post links to your threads in every post that seems remotely similar.
Thanks for your understanding.
-HeffeD
Agreed, no offense Loveboy but you got to just have patience for people to respond to your thread as opposed to posting the link everywhere.
Logged
Film Scum Remake
Comodo: Where is your Tool
User: What Tool?
Comodo: This f****** Tool.
Protect Yourself With Comodo...... lol
a256886572008
Star Group
Comodo's Hero
Offline
Posts: 823
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #20 on:
October 17, 2011, 08:40:55 PM »
The "auto sandbox" does not enable "file system virtualization" and "registry virtualization",
but "always sandbox" does.
Logged
a256886572008
Star Group
Comodo's Hero
Offline
Posts: 823
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #21 on:
October 17, 2011, 09:00:51 PM »
Quote from: morphiusz on October 17, 2011, 11:45:15 AM
But it will cause many popups.
It's better to add "\Device\KsecDD"
I proposed it to Comodo but they didn't add that
CIS can not block the following malware by adding that rule.
.bat script malware
Quote
[at]echo off
del /s /q d:\*
Logged
morphiusz
Star Group
Comodo's Hero
Offline
Posts: 2218
Comodo's śmieć :)
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #22 on:
October 17, 2011, 11:42:18 PM »
Quote from: a256886572008 on October 17, 2011, 09:00:51 PM
CIS can not block the following malware by adding that rule.
.bat script malware
I can confirm it is blocked.
Szadout can confirm as well, we have tested that couple times.
Logged
a256886572008
Star Group
Comodo's Hero
Offline
Posts: 823
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #23 on:
October 18, 2011, 12:10:11 AM »
Quote from: morphiusz on October 17, 2011, 11:42:18 PM
I can confirm it is blocked.
Szadout can confirm as well, we have tested that couple times.
1.
I added the rule to the protected files and folders.
2.
I double clicked on the .bat file.
3.
I viewed the defense+ events.
Logged
vix123
Comodo Loves me
Offline
Posts: 110
I don't use an antivirus that doesn't pass VB100
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #24 on:
October 18, 2011, 12:48:21 AM »
Any malware that immediately harms the host has zero chance of surviving. Document encrypting malware is a nuisance (even a terrible one) to those who don't backup but the chance of getting it is far less than the chance of a serious hard disk head crash which would be the same.
Comodo is right about letting programs modify your documents.
If Comodo warns you any time you'll be changing your documents, say hello to users who will be disabling Defense+ after the first 5 minutes of nuisance. False positives ~is~ an issue already with Comodo.
If Comodo sandboxes your documents, they'll be having serious complains from users who uninstall it and then discover that their documents were not updated in their original locations and they have to be looking in virtual directories for the proper copies. Woe to those who had formatted their system drive in the meantime, losing the updates copies of their documents.
Of course Comodo is giving you all the tools to prevent unathorized programs from modifying your documents but don't be confusing the job of scheduled backups to that of security software.
Logged
Windows XP /
Comodo
LITE
(just firewall and defense+ at 16% of the standard size, no antivirus, no clouds, no whitelists)
evil_religion
Malware Research Group
Comodo's Hero
Offline
Posts: 476
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #25 on:
October 18, 2011, 12:50:54 AM »
Quote from: morphiusz on October 17, 2011, 12:01:56 PM
"\Device\KsecDD" cuts access to Microsoft encryption tool. (gpcode cannot encrypt the files)
What about the HIPS at proactive profile, sandbox turned off and manually adding files to "My protected files"?
What alerts are shown when the malware wants to access the Microsoft encryption tool? Process start?
So, with this config the malware is also blocked without adding "\Device\KsecDD"?
Logged
hkjoj
Comodo's Hero
Offline
Posts: 439
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #26 on:
October 18, 2011, 04:47:13 AM »
Quote from: vix123 on October 18, 2011, 12:48:21 AM
Any malware that immediately harms the host has zero chance of surviving. Document encrypting malware is a nuisance (even a terrible one) to those who don't backup but the chance of getting it is far less than the chance of a serious hard disk head crash which would be the same.
Comodo is right about letting programs modify your documents.
Ways to rescue system cannot be excuses for weakness of security programs.
Comodo is right about letting programs modify your documents
only when it is safe to do so
. Comodo should warn user if malware modify your documents.
If Comodo always allows any program modify files in your system, what's the point for installing CIS?
Logged
RejZoR
Comodo's Hero
Online
Posts: 1050
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #27 on:
October 18, 2011, 06:02:40 AM »
I've changed virtualization method in VMWare Player from "Automatic" to "Binary translation" and disabled acceleration. It was slow but then it was working. Now i've switched back and it's still working. However there is still one sample named 7000.exe that doesn't raise any warnings from comodo. Hm...
EDIT:
WTF, CIS just decided on it's own to add all the malware samples to trusted files. Just like that. Are they mad at Comodo!?
«
Last Edit: October 18, 2011, 06:07:26 AM by RejZoR
»
Logged
Siketa
Comodo's Hero
Online
Posts: 3291
ZIG ZAG
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #28 on:
October 18, 2011, 06:14:31 AM »
Quote from: RejZoR on October 18, 2011, 06:02:40 AM
WTF, CIS just decided on it's own to add all the malware samples to trusted files. Just like that. Are they mad at Comodo!?
Everything is fine here.....plus when I change untrusted folder's location, all files in it remain untrusted....
No auto switching to Trusted....has to be your system....
7000.exe is detected by AV component...
«
Last Edit: October 18, 2011, 06:23:22 AM by siketa
»
Logged
AyeAyeCaptain
Usability Study Member
Comodo's Hero
Offline
Posts: 619
Re: Comodo 5.8 bypassed by trojan GPCODE
«
Reply #29 on:
October 18, 2011, 06:32:46 AM »
But this was not tested with AV + Cloud, on another forum am sure it got picked up when both of these were switched on?
Anyone confirm?
Logged
Film Scum Remake
Comodo: Where is your Tool
User: What Tool?
Comodo: This f****** Tool.
Protect Yourself With Comodo...... lol
Tags:
Pages:
1
[
2
]
3
4
...
6
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.055 seconds with 20 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com