Where did Comodo Cloud Scanner (CCS) originate from?

Better Safe Than Sorry.

That’s what our Live PC Support (GeekBuddy) technicians trained on. When they are cleaning our customer’s computers,
they don’t say: I don’t know this process in memory so I will ignore it,
they will say: I better mark this as suspicious and analyse it before I give it a clean bill of health.

So over the last year or so, they built tools that helped them clean customers computers. One of the tool was called LHA (Livepcsupport Helper Application: btw this is an internal name and you can’t find it as a product anywhere).

What this tool did was to identify all the issues that needed addressing, from checking all the processes in memory to cleaning registry to cleaning cookies that could be used tracking etc etc.

One of the most important feature of this was about identifying all running processes (that’s where malware is going to be if you are infected) and making sure you can verify every single one to be legit. If you can’t verify its legit, then worry and continue analysing. Don’t give up until you know. Thats the philosophy behind this tool that we internally call LHA. It can also identify hidden processes (used by real nasties) so that we can check to see if they are malware or not.

So we use services like CIMA to analyse uknown files in realtime and check the SHA1 of a file against our whitelist and blacklist and so on in this LHA (but mainly it was done manually initially). LHA also has the ability to validate Digitally signed files by trusted vendors.

So we thought, it would be a great idea to have a product that could be much smaller than a traditional security product that helped identify all the issues on your PC. Then you have a choice of either fixing those yourself, or get us to do it. It would both help end users to see if they have issues (no matter what kind of Anti virus product they are running) and would help Comodo as we can promote our services.

Thats’ when we decided to build Comodo Cloud Scanner. Its a neat tool (when its fully working that is :slight_smile: ), that has the philosophy of “better safe than sorry”. If an application is unknown and cannot be concluded as safe it should remain as unknown/suspicious. Of course as the use of this product grows we expect the unknown to be a small enough number not to be a nuisance. And after all if its still unknown after all that analysis, then its a healthy thing to be suspicious of it.

Its the first of its kind, it will need user feedback to improve. CCS comes from Technician’s toolbox straight to users, there will be some expected usability issues. We, as always, will work with our users to build this product to their liking!

Comodo is a Technology Company driven by Innovation and mission to create trust online! As a result, we will always have new products, service coming out of our Research Labs. But we will always listen to our users and improve, as we have been for last 3 years, every product we have. With over 25 million installations Comodo is now a leading provider of Security.

Melih

Now I understand all of the suspicious files.

Maybe it would be a good idea to have two separate categories. One for malware and suspicious files, and the other for unknown files.

However, the computer should not be listed as at risk merely because there are unknown files.

This does sound like a very useful tool though. I think with good heuristics it will be quite a good tool.

excellent suggestion!

We should seperate the known malware from uknown files which could be suspicious etc. You see we don’t want to give confidence to user about an unknown file “better safe than sorry”… So we have to call it unknown or something and explain why it could be suspicious etc…

Indeed, when CIMA works it will be a very useful tool. It does act like a magnifier for all your processes active in memory and checking them all, whether they are digitally signed or not, if they are hidden processes or not and so on…

Its a good tool for diagnosis!

Melih

While your there just want to extend my personal thanks for everything you’ve offered to date and all that’s to come… :-TU :-TU
Highest Regards & Happy 2010 to you & your team Melih
Xman

Thank you very much for the new tool and the clear and extensive introduction to it. (:CLP) :■■■■ (:NRD)

Comodo never ceases to amaze me. :-TU

Very nice read, now I know a lot more and look forward to making use of this latest addition. ;D

Thanks guys.

Its important to understand what this product is trying to do.

Some people say, hey its showing this legit file as unknown or suspicious etc, its an FP, so I don’t like this product. You see, when they say, they don’t understand what this product is about!

This product is about being safe than sorry, eg: mark a PC clean only when you know it is! Just because you don’t mark a file malware, does NOT make that file safe!

There is that unknown, suspicious state, that this product exposes to end users. And some people can’t handle it.

Because this product was designed for the geeks to be sure that PC was ok and didn’t have any suspicious files or unknown files.

So its a very powerful diagnostic tool for the ones who know how to use it, for the others, pls don’t touch it! :wink:

Melih

btw: we are continually improving it… watch this space…

Hi,

I just had a quick look at the beta of CCS and it looks very promising. But I’d prefer a portable version.

I’ve always a collection of small portable tools for diagnostics and file rescue on my pen drive.
At the moment I’m using mainly the pretty traditional HijackThis and Eset’s SysInspector to get a quick look into the system’s details. I think CCS would be a good addition.

Regards,
Michael

Hey lads,

right now I’m using Secunia PSI. From what I understood is it something similar to CCS? If so can someone tell me the differences between these two?

CCS is about finding if there are any “unknown” apps/processes running in your computer. A telltale sign of a malware is about an uknown process in memory or unknown file in a “critical folder” with ability to run at startup etc…

So CCS, checks all these and finds unknown processes and files.

If CCS doesn’t report any unknown/suspicious files…you can confidently say that you are clean (some nasty mbr viruses are not covered in this version but will be in future)…

so CCS is about the ability to say “this machine is clean”, rather than trying to find “infections”.

We don’t want to make a statement saying this machine is clean “Because we can’t find malware”…we want to make a statement saying this machine is clean “Because we know all processes/files in critical places are known legit files”…

And that is what CCS is about!
hope this clarifies…

thanks
Melih

Thanks Melih for clarifying! :slight_smile:

I’ve tried CCS and it showed no malicious software on my PC, so I’m happy :slight_smile: Well I can say I’m using a good combo so it’d surprise me a bit if I was infected :slight_smile: Having D+ with CFP simply rocks and once the Sandbox is fine-tuned I think I can say the bad buys bye bye! :slight_smile:

Thank you for the post, this program confused me a bit. Comodo has awesome products.

so it is gettin data from the hive mind!!! wow thats cool