Malware Sandboxed as Partially Limited Can Restart Computer [V7B][M822]


  1. Product version: COMODO Internet Security 7.0.308911.4080 BETA
    2.Operating System:xp3 (x32) runing by VMware Player
    3.Configuration: Default IS configuration

4.Comodo failed to prevent the virus from the work of the restart
file bat Designed to work quickly before the intervention of behavior blocker but sandbox Prevent the damage but did not prevent the restart

  1. link video

Okay, so I see that it restarts when set to Partially Limited. Can you please try it with Limited, Restricted, and Untrusted, and find at which level it is not able to restart?

Thank you.

ok :slight_smile:

in limited can not restart :wink:

Sounds like partially limited should not be used. FV is nice because most programs can run in it. The FW offers protection when you auto-block all requests. :slight_smile:

Thank you for checking this. In that case can you please edit your first post so that it also includes the diagnostics report?

In addition, please upload this malware to a file sharing site and PM me a download link. I will adhere to the same rules you asked me to for the previous sample. However, this time I will be sure to not share the sample with any other users. I will just provide it in the tracker so that the devs can use it for evaluation purposes.

Thank you.

The sample has been sent :wink:

Thank you very much for your report in standard format, with all information supplied. The care you have taken is much appreciated by Comodo, and will increase the likelihood that this bug can be fixed.

Developers may or may not communicate with you in the forum or by PM/IM, depending on time availability and need. Because you have supplied complete information they may be able to replicate and fix the bug without doing so.

Many thanks again.

this is intended behavior not a bug

wasgij6, thank you for pointing this out.

In that case, sd ahmad, can you please switch to Proactive Security and let us know if it is able to restart under Proactive Security.

Thanks. :slight_smile:

Egeman made this post in response to a question about the FV sandbox. Not sure if the same thing actually applies to the partially limited sandbox. :-\

That’s a good point. The same might hold true for Partially Limited, but until I hear this from staff I think I’ll keep this bug report in the tracker.


Glad I could help Chiron.

Just to check can it restart computer in proactive mode?

It cannot.

Also, to everyone, I have gotten feedback from the devs that this is by design. The default configuration is not meant to protect against malware causing the computer to restart.

Thus, I will move this report to Resolved.

Thank you.

OK, Chiron thanks. That makes sense now.