Sorry for the size of the images.
No file was detected by Valkyrie, I showed 2, but I have many with the same result.
Sorry for the size of the images.
No file was detected by Valkyrie, I showed 2, but I have many with the same result.
Thanks for sharing,
I understand what happened here, we seem to have some syncing issues internally in database where file classified as malware by Valkyrie not reflected in cloud.
May you please PM me similar hashes you have?
Thanks
-umesh
First quick scan finished within 5 minutes :-TU
It’s own installation files ccav_installer.exe and ccav_installer_beta.exe are not been trusted and send for analysis :o
Congrats on the release! CCAV looks to be really improving and making great steps. Here are some observations about the new version
Issue (I can do full bug reports if needed):
That synchronization is vital. valkyrie.comodo.com and valkyrie look up in CCAV must use this same database (many times I’ve seen file already analyzed and verdicted as malware at valkyrie.comodo.com and CCAV being silent after running this on PC). Also, valkyrie must feed its verdicts to FLS (both valkyrie.comodo.com and via CCAV).
Already day is analysis Valkyrie 3 files, long
Please consider this one, it will be usefull :-TU
Yesterday i tried to run a full scan with CCAV 1.9 Beta and got the massage Cloud not connect to cloud server, Reconnecting.
Tried it today and got the same massage.
Decided to reinstall CCAV and that fixed the problem.
With CCAV 1.8 the fullscan took was 4h 16min,
I will let you know when it done and how long it took.
16% 25 min
Files Scanned 26441
18% 59 min
Files Scanned 26451
Edit: CCAV have a problem to scan a libglesv2.dll file and it belongs to a game called World of Tanks.
The disk activity is 14 to 30 MB/s and cpu load are 1 to 4%, and it can take aprox 10 to 17 min to scan that file.
Some time the disk activity peak up to 180 MB/s and the cpu peak up to 60% for a few secounds and then back to the above value.
Its same for CCAV 1.8 and it’s not unique to CCAV 1.9.
Edit:
Full scan completed on 2h 2min
Files scanned 36791
Hi Felipe Oliveira,
Thanks for providing hashes.
We analyzed hashes and they all seem to have malware verdict due to automated valkyrie analysis but still need human verdict before they are visible via cloud.
In certain cases we want to be sure and improve auto mated system before we can fully trust.
So that explains the behavior you have observed. It’s a continuous process where we apply new heuristics and after they are matured, we can full rely on them without requiring human analysis.
Thanks
-umesh
Hi hkjoj,
May you please provide screenshot?
In general, if you try to submit file and if file is already safe, you get a message that file is already trusted.
For both setups examples you should have received trusted message.
Thanks
-umesh
Hi wasgij6,
Thanks for feedback.
2. Can you please remove the swiping animation when navigating in the settings? This is very annoying and is not very consistant.Agree.
Issue (I can do full bug reports if needed): 1. If ccav detects a file as malware using signatures a popup is shown after selecting quarantine ccav then shows a sandbox alert asking if i want to sandbox the file (i have the sandbox set to alert)Thanks, i can produce the behavior you observed.
Thanks
-umesh
Hi morphiusz,
We have had lot of cases in the past where syncing could have taken longer but we have greatly improved and such cases should have reduced now.
As pointed earlier, in some cases Valkyrie results need to be further analyzed to be confirmed malware and reflected in cloud.
We will make some changes in Valkyrie GUI to make it explicit that verdict may yet not available in cloud or pending further investigation to avoid such confusion.
Thanks
-umesh
We will consider, may be restricting to certain maximum number of files at a time.
Our current prioritization on Valkyrie is to analyze files, which have run in Sandbox.
Thanks
-umesh
Hi BlueTesta,
Thanks for testing it out.
Edit: CCAV have a problem to scan a libglesv2.dll file and it belongs to a game called World of Tanks. The disk activity is 14 to 30 MB/s and cpu load are 1 to 4%, and it can take aprox 10 to 17 min to scan that file.May you please PM me sha-1 of file and we can see if we can produce same behavior?
Full scan completed on 2h 2min Files scanned 36791Great!
Thanks
-umesh
Umesh, could you explain e.g. this case?
Is it a case with pending human analysis or lack of synchronization of databeses? I don’t except the signature to be created for FLS so fast, at least CCAV which analyzes it with valkyrie should give the verdict almost immediately, right? Since it was scanned previously by valkyrie.
Hi megaherz33,
You mean you have 3 files that ran in Sandbox and yet to be given verdict?
Thanks
-umesh
Yes
Files:
sentry.exe
SputnikUpdateOnDemand.exe
SputnikCrashHandler.exe
Files owned browser Sputnik (Russian)
Hello umesh,
Here is my experience with this beta on Win 10 64 Pro with 6GB RAM with Windows Firewall
Other programs that start with Windows
Adguard Desktop
FlashBack V2
Pros
Good GUI - Default Black (others, see Cons)
Full Scan completed in 2 Hours 30 Mins (Last 2 stable versions, one time, Full Scan completed in 5-6 hours & second time, after 4 hours & 30 mins, got cloud couldn’t connect & didn’t reconnected for a long time)
Cons
Theme not working i.e tried light & classic & after GUI restart, theme still default i.e dark
Boot time long
After boot, on reaching desktop, taskbar icons load take time
Restart/Shutdown time long
Lag issue i.e programs opening, installing, etc
Idle disk usage i.e not doing or opened anything on the system - fluctuate between 30-60%
Dis usage i.e programs opened, install, etc - 95-100% i.e after program is opened or install completed, back to “idle disk usage” mentioned above i.e fluctuate between 30-60%
Sandbox/AV test
LeakTest from grc.com - rightclick Valkyrie mention “Malicious”. If I run, is not sandboxed or detected. “Detected Threats” section mention “Trusted”.
PotentiallyUnwanted from AMTSO - same as “LeakTest” mentioned above.
CloudCar from AMTSO - was automatically detected & quarantined after download. “Detected Threats” section mention “Trusted”.
Update
After CCAV uninstall, boot, restart, shutdown, disk usage, etc back to normal.
I use CFW on this system with Proactive config, HIPS disabled, ViruScope set to monitor sandboxed programs only, other customizations Plus UAC disabled, Smart Screen disabled, Windows Defender disabled through Group Policy And no other 3rd party Antivirus…No above mentioned probs with this setup.
I uninstalled CFW, enabled Windows Firewall & kept the same above mentioned setup for CCAV test.
CFW runs excellent here, after boot, on reaching desktop, immediately I can run any programs & programs run quick.
CCAV, long boot time, on reaching desktop, taskbar icons load take time, rest I have mentioned above.
As mentioned programs response, etc is slow. First time programs response is slow, second time is quick. BUT after system restart, for the same programs (19 portable programs), I noticed the same behavior i.e first time programs response is slow, second time is quick.
Thank You
Hi Yash Khan,
Thanks for detailed report.
Now scan speed is improved, we are going to further focus on improving overall performance improvements and report back in next releases.
LeakTest from grc.com - rightclick Valkyrie mention "Malicious". If I run, is not sandboxed or detected. "Detected Threats" section mention "Trusted".I downloaded leaktest from following location and CCAV detected and offered for quarantining: https://www.grc.com/lt/leaktest.htm Can you please share SHA-1 of file you tested?
PotentiallyUnwanted from AMTSO - same as "LeakTest" mentioned above.Please provide sha-1 of sample.
Thanks
-umesh
Hi
Yesterday it was all good. Today writes “A communication error with the cloud server”
When you solve this problem permanently?
Quick and Full scan issued a communication error with the server by 8%