Welcome, Guest. Please login or register.
Did you miss your activation email?
June 18, 2013, 07:39:51 PM

Login with username, password and session length

668794 Posts
71123 Topics
145736 Members

Latest Member: Lolkid

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  News / Announcements / Feedback - CIS
| | | |-+  How Comodo protect my system against Trojan.Win32 GPCODE ?
« previous next »
Pages: [1] 2 3 ... 7 Go Down Print
Author Topic: How Comodo protect my system against Trojan.Win32 GPCODE ?  (Read 23119 times)
slayer76
Comodo Loves me
****
Offline Offline

Posts: 123


How Comodo protect my system against Trojan.Win32 GPCODE ?
« on: October 20, 2011, 06:00:55 PM »

I tested new Comodo against  Trojan.Win32 GPCODE.    And Comodo protect my system . I just add my local disks to protect files and folders and everything is just fine .
Logged
a256886572008
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 820



Re: How Comodo protect my system against Trojan.Win32 GPCODE ?
« Reply #1 on: October 20, 2011, 06:46:54 PM »

?:\*

This one is better.

 Grin
Logged
wasgij6
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3101



WWW
Re: How Comodo protect my system against Trojan.Win32 GPCODE ?
« Reply #2 on: October 20, 2011, 07:12:35 PM »

?:\*

This one is better.

 Grin

do you know what the difference is between ?:\* and \Device\KsecDD?
i know can be used to block gpcode
Logged

| Win 7 Ultimate (x32) SP1; Admin | UAC Disabled | CIS 6.1.276867.2813 | CD 27.0.4 | VMWare Workstation; XP (x32), 7 (x64) |
a256886572008
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 820



Re: How Comodo protect my system against Trojan.Win32 GPCODE ?
« Reply #3 on: October 20, 2011, 07:49:19 PM »

do you know what the difference is between ?:\* and \Device\KsecDD?
i know can be used to block gpcode


CIS auto sandbox can block the following malwares by adding this rule.

?:\*

1.
GPcode

2.
the .bat script malware that deletes all files or hides all files

3.
the malware that infects all executable files or all script files

--------------------------------
\Device\KsecDD

block GPcode only
Logged
trscsaeg
Comodo's Hero
*****
Offline Offline

Posts: 1156


Re: How Comodo protect my system against Trojan.Win32 GPCODE ?
« Reply #4 on: October 21, 2011, 03:52:26 AM »

why doesn't comodo just add the rules needed to protect against this in an update as a temporary solution while they work on a real solution so that average users can be protected that don't visit forums
Logged
Siketa
Comodo's Hero
*****
Offline Offline

Posts: 3284


ZIG ZAG


Re: How Comodo protect my system against Trojan.Win32 GPCODE ?
« Reply #5 on: October 21, 2011, 04:04:18 AM »

why doesn't comodo just add the rules needed to protect against this in an update as a temporary solution while they work on a real solution so that average users can be protected that don't visit forums
+1
Logged
evil_religion
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 476


Re: How Comodo protect my system against Trojan.Win32 GPCODE ?
« Reply #6 on: October 21, 2011, 05:19:45 AM »

do you know what the difference is between ?:\* and \Device\KsecDD?
i know can be used to block gpcode
Won't ?:\* block many other actions too?
Then quite less program would be working in the auto-sandbox.

And \Device\KsecDD? might help to block this particular GPCode sample but your files are still not protected, other ransomware or viruses might still be able to alter your personal files.

The best solution is IMO simply adding your important files to the protected ones, this will always be safe.
Logged
joe7
Comodo Family Member
***
Offline Offline

Posts: 81


Re: How Comodo protect my system against Trojan.Win32 GPCODE ?
« Reply #7 on: October 21, 2011, 06:04:34 AM »

hi, is it possible please, to be shown how to add these settings to CIS please, thank you ,  Thumb Up   Huh
Logged
Siketa
Comodo's Hero
*****
Offline Offline

Posts: 3284


ZIG ZAG


Re: How Comodo protect my system against Trojan.Win32 GPCODE ?
« Reply #8 on: October 21, 2011, 06:15:07 AM »

hi, is it possible please, to be shown how to add these settings to CIS please, thank you ,  Thumb Up   Huh
http://www.youtube.com/watch?v=p2ZV4aEeNy0
Logged
naren
Comodo's Hero
*****
Offline Offline

Posts: 3914


Re: How Comodo protect my system against Trojan.Win32 GPCODE ?
« Reply #9 on: October 21, 2011, 06:24:13 AM »

CIS auto sandbox can block the following malwares by adding this rule.

?:\*

1.
GPcode

2.
the .bat script malware that deletes all files or hides all files

3.
the malware that infects all executable files or all script files

--------------------------------
\Device\KsecDD

block GPcode only


Adding these rules, do one also need to set sandbox to untrusted or the default partial limited will do?

Thanxx
Naren
Logged
pikusek
Comodo Loves me
****
Offline Offline

Posts: 137


Re: How Comodo protect my system against Trojan.Win32 GPCODE ?
« Reply #10 on: October 21, 2011, 06:56:01 AM »

I have a strange and stupid question. What is a differance between "?:\*" and added default "*" ("All applications")?
Logged
GOA
Comodo's Hero
*****
Offline Offline

Posts: 478


Re: How Comodo protect my system against Trojan.Win32 GPCODE ?
« Reply #11 on: October 21, 2011, 07:21:43 AM »


The best solution is IMO simply adding your important files to the protected ones, this will always be safe.

Can you give me or us an example (Screenshot) ?

Thanks
Logged

CF 6.1.275152.2801
Windows 7 x64
a256886572008
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 820



Re: How Comodo protect my system against Trojan.Win32 GPCODE ?
« Reply #12 on: October 21, 2011, 07:23:40 AM »

I have a strange and stupid question. What is a differance between "?:\*" and added default "*" ("All applications")?

*

It contains  "device\*", "systemroot\*", ..........,etc.

But we just want C:\*, D:\*, .............,etc  be protected only.

The rules of COMODO is not the same as that of other HIPS programs.
« Last Edit: October 21, 2011, 07:35:14 AM by a256886572008 » Logged
a256886572008
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 820



Re: How Comodo protect my system against Trojan.Win32 GPCODE ?
« Reply #13 on: October 21, 2011, 07:27:01 AM »

Adding these rules, do one also need to set sandbox to untrusted or the default partial limited will do?

Thanxx
Naren

keep the sandbox level as "partially limited"
Logged
RejZoR
Comodo's Hero
*****
Offline Offline

Posts: 1045


Re: How Comodo protect my system against Trojan.Win32 GPCODE ?
« Reply #14 on: October 21, 2011, 08:06:32 AM »

I certainly hope they will add \Device\KsecDD as a default entry in Comodo now...
Logged
Tags:
Pages: [1] 2 3 ... 7 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.142 seconds with 21 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com