CIS Test

CIS 5.9 Latest Test with Default Settings on real system XP SP3
No other security software
CTM Beta installed

I did a rightclick scan on 281 zeroday malware from last 7 days. Of which CIS missed 70 malware.

I run all 70 malware. Few were autosandboxed & I clicked block on all the D+ alerts.

After restart KillSwith showed no Unknown/Malware active processes.

After restart few changes -

2 files start automatically, rfw1973124 & Virtual-Families

2 desktop icons

1 msconfig-startup entry i.e rwf1973124

1 icon in C Drive, DelUS

Internet Explorer Favourite changed i.e chinese entries

21 files in Trusted Files of which 4 were scanned & found safe by cloud.

Attached are all the related screenshots.

Are the files safe or malware? In Trusted Lists coz of TVL or Internal TVL?

Can anyone check this? I have 21 files zipped.

Thanxx
Naren

File Link - hxxp://uploading.com/files/bd3e1625/Malware/
Password is pass

[attachment deleted by admin]

Testing it will let u the results as soon as possible
By the way you used the stock setting right no change

your submited ‘21 files’ is all safe exclude ‘speeder.exe’

https://valkyrie.comodo.com/Result.html?sha1=165537e24db4338f713cffc1f190116a90206fcd&&query=0&&filename=speeder.exe

this file is re-submitted.

this is my analyzed result, COMODO Analysts’ opinions may vary.

I bet this file is safe, look at the first time it was seen on VT, 2006. And only 6 detections, only one of those vendors anti-vir is reputable and I can bet that it is a FP.

Ok i did the test on winxp 32bit updated till date 1GB of ram only CIS with default settings and time machine installed and these are the results

  1. half the files are installers and mostly signed by trusted sources that’s why they are trusted

  2. some files contain or download malwares during installation or execution and some are detected by CIS (see screenshot)

  3. most of the files are detected by other vendors (check malware link below)

  4. some files are not detected or are completely safe (check safe file link below)

  5. some files are unknown to CIS and are sandboxed (see screenshot)

  6. during the test the computers performance was not affected except for when “speederxp.exe” was executed inside the sandbox the computer came almost to a halt

No Detection or Safe files

amh-uni

http://anubis.iseclab.org/?action=result&task_id=1a83f87eecb918f440d83026f116b1429&format=html
https://valkyrie.comodo.com/Result.aspx?sha1=7fb4defe3ec57ab593365c7df938422db573bac8&&&query=0&filename=amh%u2014uni.exe

converter_downloader

http://anubis.iseclab.org/?action=result&task_id=10d49e0c6b2da0124e573f51e4b26c33c&format=html
https://valkyrie.comodo.com/Result.html?sha1=8a2ba5aee6ed30557fb472ac12cfdfc33c219738&&query=0&&filename=converter__downloader.exe

utorrent

http://anubis.iseclab.org/?action=result&task_id=16d9128d594f20b24c9770f1c958bc654&format=html
https://valkyrie.comodo.com/Result.html?sha1=f4dacada8286795589f51dae06e1b4522a1baaf0&&query=0&&filename=utorrent.exe

wReplace12

http://anubis.iseclab.org/?action=result&task_id=103d385b645da1b0481d55aa1cb53348f&format=html
https://valkyrie.comodo.com/Result.html?sha1=ff0e0b68d9237edc70fef5b267b82af4dd48ce86&&query=0&&filename=wreplace12.exe

youtube-flv-downloader

http://anubis.iseclab.org/?action=result&task_id=14e0cfcbf5173167471181c0e81257710&format=html
https://valkyrie.comodo.com/Result.html?sha1=6ae07b2f8696768ee7177b4c26bec8a64474a3cd&&query=0&&filename=youtube—flv—downloader.exe

Malware DEtection

EurostarJewelry-Notify

http://anubis.iseclab.org/?action=result&task_id=1c8eb2c697a3e38f44ddf29e2e698ea75&format=html
https://valkyrie.comodo.com/Result.html?sha1=7e323a1602bd4b6744b394fe1bcd13b9a548055f

more_fun_tasty_coffee_maker_cup_recipes_to_impress

http://anubis.iseclab.org/?action=result&task_id=159ceff155612141415eb581b9a20201b&format=html
https://valkyrie.comodo.com/Result.html?sha1=71869d5c8ab6845435a115bcf7fc97d6b8e91513

SetupCasino_641f

http://anubis.iseclab.org/?action=result&task_id=14482f19ec487cfe4c9a21f818cea54d7&format=html
https://valkyrie.comodo.com/Result.html?sha1=506216abc713bee89f5abdf2db7687479fdbbfd8

speeder

http://anubis.iseclab.org/?action=result&task_id=1458807226ce2ed940df618504df89ac0&format=html
https://valkyrie.comodo.com/Result.html?sha1=165537e24db4338f713cffc1f190116a90206fcd

3DP_Chip_v902b25

http://anubis.iseclab.org/?action=result&task_id=17bffa9bad98e44b4ed2e368f2f2c3175&format=html
https://valkyrie.comodo.com/Result.html?sha1=3a34259dc32607d2cb15f52d16befc28fed8bdcf&&query=0&&filename=3dp__chip__v902b25.exe

alien-attack

http://anubis.iseclab.org/?action=result&task_id=18f53369d3e3b032431f951d2c8cfbe7d&format=html
https://valkyrie.comodo.com/Result.html?sha1=d769733c4b02efc71b3e8a1673c831735d01324d&&query=0&&filename=alien—attack.exe

buildwindgenerator

http://anubis.iseclab.org/?action=result&task_id=1db188e99b6a2dd74a9f14377fcf017ab&format=html
https://valkyrie.comodo.com/Result.html?sha1=dbaedbf2215a0b4a2683e54559bbe2fcaf38c60b

