Good cleaning technique (disinfection) is as important as detection

First of all, thank you Comodo for protecting my computer for years… yes since the days of CFP 2 and CAVS 2! Even in the days the detection rates were said to be lower compared to others, I stuck to CFP & CAVS. Since the inception of CIS 3.0 it has become better and would detect the virus before it can wreck havoc in my computer.

However, recently, I installed CIS in one of my friend’s computer. Unfortunately, the computer was infected with some Virut virus. Immediately after updating the antivirus, the CIS (realtime detection) said that virut virus was found in the computer and CIS automatically quarantined it. Nice to hear…. But no! CIS detected virut injection in wuauclt.exe, explorer.exe etc. and quarantined it. Within seconds the computer was without a desktop screen and icons. I right clicked on start button to open explorer.exe and explorer.exe was quarantined. I tried to open taskmanager and it was also quarantined. In short, as a layman, I understand that in case if any exe file is opened, the said ‘virut’ would make a hook into it and CIS antivirus would detect it as virut and quarantine it. (I have no idea why defense+ didn’t give any alert). From my friend’s point of view, the computer which was otherwise working was dead within seconds.

Ultimately, the screen was without any usable think as right click of mouse also didn’t give me any options and without a taskmanager, explorer and a desktop screen not even showing the icons the computer was of no use. I had to hardboot by pressing reboot and the screen again returned to the blank screen. Tried safe mode same result (as explorer and wuauclt and taskmanager was quarantined). Fortunately, I hadn’t tried cmd.exe, so I got the option of safe mode with command prompt. Opened CIS through command prompt but the antivirus gave error message that the ‘quarantined files cannot be restored’ stating some code number mentioning that the feature is not supported. Ultimately, I disabled CIS antivirus rebooted it and then copied the above files from another computer and pasted it in its respective places and removed CIS antivirus. Installed MSE and MSE detected the same files, but, ‘disinfected’ it from virut and the computer continued to run without any problems while the viruses were removed. (After removal I scanned the same using CCE & MBAM to confirm that virus is not hiding somewhere, but, it turned out to be a clean computer)

My point is… disinfection feature is a must to deal with the already infected computers, otherwise, reformat of the computer would be the only option. I hope that the antivirus in CIS 6.0 with killswitch and acid cleaning technologies dons these capabilities.

Easier said than done, as some people still store everything in c drive and an operating system reinstall would erase the same. Again, the option to completely get rid of everything is by a clean installation including the partitions (to remove possible MBR infections also). So, all the data will go.

Yes, you can ask about backups… but everybody don’t always keep backups, as they never fear that their computer will die that way. (Don’t ridicule that they don’t deserve to use computer, as such things do happen)

Disinfection, as I said is important because as in the instant case I mentioned, CIS quarantined important operating system files thereby making the computer unusable. I got a workaround and succeeded in it. But, all may not be that lucky and he may never return to CIS. So, disinfection is a must, especially for infected systems. Had CIS been able to disinfect the virus (like MSE) and allow the computer to be able to run, there was chance to using other standalone antivirus / spywares to ensure that nothing is left behind.

I could have made my first post by making just a 1 line entry, but, that would not have shown the severity of issue or reason for asking the same. Hence, made it lengthy.

Did you try CCE? (Comodo cleaning essentials) which was purely designed for cleaning.

In CIS 6 beta. In scanner settings you can have it automatically have it either quarantine threats or disinfect threats it finds. I don’t know if it does a disinfection procedure if realtime scanning detects something. so You cna look forward to have a disinfection after a scan if CIS 6 final if they keep the feature.

