Wilders Security Forums  

Go Back   Wilders Security Forums > Security Software > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old October 30th, 2009, 11:48 PM
a256886572008's Avatar
a256886572008 a256886572008 is offline
Infrequent Poster
 
Join Date: Oct 2007
Posts: 34
Default a virus pass COMODO

COMODO Firewall 3.12.111745.560

1.I execute a virus

2.COMODO diplay an alert"wscript.exe is doing something."

3.I choose "limited applications", and click OK.

4.My disks of C & D become.......
Attached Images
  
  #2  
Old October 31st, 2009, 12:58 AM
dcrowe0050's Avatar
dcrowe0050 dcrowe0050 is offline
Frequent Poster
 
Join Date: Sep 2009
Location: NC
Posts: 368
Default Re: a virus pass COMODO

So what is your question??
__________________
"The only real security that a man can have in this world is a reserve of knowledge, experience, and ability"

"Only two things in the world are infinite, the Universe and human stupidity, and nobody seems to be sure of the former"

  #3  
Old October 31st, 2009, 01:01 AM
a256886572008's Avatar
a256886572008 a256886572008 is offline
Infrequent Poster
 
Join Date: Oct 2007
Posts: 34
Default Re: a virus pass COMODO

Quote:
Originally Posted by dcrowe0050
So what is your question??

COMODO can not block this action of the virus
  #4  
Old October 31st, 2009, 06:46 AM
dell boy dell boy is offline
Frequent Poster
 
Join Date: Apr 2009
Location: uk, england
Posts: 240
Default Re: a virus pass COMODO

what is the point of this thread? if you want to report a virus then try their forums, if your not happy with the protection offered there is other free alternatives to comodo that you might prefer, to name a few there is AVG Avast! Avira and microsofts own free antivirus MSE.
__________________
The best protection a computer could ever have, proven by experts and professionals is Safe-Hex.
Guaranteed!
  #5  
Old October 31st, 2009, 07:15 AM
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,287
Default Re: a virus pass COMODO

Quote:
Originally Posted by a256886572008
COMODO Firewall 3.12.111745.560

1.I execute a virus

2.COMODO diplay an alert"wscript.exe is doing something."

3.I choose "limited applications", and click OK.

4.My disks of C & D become.......
Thanks a256886572008, btw what virus was it?.
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld

Thanks to everyone for the kind words and get well soon messages, it is very much appreciated .

Last edited by Meriadoc : October 31st, 2009 at 07:21 AM.
  #6  
Old October 31st, 2009, 07:20 AM
funkydude's Avatar
funkydude funkydude is offline
Very Frequent Poster
 
Join Date: Apr 2004
Posts: 2,926
Default Re: a virus pass COMODO

Quote:
Originally Posted by Meriadoc
Thanks a256886572008, btw what virus was it?

Joke:Win32.GreenEnvironment
__________________
Light, fast, secure & free:
Win7x64+MSE+WinFirewall+UAC+DEP+SEHOP
  #7  
Old October 31st, 2009, 09:26 AM
blacknight's Avatar
blacknight blacknight is offline
Frequent Poster
 
Join Date: Sep 2007
Posts: 869
Default Re: a virus pass COMODO

Not a bad idea post it also in Comodo Forum, isn't ?
  #8  
Old October 31st, 2009, 10:11 AM
dcrowe0050's Avatar
dcrowe0050 dcrowe0050 is offline
Frequent Poster
 
Join Date: Sep 2009
Location: NC
Posts: 368
Default Re: a virus pass COMODO

From my experience CIS miss a lot of virus and malware so my advice would be clean up uninstall all but the Firewall which is great and get another freeAV like Avast
__________________
"The only real security that a man can have in this world is a reserve of knowledge, experience, and ability"

"Only two things in the world are infinite, the Universe and human stupidity, and nobody seems to be sure of the former"

  #9  
Old October 31st, 2009, 10:26 AM
smage smage is offline
Regular Poster
 
Join Date: Sep 2008
Posts: 191
Default Re: a virus pass COMODO

Hi a256886572008,

Here is the link for you to submit the virus to Comoso so that other CIS users get protected as well.

http://internetsecurity.comodo.com/submit.php

Thanks
  #10  
Old October 31st, 2009, 10:41 AM
NodKiller NodKiller is offline
Infrequent Poster
 
Join Date: Feb 2009
Posts: 13
Default Re: a virus pass COMODO

First thing: all av products are far from perfect (I tested a well-known av product which has a huge fan-camp here not long ago against zero day threats and it was like 1 out of 10) so you're silly if you rely on them (need better solution like HIPS and sandboxing).
Second thing: I use the whole CIS package and I'm very satisfied even with the av scanner (the whole suite running smoothly and very light on resources). No need to use another av scanner.
Third thing: you didn't even remove it or quarantine it, just set the application rule to limited app (what's with that).
Fourth thing: are your settings the highest possible for really good protection? (guess not). You can find good guides how to setup CIS for maximum protection.
Fifth thing: looking at your threads on this forum and comodo's you just want to discredit their product mostly because of your ignorance.


