We received over 2Gig of Malware last 24 hours from our users!!!!

AHH. I see, Shows how much i know about comodo 88)
I understand now.

Really? It always works for me. Make sure you dont have a rule or something on the firewall. I even submit files and get a response back: “ALREADY SUBMITTED BEFORE” or “ALREADY IN COMODO LABS UNDE EVAL.”

LOL. ;D
that’s ok. It happens to the best of us!

Well, we do receive those… but the ones that gets sent to me get priority :slight_smile:
So at this stage, until things calm down a bit, i would recommend using me as the point to push these malware into our system. The reason is cos we get huge amount of files (of which majority are non-malware) from these submissions. So sending the malware to me gets on top of the queue.

thank you

Melih

Great to see that everyone tries their best to help somehow.

(I hope you guys also use honeynets/honeypots)

Is it your private email address, or the “malwaresubmit {at} avlab.comodo {dot} com” one?

private pls.
thanks
Melih

Umm…where do I find your private email? Our am I supposed to PM you?

You can or pm them to melih and upload the malware to a remote server 2share/megashare/rapidshare or such. or follow the rules on this topic

https://forums.comodo.com/false_positivenegative_reporting_is_this_a_malware_that_cis_hasnot_detected/reporting_false_positivessuspicious_files_submitting_them_to_the_lab-t27062.0.html

Xan :slight_smile:

What happens when trojan downloaders are found\submitted (most of the malware embedded in websites)?

Do you just add those individual files to the database, or do your analysts let that malware do whatever it wants (i.e. download files) and monitor that process, so you can eliminate the entire “system” in one go? In other words, do you deal with a single file or with the x-number of files that automatically follow the first one as well?

AFAIK, they analyze the malware and then add it to the database. So it wil be whole the trojan I think…

Xan

Well, lets hope so. The names of these files are a bit odd and non-descriptive, which doesn’t look good to me. Like they can’t come up with a real name for new threats, or don’t check “beyond” the individual file (a trojan downloader in this case).


http://img370.imageshack.us/img370/4416/comodoeu3.gif


http://img370.imageshack.us/img370/comodoeu3.gif/1/w392.png

I’m a Comodo Firewall 3 and Avast! Antivirus user.
I think I may have tried Comodo AV in the past and decided it wasn’t matured enough.
I’m glad to see that Comodo are now focusing on updating CAV and will certainly give CIS a try at some point.

Regarding this actual topic of Comodo soliciting for submissions I would suggest sites like VirusTotal and Jotti’s Malware Scan. I notice Comodo AV is already listed on VirSCAN.
I personally submit samples through VirusTotal and VirSCAN in the hope that this spreads the benefit to the widest number of people.

I would also like to see Comodo AV listed on AV comparative and testing sites. I would guess this is something Comodo are planning once they feel the new CAV is ready ?
For example: AV-Test, Virus Bulletin VB100, AV-Comparatives.
Much like CFP is listed on Matousec’s Firewall Challenge.

Perhaps the more active forum regulars here can suggest more ?

Sure they will :slight_smile: Just waiting on detections to increase, Thanks for the suggestions

A

The Matousec’s Firewall Challenge site lists Comodo Firewall Pro as free evaluation version, with a paid version that offers additional features.
Correct me if I am wrong, but CFP (now CIS) is completely free, non-limited/non-restricted, and the paid ‘feature’ is an on-line service.
Their information should be updated to correct any errors that may mis-represent the firewall in any way. I did send them a friendly email letting them know this, and the current version available.

You are correct.

Melih

Thank you, Melih.

i still got like 50 or so files that are undetected from when i submitted them a while ago

mostly fake antivirus’s left, a few that don’t connect anymore as the phone home is broke(doesn’t mean it won’t come back up), and 2 online games files left, and hmmm think thats it

anyway the version of comodo on matousec site is old build.

yes the fake antivirus ones don’t show up as malicious with automatic analysis so they are done manually… (long process :frowning: )… you can always send those to me if you like for me if you know for sure they are malware… I will tell the guys so that they can push it thru the system…

thanks
Melih

Just waiting for that back end infrastructure aren’t ya Melih!! (:WIN)

Josh