cd-client-4_33_4-en

http://anubis.iseclab.org/?action=result&task_id=1801f2e3f6d1ecf74b5affa15ff1dcacf&format=html
https://valkyrie.comodo.com/Result.html?sha1=e84a93507984d7d36f9c3578fd57fbca06689bca&&query=0&&filename=cd—client—4__33__4—en.exe

christmas16-santas-workshop

http://anubis.iseclab.org/?action=result&task_id=132a3f03d323d39943971c8a9cac22773&format=html
https://valkyrie.comodo.com/Result.html?sha1=6915f0b9ff3ca233dff42a30e79d17399d2efca9

exp6wba

http://anubis.iseclab.org/?action=result&task_id=13de72c2bcceaab7451ef60a30946e66e&format=html
https://valkyrie.comodo.com/Result.html?sha1=47274c5162c76cb366cd3f13962742974c98fd5d&&query=0&&filename=exp6wba.exe

klite272

http://anubis.iseclab.org/?action=result&task_id=1b86d381e9aedd144653158024e07086c&format=html
https://valkyrie.comodo.com/Result.html?sha1=23c83152e5dfdef41ff9366067d40e307b226500&&query=0&&filename=klite272.exe

loveyounot11

http://anubis.iseclab.org/?action=result&task_id=11ebc79916b347664a95558f0ee7056e6&format=html
https://valkyrie.comodo.com/Result.html?sha1=b20f548b4d800afcc4e266db9de8b5d262c4fc6a&&query=0&&filename=loveyounot11.exe

Mir2Patch20110926
https://www.virustotal.com/file/f42934c4343bf894f7db29b2d97fac2b3354516ca5895a43708a78d4916660ff/analysis/1327552489/
http://anubis.iseclab.org/?action=result&task_id=18dbe1babe6644374617aa777ced35e1c&format=html
https://valkyrie.comodo.com/Result.html?sha1=97ec52afffe7242c7325551bfa2f0f113401abb0&&query=0&&filename=mir2patch20110926.exe

mvregcompactportable
https://www.virustotal.com/file/41558fb972295a8317a6f1e3c25f5b2c139e7eb22f614065c1fd92c0aa4950d7/analysis/1327552491/
http://anubis.iseclab.org/?action=result&task_id=1371d57d357ae95346523f8e0f5e97e4f&format=html
https://valkyrie.comodo.com/Result.html?sha1=5665bd91d580fd8e4c3dd787b1f3b629a6afc07d&&query=0&&filename=mvregcompactportable.exe

rfw1973124
https://www.virustotal.com/file/e9781f0947f40080b75e32d72a2cc6551bfe74e6e983661132e41fca9053f6cb/analysis/1327552776/
http://anubis.iseclab.org/?action=result&task_id=13d40546f6e5ac304195507a45c79f850&format=html
https://valkyrie.comodo.com/Result.html?sha1=ec88499ca540a1c6968589c17b14fddfb6f43cc8&&query=0&&filename=rfw1973124.exe

Virtual-Families
https://www.virustotal.com/file/31bab278396218f47fa84d77d192aa7eb0e90e5b016a8b3e3336c5ee7a46b927/analysis/1327552781/
http://anubis.iseclab.org/?action=result&task_id=1416d9df5554316244950656bab76ef41&format=html
https://valkyrie.comodo.com/Result.html?sha1=433086327b460745c53876024a6f9626b91c4519&&query=0&&filename=virtual—families.exe

[attachment deleted by admin]

Yes stock settings. And I clicked block on each & every D+ alerts.

loveboy_lion

So 16 out of 21 files are detected as malware. Are these really malware? And they were in Trusted Files coz of TVL? Its very tough to check the TVL. There should be a search function.

Thanxx for the test.

Yesterday I was testing CIS Suite Free latest on real system XP SP3. I ran 50 zeroday malware.

And yesterday I came to know why executing malware test is better than rightclick scan.

Out of 50 malware Comodo AV detected 27 & the amazing part was Comodo Cloud AV detected more 10 malware, so thats 37/50. Same samples tested against Kaspersky IS 2012 26/50. Others got popups & few missed.

But the reason of the post is here.

While testing a full screen malware appeared. I wasn’t able to get to the desktop. I tried alt + tab but was not possible. I tried to open KillSwitch as I have replaced taskmanager with KS. It initiated but started behind the fullscreen malware. I wasn’t able to get KillSwitch on top of full screen malware. Then again I was trying alt + tab I saw Comodo Cloud AV alert & it appeared on top of full screen malware. 4 alert were there & I clicked clean & the full screen malware was gone, great work by cloud av.

Nothing including KillSwitch was able to be on top of full screen malware but Cloud Alert was which solved the thing.

How Cloud Alert was able to appear on top of malware?
Why KillSwitch was not able to appear on top of malware? In this situation how can I access killswitch so that I can kill the malware?

was this enabled in killswitch
option > always on top

This was not enabled.

I think this should be enabled by default.

Enabled this & checking now.

Hi Naren. Thanks for the test and yes it is daft not having on top in killswitch enabled by default as these full screen malware are sneaky little devils and its only common sense in my opinion to have it enabled.Can you imagine the bother a less knowledgeable person would have if he was infected by such and did not have it enabled.

Regards
Dave1234.

I dont have the full screen malware now.

But I have the same malware, not full screen but rectangular window.

This malware does not allow me to take the cursor out of its window so I am not able to access KillSwitch when it is opened.

But if the KillSwitch position is not by the side of this malware window but on top of the malware then you can access KillSwitch & kill it i.e KillSwitch position should be on the top of malware when you open KillSwitch as the malware does not allows the cursor outside of its window & if KillSwitch position is by the side of malware when it is opened then you cant access KillSwitch.