Rogue slips right through Comodo!

Discussion in 'other anti-malware software' started by hamzah95, Jul 28, 2009.

Thread Status:
Not open for further replies.
  1. firzen771

    firzen771 Registered Member

    Joined:
    Oct 29, 2007
    Posts:
    4,815
    Location:
    Canada
    hmm thats good to know.
     
  2. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    Aren't the exes there by default? and even with the exes in the list, the image execution can't block the rogue in normal mode only in aggressive.
     
  3. thathagat

    thathagat Guest

    private firewall seems to block it...avast and a2 deny access to the site itself
     

    Attached Files:

  4. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    With Image execution control set to aggressive, the alerts show that xpdeluxe.exe tries to access or execute:
    ntdll.dll
    kernel32.dll
    msvcrt.dll
    user32.dll
    qdi32.dll
    ole32.dll
    advapi32.dll
    rpcrt4.dll
    secur32.dll
    imm32.dll
    lpk.dll
    and many more
    got bored so stopped:D
     
  5. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    I already had the executables (by default) list since i installed COMODO
     
  6. tsec

    tsec Registered Member

    Joined:
    Nov 18, 2008
    Posts:
    181
  7. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    I don't have sandboxie installed, don't like it.
    And i'm running this with Shadow defender:)
     
  8. alex_s

    alex_s Registered Member

    Joined:
    Aug 13, 2007
    Posts:
    1,251
    the first popup is from OA++, the second with AV module off
     

    Attached Files:

    • 1.gif
      1.gif
      File size:
      23.2 KB
      Views:
      343
    • 2.gif
      2.gif
      File size:
      28.5 KB
      Views:
      344
  9. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    What do u mean, shadow defender runs the pc like in any virtual machine.o_O
     
  10. thathagat

    thathagat Guest

    more screenies......
     

    Attached Files:

  11. alex_s

    alex_s Registered Member

    Joined:
    Aug 13, 2007
    Posts:
    1,251
    If according to Egenem Defence+ also gives equivalent initial execution alert, what the whole thread is about ? :)
     
  12. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    Maybe the same things happening to egeman then.
     
  13. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    only egemen gets the execution alert. I don't neither does ssj100
     
  14. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    Quill doesn't even think this has malware. And both are using VMs
     
  15. alex_s

    alex_s Registered Member

    Joined:
    Aug 13, 2007
    Posts:
    1,251
    This is kinda kind of magic. Melih and Egenem re the only people in the Universe Comodo never fails for :)
     
  16. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    LOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOL:D
     
  17. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    He says
     
  18. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    And there should be a execution alert atleast. I tested the whole thing again
    and the only alert i get is xpdeluxe is trying to access explorer and if blocked the rogue still runs.
     
  19. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    LOOOOOL:D :D :D :D
    EDIT:And i'm using defense+ with safe mode (higher than yours)
     
  20. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    Oh well, now all we can do is wait for other people to test this 'smart' rogue with comodo.
     
  21. thathagat

    thathagat Guest

    ummm......comodo might be taking a one off break and letting other security apps deal with such cyber trivalities....haha(ssj i have borrowed your trademark exclaimation for once)
     
  22. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    I hate you man!!! I restarted my pc into normal mode without any shadow mode. And I disabled NOD32 becuz it detects the rogue, and then downloaded the rogue. Guess what happened? The same thing happened, I got a access to memory alert and thats it, i blocked it, and the rogue started running!!!!!!!
    :'( :'( :'( :'( :'( :'(
    Doing an on-demand scan now.:mad: :mad: :mad:
     
  23. arran

    arran Registered Member

    Joined:
    Feb 5, 2008
    Posts:
    1,156
    this is the reason why I don't bother using an AV, not worth it as there is only a small chance your av will detect it.

    ps can some one pm me sample.
     
  24. thathagat

    thathagat Guest

    oops ! the plunge as advised by ssj has plunged you into an abyss .mbam should get rid of it imho
     
  25. hamzah95

    hamzah95 Registered Member

    Joined:
    Jun 22, 2009
    Posts:
    108
    I have basically jumped into a empty water well man.LOL
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.