Author Topic: Comodo Cloud Antivirus v1.12.420066.533 RC  (Read 28865 times)

Offline woodrow

  • Comodo Family Member
  • ***
  • Posts: 81
Re: Comodo Cloud Antivirus v1.12.420066.533 RC
« Reply #45 on: July 19, 2017, 12:38:02 PM »
Hi guys, what happened to Valkyrie now?
You guys must have found my id or something, poof and all the "Being analyzed" were gone and counter down to zero.
Just for fun I did run 2 of these files again (all malware by the way), and they ended up Being analyzed again... :o
Another thing is even more strange, all the files (malware) are now analyzed, but they did not get removed, Valkyrie had a few to many in these vaccination times or what?

/W

Offline morphiusz

  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 3082
    • Suspicious file?
Re: Comodo Cloud Antivirus v1.12.420066.533 RC
« Reply #46 on: July 19, 2017, 02:51:03 PM »
We are still missing  point 6 in this graphic. Many unnecessary reanalysis and a great delay in protecting the whole community(detecting malware on everyone's system). This had been working great with CIMA analysis - after finding suspicious behaviour the global cloud signature was made instantly (i.e. from executing new malware in sandbox to global detection of CIS users in ~15 minutes). BTW This is the new MS Windows Defender algorithm.
« Last Edit: July 19, 2017, 02:53:53 PM by morphiusz »

Offline Umesh

  • Comodo Alumni
  • Comodo's Hero
  • *****
  • Posts: 3421
  • Comodo Alumni
    • COMODO
Re: Comodo Cloud Antivirus v1.12.420066.533 RC
« Reply #47 on: July 19, 2017, 02:54:02 PM »
Hi morphiusz,
Please elaborate as what you mean we are still missing point 6?

Thanks
-umesh
We are still missing  point 6 in this graphic. Many unnecessary reanalysis and a great delay in protecting the whole community. BTW This is the new MS Windows Defender algorithm.
We can't stop malware entering user's PC but we render them use-less when they enter PC: Welcome to Comodo's Default Deny innovation

Offline morphiusz

  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 3082
    • Suspicious file?
Re: Comodo Cloud Antivirus v1.12.420066.533 RC
« Reply #48 on: July 19, 2017, 02:58:53 PM »
No synchronization with verdicts from valkyrie.comodo.com and CCAV.
Are files found by valkyrie as malware (especially human analysis) submitted either via web interface or CCAV itself detected globally ad hoc?
Reanalysis of again executed files despite they've got a verdict before (according to woodrow).
I haven't tested CCAV recently but remember that I had similar experience. 

Offline Umesh

  • Comodo Alumni
  • Comodo's Hero
  • *****
  • Posts: 3421
  • Comodo Alumni
    • COMODO
Re: Comodo Cloud Antivirus v1.12.420066.533 RC
« Reply #49 on: July 19, 2017, 03:08:05 PM »
Hi morphiusz,
This is how it works:
1.
A file gets analyzed by any system, Valkyrie/ human, file's verdict is immediately reflected via FLS (File Lookup Service). This way any new user who sees the file gets benefited immediately.

2.
In case a file has been seen by CCAV and is under analysis on a given client, it is looked up at least once a day to re-check latest verdict if malware or safe.

So we do have all six points firmly in place.

Now regarding problem woodrow seeing that he has files classified in back-end but still not classified by CCAV, we will be looking at those cases if we have syncing problem somewhere between Valkyrie and look up service.

So to answer your questions:
Quote from: morphiusz
No synchronization with verdicts from valkyrie.comodo.com and CCAV.
There is periodic look up for files under analysis in CCAV.
Quote from: morphiusz
Are files found by valkyrie as malware (especially human analysis) submitted either via web interface or CCAV itself detected globally ad hoc?
Yes, including CIS gets benefited.

Quote from: morphiusz
I haven't tested CCAV recently but remember that I had similar experience.
We did have issues in past where Valkyrie results were not reflect in cloud. Should be all fine now.


Thanks
-umesh


No synchronization with verdicts from valkyrie.comodo.com and CCAV.
Are files found by valkyrie as malware (especially human analysis) submitted either via web interface or CCAV itself detected globally ad hoc?
Reanalysis of again executed files despite they've got a verdict before (according to woodrow).
I haven't tested CCAV recently but remember that I had similar experience.
We can't stop malware entering user's PC but we render them use-less when they enter PC: Welcome to Comodo's Default Deny innovation

Offline morphiusz

  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 3082
    • Suspicious file?
Re: Comodo Cloud Antivirus v1.12.420066.533 RC
« Reply #50 on: July 19, 2017, 03:12:50 PM »
Thanks! Good to know.
Is this scenario true?
1. File is submitted via valkyrie.comodo.com
2. Found to be malware
3. Immediate synchronization with FLS is made and after execution of that file user will get cloud detection (either CIS/CCAV)?

