Comodo Internet Security 2025 does not contain RANSOMWARE (bypass, infection and lost of files)

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,513
Why not set containment to "block" unrecognized files and programs instead?

This setting alone will not prevent several fileless methods. Without Script Analysis settings several fileless attacks might not be contained, so the "Block" setting could not help.
 
Last edited:
  • +Reputation
Reactions: simmerskool

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,513
I still say sandboxie is the best defense when properly used when knowing a file could be malicious or you are savvy enough to use it.

It is not for most people, but it can be the best defense for you or others. Almost all users apply Sandboxie on demand, so it cannot be compared to Comodo which uses auto-containment.
I used Sandboxie for a few years and still have several sandboxes with very different restrictions on my old disk images.
Also, the term "best defense" has a different meaning for many people. :)

Edit.
Most users who use Sandboxie are unprotected against the attacks mentioned in this thread.
It is possible to use auto-sandboxed Windows Explorer (explorer.exe) for more security, but I knew only one person who used Sandboxie that way.
 
Last edited:
  • +Reputation
Reactions: simmerskool

vitao

Level 2
Thread author
Mar 12, 2024
64
Latest Xcitium edition (Xcitium Client Security 13.2.0.9560) exploited by the same poc. RansomFest it seems...

Edit. Default Configs for endpoint. The recomended one from Xcitium EDR Dashboard.

Edit.: I see there is an 13.3.1 edition released (anounced on their forum) but i have no idea on how to upgrade to it or download it. Does anyone have any idea? Or is it something wrong with their edr dashboard/platform preventing clients to have the latest client released? or is it not released? o_O
 

Attachments

  • xcitium1.jpg
    xcitium1.jpg
    200.4 KB · Views: 20
  • xcitium2.jpg
    xcitium2.jpg
    158.3 KB · Views: 18
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top