COMODO Cleaning Essentials 2.0.212902.151 BETA Released!

Guys…please understand!
If CCE says that DNS is changed that means DNS is changed!
It could be Google DNS, Comodo DNS and malware DNS, but it’s changed!
That was said several times, CCE is nor for everyone.

This option is to detect network settings changes to improve cleaning capabilities and restoring network connection.
And yes, every change made to your DNS will be shown as a “Changed” - no matter if Comodo DNS or any other. You can simply ignore them if you know that you have done this change - anyway - see on risk, it’s low.

Thanks!

Thanks for the release…:slight_smile: ;D

Indeed CCE is a Sys Admin Tool rather than end user tool. Its a very powerful tool and in the hands of novice users they could be causing issues to themselves. CCE IS A VERY POWERFUL TOOL AND MUST BE USED WITH CARE!!!

Thanxx for the info. Understood now.

Regards
Naren

Hello,

KillSwitch beta can’t find CCE.exe (PID 3228 Error not found)

edit: Sorry, after reboot OK

[attachment deleted by admin]

this is a great release i love the smart scan feature

egemen can something be done with the leftover registry entries after the malware is deleted?
there are a bunch of keys that say file not found can comodo add something that checks for these and deletes them?

[attachment deleted by admin]

Autoruns analyser with verdict is great :slight_smile:

Is there any way I can get a view of everything executable (inc modules) running on my computer with verdict.

Modules seem to be listed under processes, meaning you have to click on each process to see the verdicts on all the modules on your computer.

Seem to remember at least an ‘all modules’ view in past versions but now cannot find it. Probably missing something obvious.

Best wishes

Mouse

KS->Show only unsafe images in memory option will show you all the executables that are NOT safe.

Thanks Egemen, was confused by the fact that the pane still says processes. Though I realise terminology in this area is very ill-defined

Semantic entropy strikes again :slight_smile:

Autoruns has found processes that the sysinternals tool did not seem to. :■■■■

No malware thankfully. Well one toolbar, but from a reputable CD burner software company (Cyberlink) whose software I did install, so probably OK, though they should have signed.

Good stuff

Mouse

CAR is the most comprehensive autorun analyzer in the market as far as i know.

Mine only finds ‘Tasks’ :cry: :-\ >:( But I’m sure it will be fixed soon ;D

Did you try to delete the folder? maybe re-download CCE?

The program is no more portable? It insists on copying files to the hard disk even when in USB drive.

:smiley: all i can say is WOW… killswitch + the new autoruns feature …WOW. my new favorite set of tools for cleaning… well done Comodo :Jiggy:

looks like some system files were classified as malware (Heur.corrupted)

http://wstaw.org/m/2011/10/20/sshot-2.png

Can you please attach them here?

Normally the PE header should be corrupt in this case… not the best files to have corrupt :wink:

Checked now and they are not longer detected.

The newest KillSwitch/CCE seems to be easily killed by ZeroAccess.
Autorun analyzer was the only on that could stand alone in that battle vs rootkit :slight_smile:
I can send you a sample if you want so.

2 things that need to be fixed:

  1. Aggressive mode is not enough against fakeAVs,
  2. ZeroAccess can still easily kill CCE/Killswitch.

Send me the sample pls.