Comodo Memory Guardian Beta v1.0.1.5 Bug Reports [Closed]

Today, in our office one guy noticed the same issue. The most strange thing is that as soon as he closed cmg.exe BOClean backed to normal state… That’s very strange, 'cause cmg.exe is nothing but some “server” app to recieve&log attack notifications from the clients and draw an attack dialog (kill/allow)

Hey, my BOCore is actually 2.7 MB right now, and nothing happened when I closed CMG. Is 2.7 MB too much? Maybe I’m not so lucky after all? At least BOClean doesn’t seem to hang up here.

/LA

EDIT: As I was browsing around here, having no other programs open - and CMG still shut down - BOClean suddenly crashed?!

[attachment deleted by admin]

To make things even more strange, I never got the chance to uninstall/reinstall CMG as per my posts yesterday.

However (and this is the strange part), BOC has not frozen yet today. Not a single blip from it.

How’s that for “Huh??”

LM

I wonder if a past BOclean update could have caused this problem…and then maybe corrected with a newer update. But, on the other hand CMG Beta 1.0.1.5 was released on Aug 23 when these problems started.

Speaking of uninstalling; I did so, and found another bug (minor, but still): the start up entry was not removed by the uninstaller, I had to do it manually.

(XP SP2 32 bit)

/LA

Ditto:

https://forums.comodo.com/comodo_memory_guardian_beta_corner/comodo_memory_guardian_beta_v1015_bug_reports-t11996.0.html;msg84730#msg84730

My usual registry cleaners did not pick this up. I only found it when I ran a hijack this scan.

:SMLR

Ah, so that was the key that the CMG uninstaller forgot in your case. Now things have been clarified! :slight_smile:

I though registry cleaners was supposed to find those things. For me it was a coincidence as I looked in CCleaner which start up entries I had left, after uninstalling CMG.

/LA

Hey Tyler :slight_smile:

Maybe it sounds strange to you, but I am happy it happened to one of your guys too. So you see it is a serious problem. But again : Personaly I think this is a CBOClean problem ( even a version 4.25 problem if you ask me) triggered by CMG, and maybe also by some other programs ( maybe NOD 32 ? ).

Greetz, Red.

About BOClean lock: https://forums.comodo.com/empty-t12075.0.html;topicseen‏
As soon as it seems that BOClean locks even without installed CMG, I think it’s not a problem of CMG.

I agree, but somehow CMG can trigger the problem. And in the CBOClean forum part no one of the Staff takes the effort to give a reaction. So far you are the only one :-\

Greetz, Red.

I have Antivir anti-virus and it thinks it is an unwanted program. I sent some files to them so maybe they will have a new definition for it.

BTW test32.exe (tesst app for CMG) I’ wrote in assembler and it’s less then 1kb, so some “antiviruses” think that it’s a virus :slight_smile: Don’t be afraid :slight_smile:

This file cann’t be blocked . When I read the word file , the CPU will be used fully . The file must be pened by office2003 .

[attachment deleted by admin]

This exploit doesn’t work on your office mate. It’s just a very old PoC.

Maybe it is really very old , but it does work on my machine , I use office2003 , when I open that file , CPU is used fully by word.exe , but there is no alert for that . why ?

[attachment deleted by admin]

No shellcode executed by it, because it doesn’t work. Corresponding version of the Office is not enough to make it work mate, you need exactly the same OS version/language for this exploit. And when it’ll work, CMG will detect it. 'Cause CMG does not detect a strange behavior but a shellcode execution on BO.

I’ve fixed this exploit to make it work (now it should execute cmd.exe) but the “shellcode” is very OS specific (calls API by a hardcoded address in ret2libc manner), so probably it’ll not work on you version of Windows (mine is XP SP2 Russian. Send me pls your version, so I can make it works for you, if you want). I can’t inject the real shellcode into it 'cause the stack buffer is very small in this vulnerability. That’s why it’s just a PoC I think.

[attachment deleted by admin]

This one is also intercepted by Avira, on any version of Windows. :smiley:

Yep :slight_smile: It’s intercepted by it’s behavior analizer. E.g. eEye Blink “intercepts” any .exe which calls GetModuleHandle, funny :slight_smile: It’s very easy to avoid mates, e.g. almost any “blockers” skips LdrLoadDll instead of LoadLibrary…

I deinstalled CMG for now because of the probs with CBOClean.

Greetz, Red.