Welcome, Guest. Please login or register.
Did you miss your activation email?
June 20, 2013, 04:29:16 AM

Login with username, password and session length

669229 Posts
71157 Topics
145763 Members

Latest Member: steigfus80

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  News / Announcements / Feedback - CIS
| | | |-+  Comodo 5.8 bypassed by trojan GPCODE
« previous next »
Pages: 1 [2] 3 4 ... 6 Go Down Print
Author Topic: Comodo 5.8 bypassed by trojan GPCODE  (Read 25589 times)
Szadout
Comodo's Hero
*****
Offline Offline

Posts: 258


Keeper of the Eternal Sun


Re: Comodo 5.8 bypassed by trojan GPCODE
« Reply #15 on: October 17, 2011, 12:32:43 PM »

It's better to add "\Device\KsecDD"
I proposed it to Comodo but they didn't add that Sad

Was any reason given?

edit: Never mind, I found his concern..

It can be used by many legitimate apps frequently i.e. everytime they are executed. I am not sure.,


for example, Windows Socket Interface is also used by many legitimate programs, and yet are in the protected files, and it does not create problems
« Last Edit: October 17, 2011, 12:34:59 PM by Szadout » Logged



If you have nothing to hide, you still have something to fear.
morphiusz
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 2218


Comodo's śmieć :)


WWW
Re: Comodo 5.8 bypassed by trojan GPCODE
« Reply #16 on: October 17, 2011, 12:34:22 PM »

for example, Windows Socket Interface is also used by many legitimate programs, and yet are in the protected files, and it does not create problems

+1
It is used by almost all application which are supposed to connect to the net..
So, there is a little misunderstanding.
Logged
loveboy_lion
Comodo's Hero
*****
Offline Offline

Posts: 465


COMODO Is Good Hope We Make it The BEST !


WWW
Re: Comodo 5.8 bypassed by trojan GPCODE
« Reply #17 on: October 17, 2011, 03:40:41 PM »

I too was bypassed my one malware and tis was on my personal laptop while testing some malware and it infected me so badly that i had to format  i pinged egemen and he asked me for samples submitted to him now lets see what he does hope he fixes it

http://forums.comodo.com/bug-reports-cis/cis-58-bug-that-crashed-cis-and-windows-t77531.0.html
Logged

HeffeD
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6624



Re: Comodo 5.8 bypassed by trojan GPCODE
« Reply #18 on: October 17, 2011, 04:00:40 PM »

Loveboy_lion,

This thread has nothing to do with your issue. Please stop post poisoning/thread jacking/cross posting as this behavior is a violation of forum policy. Police

You really don't need to post links to your threads in every post that seems remotely similar.

Thanks for your understanding.

-HeffeD
Logged

AyeAyeCaptain
Usability Study Member
Comodo's Hero
*****
Offline Offline

Posts: 619



Re: Comodo 5.8 bypassed by trojan GPCODE
« Reply #19 on: October 17, 2011, 04:34:01 PM »

Loveboy_lion,

This thread has nothing to do with your issue. Please stop post poisoning/thread jacking/cross posting as this behavior is a violation of forum policy. Police

You really don't need to post links to your threads in every post that seems remotely similar.

Thanks for your understanding.

-HeffeD

Agreed, no offense Loveboy but you got to just have patience for people to respond to your thread as opposed to posting the link everywhere.  Grin
Logged

Film Scum Remake
Comodo: Where is your Tool
User: What Tool?
Comodo: This f****** Tool.
Protect Yourself With Comodo...... lol
a256886572008
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 823



Re: Comodo 5.8 bypassed by trojan GPCODE
« Reply #20 on: October 17, 2011, 08:40:55 PM »

The "auto sandbox" does not enable "file system virtualization" and "registry virtualization",
but "always sandbox" does.
Logged
a256886572008
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 823



Re: Comodo 5.8 bypassed by trojan GPCODE
« Reply #21 on: October 17, 2011, 09:00:51 PM »

But it will cause many popups.
It's better to add "\Device\KsecDD"
I proposed it to Comodo but they didn't add that Sad

CIS can not block the following malware by adding that rule.


.bat script malware
Quote
[at]echo off

del /s /q d:\*
Logged
morphiusz
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 2218


Comodo's śmieć :)


WWW
Re: Comodo 5.8 bypassed by trojan GPCODE
« Reply #22 on: October 17, 2011, 11:42:18 PM »

CIS can not block the following malware by adding that rule.