P.S. If you test seriously well-know av products against zero day malware (not against zero day links) your result will be very disappointing: if they can protect against 20-30% this is very good result (just forget about this very outdated technology). I guess you still live in this fancy world of antiviruses or paid by one of the companies.
Please stop submitting BS's like this....
  #11  
Old October 31st, 2009, 11:22 AM
thanatos_theos's Avatar
thanatos_theos thanatos_theos is offline
Frequent Poster
 
Join Date: Apr 2007
Posts: 487
Default Re: a virus pass COMODO

I think he did this to test CIS's HIPS and not the AV. So it's possible the AV is not installed (so even if it detects the threat...). This thread might be inspired from the thread below (malware able to install in LUA/with limited access),

http://www.wilderssecurity.com/showthread.php?t=256948

Unfortunately the malware was still able to install even with 'limited' rights set by CIS. With limited, writing to disk is blocked. Maybe this is a flaw with the default limited rule? Or the malware executed was a script and the rule didn't apply correctly/well to wsrcipt.exe (which is a part of Windows and set as trusted?)? I think CIS doesn't monitor scripts on-execution?

Probably a256886572008 should explain?
__________________
"O miserable shadow clad in darkness! Hurting and disdaining people, a karmic soul drowning in sin... Would you try dying for once?" - Enma Ai
  #12  
Old October 31st, 2009, 11:38 AM
_kronos_'s Avatar
_kronos_ _kronos_ is offline
Regular Poster
 
Join Date: Dec 2008
Posts: 93
Default Re: a virus pass COMODO

Exactly, your observation means that this malware can infect even with user rights (not only administrator). Nothing else.
So please be carefull before to do a test, or publishing it as "CIS Bypassed", because if you click ALLOW to its alerts CIS is bypassed as well, but it is not a vulnerability.

Otherwise, if we are misunderstanding your test, please explain us your metodology...

Regards
__________________
Realtime: Malware Defender, Prevx
  #13  
Old October 31st, 2009, 11:48 AM
dawgg's Avatar
dawgg dawgg is offline
Frequent Poster
 
Join Date: Jun 2006
Posts: 754
Default Re: a virus pass COMODO

Quote:
Originally Posted by funkydude
Joke:Win32.GreenEnvironment
... its not a virus then is it?
I wont be surprised if most AVs miss it and possibly many behaviour blockers if it just changes the background.
  #14  
Old October 31st, 2009, 03:09 PM
tcarrbrion tcarrbrion is offline
Infrequent Poster
 
Join Date: Dec 2007
Posts: 31
Default Re: a virus pass COMODO

Quote:
Originally Posted by thanatos_theos
With limited, writing to disk is blocked.

A limited application is not blocked from writing to disk or the registry. Only direct disk access and protected files/registry settings are blocked. It could still delete everything in "my documents" unless added to "my protected files".
  #15  
Old October 31st, 2009, 05:20 PM
Fuzzfas's Avatar
Fuzzfas Fuzzfas is offline
Very Frequent Poster
 
Join Date: Jun 2007
Posts: 1,918
Default Re: a virus pass COMODO

I don't see where's Comodo failure on this one...

ALL classical HIPS, won't protect you if you THINK that the malware isn't "bad enough". Just like it won't protect you from something you THINK it's legitimate software, so you switch to "installer-updater" mode and let it install... This is the biggest limitation of classical HIPS. If you don't think at all that it's malware, they can't protect you if you install them.

In this case, by setting "limited application", you bypass a good part of Comodo's protection...