Quote
In case a file has been seen by CCAV and is under analysis on a given client, it is looked up at least once a day to re-check latest verdict if malware or safe.

An option in "being analyzed" tab in CCAV to "refresh verdict" would be handy. :)

Thank you for your detailed answer.

Offline BlueTesta

  • Star Group
  • Comodo's Hero
  • *****
  • Posts: 482
Re: Comodo Cloud Antivirus v1.12.420066.533 RC
« Reply #51 on: July 19, 2017, 03:18:29 PM »
Dunno how reliable (False positive) Viruscope is but just wanted to share my thought i had.


When a unknown file run in sandbox, viruscope can take up 5sec to 1min to detect the file as malicious.

When the next user run the same unknown file, the file could be detected as Viruscope Cloud Signature and the user could get a alert immediately that Viruscope cloud detects its as a malicious file.
So the next user dont have to wait for Viruscope to detect the malicious file in the sandbox.

And since the file is the same as the first user. they will get the same recommended option to quarantine the file.
« Last Edit: July 19, 2017, 03:48:21 PM by BlueTesta »
"Everybody is a genius. But if you judge a fish by its ability to climb a tree, it will live its whole life believing that it is stupid."

Offline Umesh

  • Comodo Alumni
  • Comodo's Hero
  • *****
  • Posts: 3421
  • Comodo Alumni
    • COMODO
Re: Comodo Cloud Antivirus v1.12.420066.533 RC
« Reply #52 on: July 19, 2017, 03:42:27 PM »
Hi morphiusz,
That's right.

3. Immediate synchronization with FLS is made and after execution of that file user will get cloud detection (either CIS/CCAV)?

As soon as malware or safe verdict is given on a file on server side, it is immediately reflected via cloud and is available to all clients whether CIS, CCAV or any other Comodo services that could be using FLS.

However, once a file is found unknown by CCAV, the question comes as what frequency you poll on server to know latest verdict, here we have incremental logic like, check after 1hour then 2hrs and finally file is looked up once in maximum 24hrs.

So if a file that was under analysis and has been confirmed as malware on server side, client must see latest malware verdict within maximum next 24hrs. If not, then either we have some issue with syncing results to cloud or client is failing to look up for some machine specific issues.

Thanks
-umesh




Thanks! Good to know.
Is this scenario true?
1. File is submitted via valkyrie.comodo.com
2. Found to be malware
3. Immediate synchronization with FLS is made and after execution of that file user will get cloud detection (either CIS/CCAV)?

An option in "being analyzed" tab in CCAV to "refresh verdict" would be handy. :)

Thank you for your detailed answer.
We can't stop malware entering user's PC but we render them use-less when they enter PC: Welcome to Comodo's Default Deny innovation

Offline Umesh

  • Comodo Alumni
  • Comodo's Hero
  • *****
  • Posts: 3421
  • Comodo Alumni
    • COMODO
Re: Comodo Cloud Antivirus v1.12.420066.533 RC
« Reply #53 on: July 19, 2017, 03:52:14 PM »
Hi BlueTesta,
Virusscope is for providing results immediately based on behavior and allows to handle any kind of polymorphic malware and these results are also transmitted to back-end.

Finally in back-end, when centralized system ensures that file was really malware, via cloud results are made available to all users.

Thanks
-umesh

Dunno how reliable (False positive) Viruscope is but just wanted to share my thought i had.


When a unknown file run in sandbox, viruscope can take up 5sec to 1min to detect the file as malicious.

When the next user run the same unknown file, the file could be detected as Viruscope Cloud Signature and the user could get a alert immediately that Viruscope cloud detects its as a malicious file.
So the next user dont have to wait for Viruscope to detect the malicious file in the sandbox.

And since the file is the same as the first user. they will get the same recommended option to quarantine the file.
We can't stop malware entering user's PC but we render them use-less when they enter PC: Welcome to Comodo's Default Deny innovation

Offline BlueTesta

  • Star Group
  • Comodo's Hero
  • *****
  • Posts: 482
Re: Comodo Cloud Antivirus v1.12.420066.533 RC
« Reply #54 on: July 19, 2017, 04:00:56 PM »
Ah thanks, good to know  :)
"Everybody is a genius. But if you judge a fish by its ability to climb a tree, it will live its whole life believing that it is stupid."

Offline Yousername

  • Comodo's Hero
  • *****
  • Posts: 236
Re: Comodo Cloud Antivirus v1.12.420066.533 RC
« Reply #55 on: July 19, 2017, 06:50:23 PM »
I can confirm that many detections are being made in the cloud. I tested CIS on a VM and I notice that quite a few samples are not detected by on-demand at first, but are detected on-execution when CIS performs Cloud Lookup.

