Please post your screenshots of KillSwitch

I gotcha ;D. Ran KS again but no new entries detected. However, it’s name has changed :-.

:slight_smile:

have you tried searching the registry for that name, you could also use Autoruns from sysinternals to find the ‘Driver’ location for the running process, maybe it’s in CCE’s folder :wink:

I found ydrukp in registry but no reference to what it is or where it’s located. No reference to hidden service in registry or autorums.

:slight_smile:

HI,

Any idea about this suspicious services: [hidden]KKillSwitch2? (Please See the following attached screen shot)

[attachment deleted by admin]

Hi WinBMY

I would say this service is legit (being KillSwitch’s service) as I have this service running also. From my previous post (inc. screenshots) I believe this service was also present but detected under a different name.

I would be more worried about the service above with the odd name. I had a similar type of service but since restoring to my base image, it is no longer there.

:slight_smile:

Well, the sheeper behavior of VirusTotal mess the DACS response (false positives). You submit a clean file and then antivirus start the detection :stuck_out_tongue:
Second, the “unknown” files, even when submitted a lot of times to Comodo, never get a clean status from it.

[attachment deleted by admin]

These files are recognised and trusted by CIS, but unknown to KS. ???

[attachment deleted by admin]

Each time it is worse… What’s happening with the quality of DACS? Poor job…
I’ve already submitted and reported a lot of these files and uploaded some of them.
Why does the virus lab do nothing?

[attachment deleted by admin]

thats remember me: https://forums.comodo.com/comodo-cleaning-essentials-cce-killswitch-cce/please-post-your-screenshots-of-killswitch-t67230.0.html;msg476708#msg476708

i have submitted netbalancer and coretemp to be white listed on dacs some long weeks ago:
https://forums.comodo.com/news-announcements-feedback-cis/submit-applications-here-to-be-whitelisted-2011-t66773.0.html;msg493175#msg493175
https://forums.comodo.com/news-announcements-feedback-cis/submit-applications-here-to-be-whitelisted-2011-t66773.0.html;msg476761#msg476761
if you go down you will see i get response
but both program still in FLS:unknow state

i think the white list team only check the installer but not the app installed

kinemitor, if this is the case, there is no meaning on submitting info to the virus lab… After all, everything is unknown :cry:

Sorry for heard about this. I will have virus lab to check these issues. And give you answer asap.

Thanks,
Doskey.

Killswitch is very very good.
See Scren.

(KMService.exe)

Congratulations to Comodo

[attachment deleted by admin]

It a little better… But I can’t understand that submitted files are still ignored (unknown)… >:(
I have sent the files to Haibo Zhang in March, 8 :embarassed:

FlashPaste.exe (Professional Edition): http://flashpaste.com/
sTabLaucher.exe: http://stablauncher.com/
AeroWeather: http://spikex.net/2010/04/aeroweather-weather-based-aero-color/

Bad support response :cry:

[attachment deleted by admin]

The best way to get files added to the whitelist is to post them in Submit Applications Here To Be Whitelisted - 2011. The staff will reply to your post twice to confirm that they have received your request, and then a second time when the files have been added to the whitelist.

They have a bit of a backlog at times so it can take a while for some submissions to get processed, but they’ll get to it eventually. :slight_smile:

They said that the better will be in the false positive thread… So…

Take a while?
Well, since the first release of KillSwitch beta I’m facing the same problems…

Some seconds after that, KillSwitch report is worse…
What’s going on?
Is it reliable?

[attachment deleted by admin]

http://dl.dropbox.com/u/4600837/comodoss.png

Safe application. Used for Sending Faxes through a Samsung Multifunctional Printer for your PC

The other app though… Looks dodgy to me :wink: ;D

My KillSwitch is completely clean now… Everything is shown as safe :-TU

Hello there

Second post here :smiley:

Here is my screenshot :

This process is related to Cyberlink

Regards

AV Tube is definitely safe.

Thaks again to Comodo for my Personal Edition Killswitch. My friend is asking for that too. Can I give him my activation code? He wants registration for his name. If I give him my activation code won’t COMODO cancel my Personal Edition Killswitch activation? and it again goes down to general edition? I love additional functions of the Personal Edition.

:love:

[attachment deleted by admin]