App Review Comodo Cloud AV - Autosandbox only - petya bypassed

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

cruelsister

Level 43
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,224
The one important thing is not to paint all Comodo products with the same brush as they are different. Symbolic Logic shows that an argument is invalid if it goes from a specific to a general. In the case of Comodo:

1). Comodo creates software
2). Comodo created CCAV, which sucks
3) therefore ALL Comodo products suck.

This would be similar to:

1), Meghan is a girl
2). Meghan has green eyes
3. therefore ALL girls have green eyes.
 

Ink

Administrator
Verified
Jan 8, 2011
22,490
I agree with you. They hardly admit a bypass. I do not remember if they have ever done ...
For the average PC user can they claim the $500 guarantee?

Comodo's Exclusive $500 Virus-Free Guarantee
If your PC gets infected by a virus after Comodo Internet Security Pro 10 is properly installed and registered, our online GeekBuddy support technicians will restore your PC to working condition. If we cannot restore your
PC due to a virus infection, Comodo will cover up to $500 in repair costs, using an authorized repair center.
 
5

509322

For the average PC user can they claim the $500 guarantee?

Comodo's Exclusive $500 Virus-Free Guarantee
If your PC gets infected by a virus after Comodo Internet Security Pro 10 is properly installed and registered, our online GeekBuddy support technicians will restore your PC to working condition. If we cannot restore your
PC due to a virus infection, Comodo will cover up to $500 in repair costs, using an authorized repair center.

User: "My PC is infected. Remove the malware or give me my $500 !"

GeekBuddy tech: "Clean install the OS."

User: "What do you mean ?"

GeekBuddy tech: "Clean install the OS and no more infection."

User: "No, I want malware removal or my $500 !"

GeekBuddy tech: "Clean installing the OS is malware removal."
 
K

KGBagent47

it's a VM with windows 7. I only use SD for my windows 10 host machine
My host machine uses GPT-UEFI drive so petya might not be able to do anything because petya only works on MBR-BIOS drive
I did not know that about UEFI, that's really good to hear. (maybe something to do with secure boot?)

Also this might be why some of the leading AVs aren't blocking MBR ransomware behavior without signatures. Bad for Windows Seven users, but I believe UEFI has been the standard for a few years now.

Unrelated Side Note: If you're not familiar with UEFI settings, good luck figuring out how to boot from a CD/Thumb Drive with it.
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
I did not know that about UEFI, that's really good to hear. (maybe something to do with secure boot?)

Also this might be why some of the leading AVs aren't blocking MBR ransomware behavior without signatures. Bad for Windows Seven users, but I believe UEFI has been the standard for a few years now.

Unrelated Side Note: If you're not familiar with UEFI settings, good luck figuring out how to boot from a CD/Thumb Drive with it.
it's the GPT that stops petya. If you have GPT, that means you don't have MBR, which is what petya messes with.
 
D

Deleted member 2913

not high CPU but persistently low CPU usage (0.1-2.5% in idle and never drops to 0%) :)
Did you faced slow down?

I tried latest CCAV on my Win 10 64 with 6GB RAM.
It slows down everything i.e not heavy slow down But noticeable slow down with everything system boot, programs starting, programs installing, etc...
 

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
Did you faced slow down?

I tried latest CCAV on my Windows 10 64 with 6GB RAM.
It slows down everything i.e not heavy slow down But noticeable slow down with everything system boot, programs starting, programs installing, etc...
I dudn't play it with long enough but I could notice some slight slowdown too, not significant
boot time was increased noticeably
 

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
I did not know that about UEFI, that's really good to hear. (maybe something to do with secure boot?)

Also this might be why some of the leading AVs aren't blocking MBR ransomware behavior without signatures. Bad for Windows Seven users, but I believe UEFI has been the standard for a few years now.

Unrelated Side Note: If you're not familiar with UEFI settings, good luck figuring out how to boot from a CD/Thumb Drive with it.
I'm OK with actually it's very easy to boot a USB from it, just temporarily switch to Legacy and boot
 

AtlBo

Level 28
Verified
Top Poster
Content Creator
Well-known
Dec 29, 2014
1,716
not high CPU but persistently low CPU usage (0.1-2.5% in idle and never drops to 0%) :)

Comodo's products do seem to differ. Was using Dragon, but issues connecting to sites began to occur. I don't lay the fault at Comodo for this, but when I installed GC, I realized a serious improvement on the PC performance-wise. It's a decent i5 2400 PC, which benches very well for a standard business class computer, so differences can be difficult to discern. That was not the case this time. Maybe it was Comodo's default extensions or others, but disabling them didn't seem account for any of the difference in PC performance.

Dragon seems in retrospect a little bit like a slightly mis-timed automobile, at least in comparison to Chrome. Is Comodo's build for Blink/Chrome based any indication of across the board struggles within the company with regards to efficiency of design? I think maybe to be honest.

Comodo would benefit by paying a high priced developer with experience in gaming optimization. CF is fine, but it's possible to detect when a program can be more efficiently streamlined. In the rush to create products, the company seems to me to have left holes in some of their programs in this regard, especially. Best optimized apps I have experienced from Comodo...Comodo Programs Manager and Comodo Cleaning Essentials. Neither are full-time run-time.
 

Fel Grossi

Level 13
Verified
Top Poster
Well-known
Jan 17, 2014
627
COMODO engineer replied in the forum about this bypass.
Comodo Cloud Antivirus 1.8.407387.418 Hotfix Version is Released! - News / Announcements / Feedback - CCAV

Yesterday
Hi Yash Khan,
Thanks for bringing attention, team is checking. We will get back soon.

Thanks
-umesh

Today
H All,
This has been identified and under QA.

We will have a release by this week-end and it will have this fix also.

This bug got into CCAV in v403 released on Dec 21, 2016 else all previous versions protected against Petya.

Thanks
-umesh
 
R

Rodney74

The one important thing is not to paint all Comodo products with the same brush as they are different. Symbolic Logic shows that an argument is invalid if it goes from a specific to a general. In the case of Comodo:

1). Comodo creates software
2). Comodo created CCAV, which sucks
3) therefore ALL Comodo products suck.

This would be similar to:

1), Meghan is a girl
2). Meghan has green eyes
3. therefore ALL girls have green eyes.


LOL... Life is easier if you have a sense of humor. I see you have that covered.
 
R

Rodney74

User: "My PC is infected. Remove the malware or give me my $500 !"

GeekBuddy tech: "Clean install the OS."

User: "What do you mean ?"

GeekBuddy tech: "Clean install the OS and no more infection."

User: "No, I want malware removal or my $500 !"

GeekBuddy tech: "Clean installing the OS is malware removal."

LOL reminds me of the vet who said what are you complaining about. Just get a new dog.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top