App Review Comodo Cloud AV - Autosandbox only - petya bypassed

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
you think Petya is able to bypass SD and encrypt host machine? of cours i mean that MBR-BIOS
I don't know but it's super rare as someone explained. petya, I don't think it can
but hackers who really want to steal your info can

check if you are using GPT. If you do, don't worry about petya
 

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
Interesting. So CCAV doesn't protect the mbr from an isolated application? This is indeed weird and sad.

Need to not read this forum in the mornings because it makes me sad seeing such results.

you think Petya is able to bypass SD and encrypt host machine? of cours i mean that MBR-BIOS
Not at it's current state.
 

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
Interesting. So CCAV doesn't protect the mbr from an isolated application? This is indeed weird and sad.

Need to not read this forum in the mornings because it makes me sad seeing such results.
comodo firewall or CIS are the answer for that :)
they are better all the way including performance

Petya is terrifying
if you are using GPT drive, don't worry about petya :)
 

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
comodo firewall or CIS are the answer for that :)
they are better all the way including performance
But that should make 0 difference because they ported the CIS sandbox module into CCAV a while back. So they might have messed permissions for anything run isolated because in practice the 2 modules are identical. Too lazy to find the changelog but you probably remember.
 

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
But that should make 0 difference because they ported the CIS sandbox module into CCAV a while back. So they might have messed permissions for anything run isolated because in practice the 2 modules are identical. Too lazy to find the changelog but you probably remember.
actually they are different according to comodo's FAQ
Cloud Antivirus | Comodo Free Proactive Protection Software
How CCAV sandbox is different from CIS sandbox?

CCAV sandbox is a light weighted sandbox, it does not rely on service or filter drivers. It is implemented purely from user mode hooks. CCAV sandbox does not have COM/Service virtualization which CIS has. Besides, unlike CIS which has one global sandbox instance, different CCAV applications have their own sandbox instance while child process inherits sandbox instance from parent process

I also tested comodo firewall in proactive mode, I didn't change the restriction level, it blocked 100% including petya. I assume it's much better
 

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
I listen but i just don't trust them. If i ever use their software again it's only for the firewall and nothing else.
wait, or perhaps CF would be bypassed by petya also? The last time I tested, I forgot to disable file rating completely. Maybe that's the reason why CF blocked it. I may do another test then
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
the faq doesn't actually say that CCAV has the same sandbox settings as CFW "proactive" config. Maybe it has the same settings as firewall config, which is weak on the COM side. @cruelsister says that firewall config in comodo 10 is lacking in proper COM protection.
It should not matter. They should protect the mbr, who the hell doesn't when we have so many ransomware that do that.
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
It should not matter. They should protect the mbr, who the hell doesn't when we have so many ransomware that do that.
CFW in firewall config actually relies at its default settings on HIPS, while autosandbox is disabled by default.
But your scathing criticism is richly deserved by CCAV...
 

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
CFW in firewall config actually relies at its default settings on HIPS, while autosandbox is disabled by default.
But your scathing criticism is richly deserved by CCAV...
I don't care on what it relies or how it does it. They just created a program apparently for sandbox only and the sandbox has the same capabilities as CIS from what they are advertising. So they should #####ing go to work and figure a way to at least stop the most common exploited methods.
This Comodo loops you need to jump are ridiculous and i am not going to take it easy on them or defend them. If they made a terrible program is not my fault.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top