Offline nasion

  • Development
  • Newbie
  • ****
  • Posts: 24
Re: Comodo Cloud Antivirus v1.12.420066.533 RC
« Reply #56 on: July 19, 2017, 11:20:47 PM »
Hi guys, what happened to Valkyrie now?
You guys must have found my id or something, poof and all the "Being analyzed" were gone and counter down to zero.
Just for fun I did run 2 of these files again (all malware by the way), and they ended up Being analyzed again... :o
Another thing is even more strange, all the files (malware) are now analyzed, but they did not get removed, Valkyrie had a few to many in these vaccination times or what?

/W

Hello woodrow ,We will research your issue. considering that you can reproduce it ,so please do the following steps.

1  uninstall ccav if you installed ccav before.and then install it .(please donot update it ,because we want a new data)

2  save the below script as xxx.reg and excute it .they only will open the ccav log function   
*

3 reboot your system

4 run your malware file in sandbox,(manual sandbox or as you like) . as your mean ,the malware can be in valkyrie analyzing list ,we can wait for one day , there is no analyzing result.

5 there is one log for valkyrie scan or fls scan, the log is at  "C:\ProgramData\COMODO\CCAV\usage_stat_log.txt" . you can send me a email with attached the file  .my email is "xiaohua.ma[at]comodo.com" ,if sending fails ,you can change one, "273623676[at]qq.com"

6 or you can contact with me directly.

Thanks for you and your issue.





« Last Edit: July 20, 2017, 10:05:10 AM by nasion »

Offline woodrow

  • Comodo Family Member
  • ***
  • Posts: 81
Re: Comodo Cloud Antivirus v1.12.420066.533 RC
« Reply #57 on: July 20, 2017, 03:28:26 AM »
Hello woodrow ,We will research your issue. considering that you can reproduce it ,so please do the following steps.

1  uninstall ccav if you installed ccav before.and then install it .(please donot update it ,because we want a new data)

2  save the below script as xxx.reg and excute it .they only will open the ccav log function   
 
  Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\COMODO\CCAV]
"debug_log"=dword:00000001


[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\COMODO\CCAV]
"debug_log"=dword:00000001

3 reboot your system

4 run your malware file in sandbox,(manual sandbox or as you like) . as your mean ,the malware can be in valkyrie analyzing list ,we can wait for one day , there is no analyzing result.

5 there is one log for valkyrie scan or fls scan, the log is at  "C:\ProgramData\COMODO\CCAV\usage_stat_log.txt" . you can send me a email with attached the file  .my email is "xiaohua.ma[at]comodo.com" ,if sending fails ,you can change one, "273623676[at]qq.com"

6 or you can contact with me directly.

Thanks for you and your issue.

Hi nasion,
I will try to get this done, but I cannot promise when, my one year old do not like me in front of the computer  ;D

I will install CCAV in a new VM, does that work for you?
Regarding not updating after install I do not understand, I have not found a way to manually update CCAV?
Do you want me to run the same malware again, these must be detected by now and will not give the correct picture, or?

/W

Offline nasion

  • Development
  • Newbie
  • ****
  • Posts: 24
Re: Comodo Cloud Antivirus v1.12.420066.533 RC
« Reply #58 on: July 20, 2017, 03:52:05 AM »
Hi nasion,
I will try to get this done, but I cannot promise when, my one year old do not like me in front of the computer  ;D

I will install CCAV in a new VM, does that work for you?
Regarding not updating after install I do not understand, I have not found a way to manually update CCAV?
Do you want me to run the same malware again, these must be detected by now and will not give the correct picture, or?

/W


1 Yes, you can install a new ccav too.
2  Yes, You should run the same malware again.
3  "these must be detected by now ?" I donot know ,because you say you can reproduce it , so I want you to reproduce it and get the ccav log  .

Offline woodrow

  • Comodo Family Member
  • ***
  • Posts: 81
Re: Comodo Cloud Antivirus v1.12.420066.533 RC
« Reply #59 on: July 20, 2017, 03:52:37 AM »
From what i understand here it will take hours for new unknowns to get a verdict and remedy in place?

The article behind Morphiusz pic:

https://blogs.technet.microsoft.com/mmpc/2017/07/18/windows-defender-antivirus-cloud-protection-service-advanced-real-time-defense-against-never-before-seen-malware/?platform=hootsuite

If you read this you will see that Windows Defender (with cloud lookup enabled) takes care of a new unknowns in just 6 sec!

Or am I comparing apples and oranges here?

/W

 

Free Endpoint Protection
Seo4Smf 2.0 © SmfMod.Com Smf Destek