Comodo Antivirus v2: what's new?

Discussion in 'other anti-virus software' started by EraserHW, Feb 13, 2007.

Thread Status:
Not open for further replies.
  1. Oliver.S

    Oliver.S Registered Member

    Joined:
    Jan 17, 2007
    Posts:
    4
    Well, after I read that the excellence is in leak protection only I scrolled down a little further to read this:
    Talking about hooks, not filter drivers, this is total nonsense. How would anyone be able to prevent anything from any other entity in kernel mode? Maybe the kernel designers can to a certain extent (see PatchGuard), normal vendors just can't do it. Oh and mind you, the "funny" implementation of some of the products are risky, to say the least. Yes, I have seen more than one during debugging sessions and in a disassembler (and I mean specifically the kernel mode parts). As a kernel mode developer I hate the problems these freak-drivers cause anyone else!

    And even if unhooking fails for some reason, the bluescreen will point at the hooking module, not at the one attempting to unhook it!

    ... not to comment ignorance of freely available OpenSource implementations, that, if being worked on, would likely perform very good in comparison to those commercial products.

    And development has to be quick as well to keep pace with progress of malware ...

    Full ack!

    Hmm, and what about the statement by "the boss" of Comodo? No proof needed there?

    // Oliver
     
  2. danieleb

    danieleb Registered Member

    Joined:
    Dec 11, 2006
    Posts:
    111
    Yes, exactly. I don't bother with them either.

    [Probably dumb question:] Why are these (leak) tests not performed using actual known malware samples, like when you test AVs?
     
  3. TonyW

    TonyW Registered Member

    Joined:
    Oct 12, 2005
    Posts:
    2,741
    Location:
    UK
    Most of these tests are done with specific software that apparently leaks. I've yet to come across software like that in my day to day use of the computer as I don't just go downloading everything in sight.
     
  4. FRug

    FRug Registered Member

    Joined:
    Feb 7, 2006
    Posts:
    309
    Regarding Comodo FW I want to quote the frequently referred matousec page, which also ranked comodo 1st in matters of leak tests:

    Read http://www.matousec.com/projects/wi...l-analysis/Comodo-Personal-Firewall-2.3.6.81/ for the full review. It also features a quite impressive list of critical bugs. While certainly important, leak tests are very much overrated recently and comodo is a prime example here.
     
  5. Menorcaman

    Menorcaman Retired Moderator

    Joined:
    Aug 19, 2004
    Posts:
    4,661
    Location:
    Menorca (Balearic Islands) Spain
    Off topic post removed. Please let's remain focused on Comodo Antivirus v2. Many thanks.

    Menorcaman
     
  6. NAMOR

    NAMOR Registered Member

    Joined:
    May 19, 2004
    Posts:
    1,530
    Location:
    St. Louis, MO
    Anyone see the latest post on that thread?


    By Melih
    http://forums.comodo.com/index.php/topic,6272.90.html


    So is it more of a HIPS application?
     
  7. plantextract

    plantextract Registered Member

    Joined:
    Feb 13, 2007
    Posts:
    392
    i don't know if what they are using isn't basic execution control, which is very easy to achieve but annoying as hell and of course dependent on the "meat" component in front of the keyboard.

    BTW other avs also have hips/behaviour blocking capabilities: norton 2007 - if you tweak it correctly, kaspersky has it, f-secure so they should lay down a bit on the "the only AV that has it" part.
     
  8. lodore

    lodore Registered Member

    Joined:
    Jun 22, 2006
    Posts:
    9,065
    quote "Because CAVS v2 simply denied the ability to execute due to its HIPS functionality which no other AV has"
    kaspersky PDM?
    it im not mistaken pdm in kaspersky is a HIPS and was implumented in kav6.0/kis6.0 months before comodo put HIPS in to there av. so the HIPS which no other av has is simply incorrect.
    lodore
     
  9. NAMOR

    NAMOR Registered Member

    Joined:
    May 19, 2004
    Posts:
    1,530
    Location:
    St. Louis, MO


    That's what I'm thinking... Or what about other HIPS programs with AV's like Online Armor Antivirus+ or Safe'n'Sec Personal+Anti-Virus.
     
