Comodo Cloud AV Test Results & Reviews

Hi, I have tested Comodo Cloud Antivirus 1.1.387596.183 with default settings, against Crypt0L0cker/TorrentLocker,

Windows 7 32Bit VirtualBox

(have Submited this file and reported it to Comodo Blacklist)
SHA256: d5b35d55be8f392b89da3e29880a4563d45bdc59cfc4cbba29796f77d4ad65f7

The Ransomware was sandboxed at first, however the files became encrypted a few seconds later
and the Ransomware Notice stay sandboxed.

Didn’t know where to post it so i posted it here.

Edit: found a post/blog about this Crypt0L0cker/TorrentLocker

[attachment deleted by admin]

That’s strange, few weeks ago cruelsister tested CCAV vs. a keylogger and the result was that Viruscope stopped that keylogger from sending information to the internet https://forums.comodo.com/beta-corner-ccav/comodo-cloud-antivirus-first-public-beta-release-t113498.0.html;msg822843#msg822843

I wonder why that didn’t happen with this ransomware…

Yep.

I have tested COMODO Cloud Antivirus against:
about 8 lucky and 1 Serber Ransomware and system stayed clean.
but when i ran it against Cryptolocker the files become encrypted.

Viruscope remained asleep;
The problem of the CIS, and other CCAV suites allow safe procedures, certificates … allowed success in implementing the “trojancrypt”;
In proac- configuration kept secure system but allowed safe processes run. This can be misleading, incluive I;
At least in virtualization, the CIS the main machine has not delivered an alert when the “trojancrypt” was performed with the CCAV and CIS virtual machine, the malware was able to encrypt main machine files.

A viable solution was to block any file access folders and files

Edit: Trojancrypt can encrypt files on shared networks (at least in procedures done by virtual machines, it is proven). So safe applications or certificates will never be reliable and should be blocked access to folders and files, either by direct memory access, instance, folders, injection …;

Processes are the main problems of this type of malware. It is through these processes residing in memory and are considered safe, that run in the background and allow malware to gain success in their implementation. This should never happen!

Edit 2:
encrypted files in the shared folder, allow unrestricted access trusted file is safe? (see image)

[attachment deleted by admin]

Test Panda Free & Comodo Cloud Antivirus

Hi, I have tested Comodo Cloud Antivirus 1.3.395640.279 with default settings, against Crypt0L0cker

Windows 7 32Bit VirtualBox

The Ransomware was sandboxed at first, however the files became encrypted a few seconds/min later. :cry:

Link to my test (Video).
http://www.megafileupload.com/o2oZ/ccav_vs_cryptolocker.zip

Edit: when you click the download button the web page refresh it self, and you have to click the download button again.
Edit: my mouse isent visible for some reason. ???
Edit: CIS, Sandbox does protect my Virtual machine from this Cryptolocker. :-TU

How to download your test video as unregistered user?
I click on free/slow download & same page refresh?

you have to click the download button once more after the page refresh. strange ???

I tried couple times but the same page refresh.

Anyway I got it. It seems uBlock Origin was blocking something, disabling UO worked.

Hi BlueTesla,

Could you please also send me the cryptolocker sample ? After we test, will get back to you. Thanks in advance.

Kind Regards
Buket

Yea, i will PM you the link to the download site Filedropper.

And stickied.

HI just wondering how the results were for that crypto file ? Thks

I haven’t done a video in a long time so I think I might do one again and use CCAV to make a comeback. Now I need to start finding links and samples again.

Hi all

Comodo Cloud Antivirus Prevention and Detection Test

With best Regards
Mops21

Hello Mops, I split your post from the CIS Tests topic and merged it with this.

Just for curiosity

Comodo Cloud Antivirus is a good program, just missing an option to be able to open the program interface in the event of a ransomware or trusted programs (insurance programs we use on a daily basis as games, for example) always locked at the top;
A button to reset the Sandbox …

The bypass in CCAV 1.3 vs cryptolocker have been fixed in CCAV 1.4.39 :-TU
(Thanks for the reminder Davidov :))

i have Tested CCAV 1.5 vs the cryptolocker sample today and saw no bypass. :slight_smile:
Windows 7 32Bit VirtualBox

Link to video:
http://www31.zippyshare.com/v/rvDfonZ2/file.html
or
http://www.megafileupload.com/7rb5/Comodo_cloud_antivirus_vs_cryptolocker_bypass_fixed.mp4?pt=trOkUjMQ0kvbruiHZ51d%2FBPjJJYtRIt5ZnMscXTMBJ4%3D
Note: you might have to click on “Slow Download” button multiple times to trigger the download.

old post.
https://forums.comodo.com/news-announcements-feedback-ccav/comodo-cloud-av-test-results-reviews-t114685.0.html;msg839753#msg839753

In the video cryptolocker can still open the files. ???