bypass comodo?

VirusTotal:
http://www.virustotal.com/file-scan/report.html?id=1fb932caaa473d74e99480f7f8d8706aefdc55092fd21b1c54f0086e276830f6-1313310477

CIMA report:
http://camas.comodo.com/cgi-bin/submit?file=1fb932caaa473d74e99480f7f8d8706aefdc55092fd21b1c54f0086e276830f6


1.I double click on the malware.

2.bot.exe is sandboxed as partially limited

3.then, I check the active process list

4.comodo popups an alert window

5.Is it a hidden process?

[attachment deleted by admin]

Hi.
Run process and check with KillSwitch:

Download Locations:
http://download.comodo.com/cce/download/setups/cce_1.6.183539.73_x32.zip
http://download.comodo.com/cce/download/setups/cce_1.6.183539.73_x64.zip

a hidden process?

[attachment deleted by admin]

Can you provide me a sample?

Hi a256886572008.
Could you please send the sample file to me? I PMed my email address to you just now.

We will check what happen with it.

Thanks,
Doskey.

This file doesn’t want to run on my system (XP, SP3, x32).

@a256886572008: Thanks for providing the sample. :slight_smile:

My guess is that the process exited already and the pop up was already in queue → pop up for not existing process.