I disabled the antivirus and the cloud scanner.
I double clicked on the malware.
It is sandboxed as partially limited
I selected “allow”
http://i.imgur.com/KenwJ.png
comodo is then bypassed by the rootkit which is downloaded by the malware.
cfp.exe is terminated by it
I checked the defense+ events
2011-09-07 14:41:51 C:\Documents and Settings\Roger\桌面\virus\123\0access\info.exe Sandboxed As Partially Limited
2011-09-07 14:42:21 C:\DOCUME~1\Roger\LOCALS~1\Temp_898.tmp Sandboxed As Partially Limited
2011-09-07 14:42:22 C:\DOCUME~1\Roger\LOCALS~1\Temp_899.tmp Sandboxed As Partially Limited
FVS report:
http://valkyrie.comodo.com/Result.html?sha1=f95c9ade204a5cf71c210d5b1dd516f723df94a9&&query=1&&filename=info.exe
http://valkyrie.comodo.com/Result.html?sha1=8c2f57277da8e5df533408dcbd783114f87f0cd9&&query=0&&filename=_899.exe
siketa
September 7, 2011, 7:23am
#3
It’s nice to have a community of malware collectors and analysts… :-TU
Comodo should be proud of us as much as we are proud to be its users… ;D
egemen
September 7, 2011, 1:18pm
#4
Send me the smaple pls. Probably the same issue as the previosu one.
Hopefully this will soon be resolved, we can all learn and adapt from this, nothing is perfect no matter how anyone tries, it is a constant battle going back and forth. >:-D
egemen
September 7, 2011, 3:45pm
#6
Same family as before. CIS blocks it.
[attachment deleted by admin]
So, CIS didn’t get bypassed?
Or this some new version.
egemen
September 7, 2011, 3:56pm
#8
Current version is bypassed. This malware and all the malware OP submitted are all the same which use a specific bug in CIS.
So its fixed before but not released yet. this week you will get the new beta.
Current version is bypassed. This malware and all the malware OP submitted are all the same which use a specific bug in CIS.
So its fixed before but not released yet. this week you will get the new beta.
Very nice to hear Egemen. :-TU
Wisdom
September 7, 2011, 5:26pm
#11
Very nice, thanks for your job. We’re looking forward to it … :-TU
fake5
September 8, 2011, 1:18pm
#12
Current version is bypassed. This malware and all the malware OP submitted are all the same which use a specific bug in CIS.
So its fixed before but not released yet. this week you will get the new beta.
:-TU :-TU :-TU
Great news
pykko
September 8, 2011, 2:48pm
#13
Current version is bypassed. This malware and all the malware OP submitted are all the same which use a specific bug in CIS.
So its fixed before but not released yet. this week you will get the new beta.
Wonderful news. Thank you!
egemen
September 9, 2011, 12:14am
#14
Released. Pls check build 2075.