.bat script malware

I can confirm it is blocked.
Szadout can confirm as well, we have tested that couple times.
Logged
a256886572008
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 823



Re: Comodo 5.8 bypassed by trojan GPCODE
« Reply #23 on: October 18, 2011, 12:10:11 AM »

I can confirm it is blocked.
Szadout can confirm as well, we have tested that couple times.

1.
I added the rule to the protected files and folders.



2.
I double clicked on the .bat file.

3.
I viewed the defense+ events.



Logged
vix123
Comodo Loves me
****
Offline Offline

Posts: 110

I don't use an antivirus that doesn't pass VB100


Re: Comodo 5.8 bypassed by trojan GPCODE
« Reply #24 on: October 18, 2011, 12:48:21 AM »

Any malware that immediately harms the host has zero chance of surviving. Document encrypting malware is a nuisance (even a terrible one) to those who don't backup but the chance of getting it is far less than the chance of a serious hard disk head crash which would be the same.

Comodo is right about letting programs modify your documents.

If Comodo warns you any time you'll be changing your documents, say hello to users who will be disabling Defense+ after the first 5 minutes of nuisance. False positives ~is~ an issue already with Comodo.

If Comodo sandboxes your documents, they'll be having serious complains from users who uninstall it and then discover that their documents were not updated in their original locations and they have to be looking in virtual directories for the proper copies. Woe to those who had formatted their system drive in the meantime, losing the updates copies of their documents.

Of course Comodo is giving you all the tools to prevent unathorized programs from modifying your documents but don't be confusing the job of scheduled backups to that of security software.
Logged

evil_religion
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 476


Re: Comodo 5.8 bypassed by trojan GPCODE
« Reply #25 on: October 18, 2011, 12:50:54 AM »

"\Device\KsecDD" cuts access to Microsoft encryption tool. (gpcode cannot encrypt the files)
What about the HIPS at proactive profile, sandbox turned off and manually adding files to "My protected files"?
What alerts are shown when the malware wants to access the Microsoft encryption tool? Process start?
So, with this config the malware is also blocked without adding "\Device\KsecDD"?
Logged
hkjoj
Comodo's Hero
*****
Offline Offline

Posts: 439


Re: Comodo 5.8 bypassed by trojan GPCODE
« Reply #26 on: October 18, 2011, 04:47:13 AM »

Any malware that immediately harms the host has zero chance of surviving. Document encrypting malware is a nuisance (even a terrible one) to those who don't backup but the chance of getting it is far less than the chance of a serious hard disk head crash which would be the same.

Comodo is right about letting programs modify your documents.


Ways to rescue system cannot be excuses for weakness of security programs.

Comodo is right about letting programs modify your documents only when it is safe to do so.  Comodo should warn user if malware modify your documents.

If Comodo always allows any program modify files in your system, what's the point for installing CIS?
Logged
RejZoR
Comodo's Hero
*****
Online Online

Posts: 1050


Re: Comodo 5.8 bypassed by trojan GPCODE
« Reply #27 on: October 18, 2011, 06:02:40 AM »

I've changed virtualization method in VMWare Player from "Automatic" to "Binary translation" and disabled acceleration. It was slow but then it was working. Now i've switched back and it's still working. However there is still one sample named 7000.exe that doesn't raise any warnings from comodo. Hm...

EDIT:
WTF, CIS just decided on it's own to add all the malware samples to trusted files. Just like that. Are they mad at Comodo!?
« Last Edit: October 18, 2011, 06:07:26 AM by RejZoR » Logged
Siketa
Comodo's Hero
*****
Online Online

Posts: 3291


ZIG ZAG


Re: Comodo 5.8 bypassed by trojan GPCODE
« Reply #28 on: October 18, 2011, 06:14:31 AM »

WTF, CIS just decided on it's own to add all the malware samples to trusted files. Just like that. Are they mad at Comodo!?
Huh
Everything is fine here.....plus when I change untrusted folder's location, all files in it remain untrusted....
No auto switching to Trusted....has to be your system....
7000.exe is detected by AV component...
« Last Edit: October 18, 2011, 06:23:22 AM by siketa » Logged
AyeAyeCaptain
Usability Study Member
Comodo's Hero
*****
Offline Offline

Posts: 619



Re: Comodo 5.8 bypassed by trojan GPCODE
« Reply #29 on: October 18, 2011, 06:32:46 AM »

But this was not tested with AV + Cloud, on another forum am sure it got picked up when both of these were switched on?

Anyone confirm? Smiley
Logged

Film Scum Remake
Comodo: Where is your Tool
User: What Tool?
Comodo: This f****** Tool.
Protect Yourself With Comodo...... lol
Tags:
Pages: 1 [2] 3 4 ... 6 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.055 seconds with 20 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com