Welcome, Guest. Please login or register.
Did you miss your activation email?
May 21, 2013, 11:46:02 PM

Login with username, password and session length

663478 Posts
70539 Topics
145199 Members

Latest Member: kmqq

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  News / Announcements / Feedback - CIS
| | | |-+  How Comodo protect my system against Trojan.Win32 GPCODE ?
« previous next »
Pages: [1] 2 3 ... 7 Go Down Print
Author Topic: How Comodo protect my system against Trojan.Win32 GPCODE ?  (Read 22450 times)
slayer76
Comodo Loves me
****
Offline Offline

Posts: 122


« on: October 20, 2011, 06:00:55 PM »

I tested new Comodo against  Trojan.Win32 GPCODE.    And Comodo protect my system . I just add my local disks to protect files and folders and everything is just fine .
Logged
a256886572008
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 781



« Reply #1 on: October 20, 2011, 06:46:54 PM »

?:\*

This one is better.

 Grin
Logged
wasgij6
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3064



WWW
« Reply #2 on: October 20, 2011, 07:12:35 PM »

?:\*

This one is better.

 Grin

do you know what the difference is between ?:\* and \Device\KsecDD?
i know can be used to block gpcode
Logged

| Win 7 Ultimate (x32) SP1; Admin | UAC Disabled | CIS 6.1.276867.2813 | CD 26.2 | CID 20.0.1 | VMWare Workstation; XP (x32), 7 (x64) |
a256886572008
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 781



« Reply #3 on: October 20, 2011, 07:49:19 PM »

do you know what the difference is between ?:\* and \Device\KsecDD?
i know can be used to block gpcode


CIS auto sandbox can block the following malwares by adding this rule.

?:\*

1.
GPcode

2.
the .bat script malware that deletes all files or hides all files

3.
the malware that infects all executable files or all script files

--------------------------------
\Device\KsecDD

block GPcode only
Logged
trscsaeg
Comodo's Hero
*****
Offline Offline

Posts: 1156


« Reply #4 on: October 21, 2011, 03:52:26 AM »

why doesn't comodo just add the rules needed to protect against this in an update as a temporary solution while they work on a real solution so that average users can be protected that don't visit forums
Logged
Siketa
Comodo's Hero
*****
Offline Offline

Posts: 3133


ZIG ZAG


« Reply #5 on: October 21, 2011, 04:04:18 AM »

why doesn't comodo just add the rules needed to protect against this in an update as a temporary solution while they work on a real solution so that average users can be protected that don't visit forums
+1
Logged
evil_religion
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 476


« Reply #6 on: October 21, 2011, 05:19:45 AM »

do you know what the difference is between ?:\* and \Device\KsecDD?
i know can be used to block gpcode
Won't ?:\* block many other actions too?
Then quite less program would be working in the auto-sandbox.

And \Device\KsecDD? might help to block this particular GPCode sample but your files are still not protected, other ransomware or viruses might still be able to alter your personal files.

The best solution is IMO simply adding your important files to the protected ones, this will always be safe.
Logged
joe7
Comodo Family Member
***
Offline Offline

Posts: 80


« Reply #7 on: October 21, 2011, 06:04:34 AM »

hi, is it possible please, to be shown how to add these settings to CIS please, thank you ,  Thumb Up   Huh
Logged
Siketa
Comodo's Hero
*****
Offline Offline

Posts: 3133


ZIG ZAG


« Reply #8 on: October 21, 2011, 06:15:07 AM »

hi, is it possible please, to be shown how to add these settings to CIS please, thank you ,  Thumb Up   Huh
http://www.youtube.com/watch?v=p2ZV4aEeNy0
Logged
naren
Comodo's Hero
*****
Offline Offline

Posts: 3860


« Reply #9 on: October 21, 2011, 06:24:13 AM »

CIS auto sandbox can block the following malwares by adding this rule.

?:\*

1.
GPcode

2.
the .bat script malware that deletes all files or hides all files

3.
the malware that infects all executable files or all script files

--------------------------------
\Device\KsecDD

block GPcode only


Adding these rules, do one also need to set sandbox to untrusted or the default partial limited will do?

Thanxx
Naren
Logged
pikusek
Comodo Loves me
****
Offline Offline

Posts: 137


« Reply #10 on: October 21, 2011, 06:56:01 AM »

I have a strange and stupid question. What is a differance between "?:\*" and added default "*" ("All applications")?
Logged
GOA
Comodo's Hero
*****
Offline Offline

Posts: 462


« Reply #11 on: October 21, 2011, 07:21:43 AM »


The best solution is IMO simply adding your important files to the protected ones, this will always be safe.

Can you give me or us an example (Screenshot) ?

Thanks
Logged

CF 6.1.275152.2801
Windows 7 x64
a256886572008
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 781



« Reply #12 on: October 21, 2011, 07:23:40 AM »

I have a strange and stupid question. What is a differance between "?:\*" and added default "*" ("All applications")?

*

It contains  "device\*", "systemroot\*", ..........,etc.

But we just want C:\*, D:\*, .............,etc  be protected only.

The rules of COMODO is not the same as that of other HIPS programs.
« Last Edit: October 21, 2011, 07:35:14 AM by a256886572008 » Logged
a256886572008
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 781



« Reply #13 on: October 21, 2011, 07:27:01 AM »

Adding these rules, do one also need to set sandbox to untrusted or the default partial limited will do?

Thanxx
Naren

keep the sandbox level as "partially limited"
Logged
RejZoR
Comodo's Hero
*****
Offline Offline

Posts: 1045


« Reply #14 on: October 21, 2011, 08:06:32 AM »

I certainly hope they will add \Device\KsecDD as a default entry in Comodo now...
Logged
Tags:
Pages: [1] 2 3 ... 7 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.049 seconds with 21 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com