  10. lodore

    lodore Registered Member

    Joined:
    Jun 22, 2006
    Posts:
    9,065
    thats a very good point also
    great minds think a like=D
    lodore
     
  11. C.S.J

    C.S.J Massive Poster

    Joined:
    Oct 16, 2006
    Posts:
    5,029
    Location:
    this forum is biased!
    comodo antivirus...

    well, i dont care much for results but id rather use MS ONE CARE than comodos AV.

    think that stamps my thoughts on the matter :D
     
  12. Graystoke

    Graystoke Registered Member

    Joined:
    Aug 15, 2003
    Posts:
    1,506
    Location:
    The San Joaquin Valley, California
    So, besides KAV 6 and this new Comodo AV, what other AVs have HIPS?
     
  13. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    Ahem...... try it with Antivirs AV, not the suite. My PC is as fast as I can ask and the 2 love each other.

    Or try the latest Prevx1 by itself.
     
  14. ggf31416

    ggf31416 Registered Member

    Joined:
    Aug 20, 2006
    Posts:
    314
    Location:
    Uruguay
    If you are not a company or organization you can get a good antivirus and a good HIPS for the same price (free) instead of the Comodo AV.
     
  15. NAMOR

    NAMOR Registered Member

    Joined:
    May 19, 2004
    Posts:
    1,530
    Location:
    St. Louis, MO

    F-Secure has a type of HIPS I bleieve.
     
  16. Graystoke

    Graystoke Registered Member

    Joined:
    Aug 15, 2003
    Posts:
    1,506
    Location:
    The San Joaquin Valley, California
    Thanks NAMOR.
     
  17. Firecat

    Firecat Registered Member

    Joined:
    Jan 2, 2005
    Posts:
    8,251
    Location:
    The land of no identity :D
    For that matter, neither Comodo nor Microsoft is a "gold standard" for poor quality of AntiVirus. Yes they are both mediocre but not enough test results are available to truly measure their performance at this time....Besides, there *are* worse AVs out there. Hauri Virobot, AhnLab, etc.

    So don't drop the duck on any product just yet, wait for the test results and see how it does, then conclude about its performance. :)
     
  18. jzhhh

    jzhhh Registered Member

    Joined:
    Jan 20, 2007
    Posts:
    1
    :blink: I'm not pretty sure how's that going...so I choose "not use"...
     
  19. Seishin

    Seishin Registered Member

    Joined:
    Aug 2, 2006
    Posts:
    204
  20. danieleb

    danieleb Registered Member

    Joined:
    Dec 11, 2006
    Posts:
    111
    Please explain: Why do I need a HIPS to stop me from running a executable, and how do I know if it's certified? o_O

    Thank you!
     
  21. EraserHW

    EraserHW Malware Expert

    Joined:
    Oct 19, 2005
    Posts:
    588
    Location:
    Italy
  22. Inspector Clouseau

    Inspector Clouseau AV Expert

    Joined:
    Apr 2, 2006
    Posts:
    1,329
    Location:
    Maidenhead, UK
  23. Oliver.S

    Oliver.S Registered Member

    Joined:
    Jan 17, 2007
    Posts:
    4
    Well, they've got that special kind of humor :D :D :D

    @EraserHW: Have you sent them the file for analysis?;) :D
     
  24. EraserHW

    EraserHW Malware Expert

    Joined:
    Oct 19, 2005
    Posts:
    588
    Location:
    Italy
    Oh man, not yet....I'm too busy today to send the sample :D
     
  25. Macstorm

    Macstorm Registered Member

    Joined:
    Mar 7, 2005
    Posts:
    2,642
    Location:
    Sneffels volcano
    Just read the comodo forums aswell, they are funny :D

    Comodo dev. team must be working very hard these days because of the latest av-comparatives tests...
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.