Classical HIPS are good, but they are not panacea against things that you don't suspect as bad and you want to install them. This is where AV scanners and trying the software under something like sandboxie or Shadow Defender or Returnil & Co help to get a better idea.
__________________
Avast Home 5 - Win 7 Firewall Control PLUS - WinPatrol Plus
On Demand: Shadow Defender - MBAM Free - Macrium Free
  #17  
Old November 1st, 2009, 01:03 AM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 6,164
Default Re: a virus pass COMODO

@fuzzfas nice avatar
__________________
PE Guard 2.1/HitMan Pro/WinPatrol Plus/ProcessGuard 3.5
  #18  
Old November 1st, 2009, 02:13 AM
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 4,252
Default Re: a virus pass COMODO

Quote:
Originally Posted by thanatos_theos
I think he did this to test CIS's HIPS and not the AV. So it's possible the AV is not installed (so even if it detects the threat...). This thread might be inspired from the thread below (malware able to install in LUA/with limited access),

http://www.wilderssecurity.com/showthread.php?t=256948

Unfortunately the malware was still able to install even with 'limited' rights set by CIS. With limited, writing to disk is blocked. Maybe this is a flaw with the default limited rule? Or the malware executed was a script and the rule didn't apply correctly/well to wsrcipt.exe (which is a part of Windows and set as trusted?)? I think CIS doesn't monitor scripts on-execution?

Probably a256886572008 should explain?

Yep, when running in clean PC mode wscript is part of the existing, trusted nunch of programs.
  #19  
Old November 1st, 2009, 04:21 AM
Fuzzfas's Avatar
Fuzzfas Fuzzfas is offline
Very Frequent Poster
 
Join Date: Jun 2007
Posts: 1,918
Default Re: a virus pass COMODO

Quote:
Originally Posted by ssj100
Sandboxie, Shadow Defender, Returnil won't help you if the software you want to test requires a system restart - use a VM like VirtualBox (completely free) instead. VM's are much more versatile for testing things out than light virtualisation software.

Otherwise, completely agree with your other points.

True, VM is a complete solution for testing software (and malware) in general, you can do anything.

Personally i 've never tried a VM, maybe i should. From the sound of it i always thought it would take some time to setup a VM. I prefer a solution like Shadow Defender (or Returnil Free) + First Defence PC Rescue-Rollback. Most malware doesn't even require reboot. I 'd actually become very suspicious if i were to install something and it required reboot. In most cases all you need to avoid malware is to download reputable software from reputable sources. And usually malware that you execute comes in small packages (simple or camouflaged exe). Well, the exception with rogue antivirus exists, but, if you don't know which antivirus are legitimate, then probably you don't know VM/ Returnil or Rollback either.

Quote:
Originally Posted by jmonge
@fuzzfas nice avatar

Hi there Jmonge! I see that now you are trying Twister. Yeah, the avatar is nice, but since i can't run Twister on 64bit i might change it. 64bit isn't a priority for Filseclab. Which is probably understandable since i presume that in China most people don't have cutting edge hardware, so they don't rush to 64bit OS either. This is also probably the reason of why all chinese security application that i 've tried run on very low specs hardware.

Maybe i should put Scotty as my new mascot!
__________________
Avast Home 5 - Win 7 Firewall Control PLUS - WinPatrol Plus
On Demand: Shadow Defender - MBAM Free - Macrium Free
  #20  
Old November 1st, 2009, 09:38 AM
firzen771's Avatar
firzen771 firzen771 is offline
Massive Poster
 
Join Date: Oct 2007
Location: Ontario, Canada
Posts: 3,874
Default Re: a virus pass COMODO

Quote:
Originally Posted by Fuzzfas
Hi there Jmonge! I see that now you are trying Twister. Yeah, the avatar is nice, but since i can't run Twister on 64bit i might change it. 64bit isn't a priority for Filseclab. Which is probably understandable since i presume that in China most people don't have cutting edge hardware, so they don't rush to 64bit OS either. This is also probably the reason of why all chinese security application that i 've tried run on very low specs hardware.

Maybe i should put Scotty as my new mascot!

can never go wrong with good ol scotty
__________________
Windows 7 32bit - Windows FW: Enabled - Windows Defender: Disabled - UAC: Disabled - DEP: Enabled

Real-Time: ESET NOD32 Antivirus / Zemana Antilogger / WinPatrol
On-Demand: MBAM / Hitman Pro / Sandboxie
  #22  
Old November 7th, 2009, 06:55 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 9,351
Default Re: a virus pass COMODO

I have tried this virus. CFP does not fail IMO. You need a bit of custom rules, add file protection for *.lnk and *.vbs file creation.

Only thing deficient in CFP here is that it doesn,t monitor about putting hidden attributes to files and folders and malware is able to hide all folders in C drive including windows directory and program files folder.

A clever piece of malware indeed. I will post later with screen shots, hopefully in a week by God,s will. Too busy ATM.
__________________
MalwareDefender / CFP, GesWall, KeyScrambler - all under the umbrella of Comodo Time Machine
Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun.

I am waiting for a pop up HIPS for Ubuntu!
 

Wilders Security Forums > Security Software > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:39 AM.


Powered by vBulletin® Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2010, Wilders Security Forums