Comodo I.S. 5.8 FINAL vs. Trojan.Win32 GPCODE ( comodo bypassed

Discussion in 'other anti-malware software' started by manar58, Oct 31, 2011.

Thread Status:
Not open for further replies.
  1. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    It's the same path. Documents and Settings is a protected folder that applies to all user folders I believe.
     
  2. Zyrtec

    Zyrtec Registered Member

    Joined:
    Mar 4, 2008
    Posts:
    534
    Location:
    USA

    Hey Harsha,


    My mistake. I made a typo when I first posted the locations to be protected for OSes post-Windows Vista [which includes Windows 7 for that matter].
    C:\documents and settings is for pre-Vista OSes [e.g., 2000 and XP]. This nomenclature changed after the release of Vista back in 2006 and was kept unchanged for win 7 [ in my opinion, 7 = Vista SP-1 improved].


    See this article: ----http://www.blogtechnika.com/what-is-application-data-folder-in-windows-7 --------

    Hope this clarify the confusion I created with my earlier posts.





    Carlos
     
  3. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Documents and Settings/ still exists in Vista/7 - it's just protected
     
  4. Zyrtec

    Zyrtec Registered Member

    Joined:
    Mar 4, 2008
    Posts:
    534
    Location:
    USA

    It does exist, indeed! but our friends from Redmond decided to name it :

    C:\Users\*\AppData\local\

    where * is a wildcard that corresponds to the actual user logged in.


    Please, correct me if I'm wrong. I might.


    Carlos
     
  5. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    I think it's a reference folder to the /Users/ that's a remnant of XP. It's almost impossible to delete.
     
  6. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    I tried a lot with them with my thread over there but they simply refuse to fix it.

    My Q is, if some one, like me, is using CFP just as a pure classical HIPS( Defence Plus only, no Sandbox, no AV), CFP is not able to defend against Gpcode and Blackday trojan or other similar ransomware but OnlineArmor can do it very well. They damn care!.:mad:
     
  7. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    exactly:)
     
  8. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    i wonder how well will spyshelter do with this type of malware?
     
  9. zakazak

    zakazak Registered Member

    Joined:
    Sep 20, 2010
    Posts:
    529
    What about simply adding C:/Users/* to the protected files & folders?
     
  10. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    That would then include things like your documents and downloads folders and just a ton more stuff you probably don't want blocked.
     
  11. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    And I'm sure if you turned off 99% of the features in Online Armor it would fail as well.

    The fact is that CIS defeats both of these malicious files through its definitions/heuristics.
     
  12. zakazak

    zakazak Registered Member

    Joined:
    Sep 20, 2010
    Posts:
    529
    Hmm on my old laptop I always added the User folder.. never had problems with it.
     
  13. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    I would like to know what were your results with OA :D
     
  14. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    See my thread over there at comodo forums.
     
  15. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    You did not understand my thread at all.
     
  16. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    Any link?
    Or whats your username over there and on what section you posted it :D
     
  17. Baserk

    Baserk Registered Member

    Joined:
    Apr 14, 2008
    Posts:
    1,321
    Location:
    AmstelodamUM
    As you wrote previously, during a test you found the AV picks it up and the manual sandbox breaks it.
    OA doesn't have a sandbox nor an AV. What features would then have to be switched off to compare it to CIS? It's HIPS?
    That would be stretching it a bit, don't you think?
     
  18. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Probably because I didn't read it. If I did I don't recall.

    If CIS's goal is to defend you that's what it does in this case.
     
  19. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    Did a little search and found the thread, really interesting and it's nice to see OA working properly (Since i use it) :)
     
  20. zakazak

    zakazak Registered Member

    Joined:
    Sep 20, 2010
    Posts:
    529
    Also CIS works properly... it's just that this guy disabled the AV (and I belive now also D+ detects this).
     
  21. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    D+ has detected it for a while both with the HIPS and with the heuristics.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.