Can i run BOclean with...[Resolved]

Hello, I love COMODO and i noticed BOclean. Im alittle curious about it so I want to try it.

I was wondering if it would ‘play nice’ as in run along side with these applications with out any conflictions:

Zone Alarm PRO
NOD32
Spy sweeper
Kaspersky Anti Virus (on demand)

And one more thing… What exactly is BOCLEAN?

Is it like a resident scanner that simply looks for malware? Or does it reside and look for behavior based malware like cyberhawk (threatfire)

thanks

This might help explain what BOClean is:

http://www.comodo.com/boclean/boclean.html

As far as I know BOClean should be compatible with all of the programs you mention. I would advise you install it in safe mode though.

:SMLR

Yes I was reading that and I started to get the feeling of it being like a cyberhawk, but I wasnt sure.

It’s not a behavior-based application; it’s a definitions-based app. But it’s not a file-scanner like your normal AV or anti-spyware. It’s a real-time memory-scanner. The reason being, in order to do something, malware has to execute (access memory/CPU), so that’s where BOC watches and waits. The way it does so allows it to use its database of some 34,000 signatures to detect a million or so malware (since most are variants, but traditional AVs can’t find without individual definitions). The explanation is (in non-techy terms) that it can see the malware with their clothes off, so their techniques to hide what they are really don’t matter.

Hope that helps,

LM

Oh yes i understand now… Ok its just that COMODO gives a non technical way of describing how its done, and its too simple for me to understand… instead of using the terms needed to describe it… Ok I get it now… Its very simple and I would consider using it, since it only scans memory items and watches for start up entries ect. Sounds good.

Thanks

Thanks LM that is a great explanation.

:SMLR

Million or so my as- lol.That has got to be the best joke I have heard in a long while.Please show me facts on a million detections if you can.

Actually, it’s 2 million, per the malware report, available for anyone here:

http://www.comodo.com/boclean/trolist.html

As is explained there (and in my post), this is based on the standard AV’s use of individual signature files for each variant.

LM

Oh,a Comode mod /fanboy quotes a Comode site of two million,I stand corrected,lol.Prove it!

It’s back. :stuck_out_tongue:

actually, he just did, and we all saw it…
did you miss it? :slight_smile:

Melih

Well I installed it under safe mode and im am VERY pleased. BOclean scans after the application has been launched so it does not interfere with any of my security products. Allows all updates, and no visible conflictions! I have to say BOclean is a very good new layer of protection, and since it is so light weight, I dont have to worry about computer slow downs!

You summarised it perfectly Info-Sec.
Thats exactly what Boclean is designed to do. And the other advantage is that malware comes in many different disguises to defeat AV products (called Packers… think of it as clothes)… AV sees a new kind of packing (clothes) and it thinks its a new person and not a baddie and it doesn’t catch it. however boclean, because it lets the application get “naked” (as you have to be to execute the application in your CPU) before it checks, none of these disguises will work :slight_smile: Hence make Boclean a very effective “Last Layer” protection. Its your insurance in case your AV fails! (and they do!).

Melih

I am just wondering is there an advantage to installing in safe mode. I installed from the web site not using safe mode and don’t see any thing that could be lacking.

Hi,

By installing in safe mode, you reduce the risk of the install conflicting with any running programs or services. It isn’t a must do, but it can help prevent conflicts and is often recommended - especially for security applications.

Mike

OK thanks for the info. I guess I had no conflicts doing it the regular way, as it is just purring along.

                                  :■■■■

That’s good to hear. :wink:

Marking this resolved and locking it up.
If the OP needs it reopened please IM a Mod.