Rogue slips right through Comodo!

Discussion in 'other anti-malware software' started by hamzah95, Jul 28, 2009.

Thread Status:
Not open for further replies.
  1. firzen771

    firzen771 Registered Member

    Joined:
    Oct 29, 2007
    Posts:
    4,815
    Location:
    Canada
    are u serious with that kind of response? nobody forced u to try it, besides, its a rogue, not some crazy file infector or MBR rootkit, a simple scan with mbam SHOULD get rid of it.
     
  2. andyman35

    andyman35 Registered Member

    Joined:
    Nov 2, 2007
    Posts:
    2,336
    As long as you don't get taken in by it's impressive GUI and decide to pay for it you should be just fine.;)
     
  3. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    Don't worry lol. All i'm afraid of is that if comodo keeps on doing this, i'll get owned by malware.
     
  4. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    Don't worry lol. All i'm afraid of is that if comodo keeps on doing this, i'll get owned by malware.
     
  5. andyman35

    andyman35 Registered Member

    Joined:
    Nov 2, 2007
    Posts:
    2,336
    These rogues are a massive issue at the moment,especially the ones which aren't actually malware at all,just Scamware.The difficulty IMO is for HIPS to provide meaningful alerts that average users will understand for these non-malicious rogues.:doubt:
     
  6. overangry

    overangry Registered Member

    Joined:
    Apr 4, 2009
    Posts:
    309
    I restarted my pc into normal mode without any shadow mode
    I disabled NOD32
    then played with malware:doubt: Sure you'll get owned...:eek:
     
  7. Dark Star 72

    Dark Star 72 Registered Member

    Joined:
    May 27, 2007
    Posts:
    778
    Tried this against Zemana Antilogger first - sailed right by and started running (Zemana failed)
    Then ran it against Prevx 3.0. Prevx allowed the download but detected it as soon as I scanned it or tried to open it.
     

    Attached Files:

  8. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    I checked the defense+ events log and xpdeluxe installed a hook called msctf.dll, I uploaded it to virustotal, and no av detects it.o_O :eek: :'( :mad: :doubt:
    Should i manually delete it?
     
  9. thathagat

    thathagat Guest

    yup zemana does nothing

    I think Prevx scans only on execution not real time
     
  10. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    This post is all about how it got through Comodo... so your post should be more like "this is why I don't use traditional signature based AV".

    heuristic/behavioral AV analysis is still the best out there.
     
  11. acr1965

    acr1965 Registered Member

    Joined:
    Oct 12, 2006
    Posts:
    4,995
    When Prevx alerted did it stop the rogue from running? Or does Prevx allow the rogue to run and just notify that it is on the system?
     
  12. Retadpuss

    Retadpuss Suspended Member

    Joined:
    Apr 4, 2009
    Posts:
    226
    Prevx detects and blocks / prevents it running and or installing.

    I have emailed Zemana to notify them this rogue evades detection.

    Puss
     
  13. Dark Star 72

    Dark Star 72 Registered Member

    Joined:
    May 27, 2007
    Posts:
    778
    Prevx stopped it from running. Downloaded the .exe and scanned it from right click > scan with Prevx and then rebooted (using Shadow Defender) and then downloaded the .exe again and tried to run it. Both times Prevx popped up the same 'cloaked malware' as in my screen shot. Clicked 'Cleanup Now' and Prevx wiped it off the desktop. Never gave it a chance to run :thumb:

    Will see if I can find time to try it against GeSWall later

    Edit: Puss posted while I was typing - will have to learn to type faster
     
  14. virtumonde

    virtumonde Registered Member

    Joined:
    Jan 18, 2008
    Posts:
    504
    Well this could have the same system impact(Registry modification) as installing Cc Cleaner for example ,so i'm not sure what Zemana should detect.
    This is the job of an traditional antimalware application to detect it IMO.
    As pointed out by andyman this is quite a challenge as it doesn't seem to exibit traditional malware behaviour(strictly from registry impact/modification point of view).It's a GUI meant to trick average users.
     
  15. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    again, Should i manually delete it?
     
  16. thathagat

    thathagat Guest

  17. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
  18. Retadpuss

    Retadpuss Suspended Member

    Joined:
    Apr 4, 2009
    Posts:
    226
    I just tried it againat Mamutu - installed and ran undetected.

    Hitman Pro detects it and removes it.
     

    Attached Files:

  19. thathagat

    thathagat Guest

    well hamzah95 run a scan of mbam/sas or both see if they detect it and you have a2 free in your sig. scan with it too if you want if all report clean relax and go to sleep....but don't try this experiment of your's with virut/sality
     
  20. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    OK guys. The people at comodo forums helped me fiqure this out. I was running in Proactive mode updated updated which means i changed some settings, so if i go to the default proactive security mode, i get execution alerts and so on.
     
  21. Dark Star 72

    Dark Star 72 Registered Member

    Joined:
    May 27, 2007
    Posts:
    778
    Have now tried this against GeSWall free :thumbd:
    Just managed to get a screen shot as the policy notifications were fading in the first shot - note the deny messages at the bottom.
    This rogue ran as though there was nothing there to stop it.
    Would like to see a full time GeSWall user try it as I may have made a mistake :doubt:
    Also ran this rogue with Executable Lockdown on - stopped it dead, as you would expect it to.
     

    Attached Files:

    • gw#1.JPG
      gw#1.JPG
      File size:
      139.7 KB
      Views:
      8
    • gw2.JPG
      gw2.JPG
      File size:
      125.5 KB
      Views:
      4
  22. IceCube1010

    IceCube1010 Registered Member

    Joined:
    Apr 26, 2008
    Posts:
    963
    Location:
    Earth
    That's it! I'm going back to Sandboxie!
    Ice
     
  23. Franklin

    Franklin Registered Member

    Joined:
    May 12, 2005
    Posts:
    2,517
    Location:
    West Aussie
    Could anyone PM me the exe they have as it may be a morph?

    MBAM hits the installer I have.
    Sandboxie contains and deletes it no probs.

    SB.JPG
     
  24. virtumonde

    virtumonde Registered Member

    Joined:
    Jan 18, 2008
    Posts:
    504
    Lol.Probably no one read my post or that of andyman 35,to figure out what this is :) .So all you guys dissapointed with your HIPS,behaviour blocker,or whatever please think again .
    This program doesn't do nothing malicious against the system unless HIpS will add OCR technology :)(sound S.F. i know) you won't be properly notified.It's the job of antimalware products,or antispyware products to detect this.
     
  25. firzen771

    firzen771 Registered Member

    Joined:
    Oct 29, 2007
    Posts:
    4,815
    Location:
    Canada
    with free version pretty sure it doesnt terminate malware, u go into the program and manually terminate, the "isolated session" or w/e its called (i think) but all those deny messages probably meant denied from writing to the actuall system or something.

    and to all the people saying BB's and Zemana wont block it, well what do u expect lol, a rogue program that does nothing malicious, BB's arent ther to alert u whenever a program installs (which is all this rogue does really) and neither is Zemana designed for this, they detect malicious actions (which ther werent any), only HIPS will and blacklist signatures, and ofcourse sandboxing, those are the only way to catch a rogue that isnt bundled with malware.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.