Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 18, 2013, 06:38:46 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
662897
Posts
70571
Topics
145146
Members
Latest Member:
amithiel
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
Help - CIS
AntiVirus Help - CIS
AV real-time does not detect viruses downloaded in Chrome and Firefox
« previous
next »
Pages:
[
1
]
2
Author
Topic: AV real-time does not detect viruses downloaded in Chrome and Firefox (Read 6812 times)
praful
Newbie
Offline
Posts: 6
AV real-time does not detect viruses downloaded in Chrome and Firefox
«
on:
October 22, 2010, 01:56:35 AM »
Hello
There is a web site, eicar.org, that provides test virus files that can be downloaded in eight forms (http, https, unzipped, zipped). These are not real viruses: they're just files whose signature is recognised by all AV tools.
Here the results of testing the eicar files with IE, Firefox and Chrome:
- Comodo real-time detects the virus in the eight files in IE 8.0.7600.16385.
- Comodo real-time DOES NOT detect the virus in the eight files in Firefox 3.6.10.
- Comodo real-time DOES NOT detect the virus in the eight files in Chrome 7.0.517.41 beta (it failed on the latest non-beta as well).
That means the real-time scanning is ineffective with Firefox and Chrome. You have to wait for the scheduled scan to run, which could be up to a week, before the virus is detected by which time a lot of damage could have been done to your PC!
Please address this ASAP.
Thanks
Praful
Logged
brucine
Comodo's Hero
Offline
Posts: 1533
Re: AV real-time does not detect viruses downloaded in Chrome and Firefox
«
Reply #1 on:
October 22, 2010, 04:05:35 AM »
I don't know about Chrome, but you are definitely wrong about FF 3.6: the real-time alert detects all of them, i suppose you have some defectuous sandboxing and/or virtual machine settings.
Logged
clockwork
Comodo's Hero
Offline
Posts: 1922
Oxygen requires Chuck Norris to live
Re: AV real-time does not detect viruses downloaded in Chrome and Firefox
«
Reply #2 on:
October 22, 2010, 05:41:36 PM »
really? the comodo antivirus scans archives now with the real time scanner? because two of eicars are archives...
Logged
"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
Guillermo391
Comodo Loves me
Offline
Posts: 135
Re: AV real-time does not detect viruses downloaded in Chrome and Firefox
«
Reply #3 on:
October 22, 2010, 06:24:21 PM »
The thing is it will not detect the archives, but it will detect them when opened.
Logged
HeffeD
Global Moderator
Comodo's Hero
Offline
Posts: 6588
Re: AV real-time does not detect viruses downloaded in Chrome and Firefox
«
Reply #4 on:
October 23, 2010, 05:54:43 PM »
Everything is working as advertised on Firefox 3.6.11 here.
Downloading the .com file is caught as it is attempted to save to the HD. (The desktop in this instance, see screenshot) Firefox will indeed open the .txt file without issue, but if you read the website, the only reason for the .txt file is because some people have problems downloading the .com file. The .txt file is intended to be downloaded and renamed eicar.com to circumvent these download issues.
The archives are indeed not scanned when downloaded. The AV engine is an on-access scanning engine, so by design to improve performance, archives are only scanned when accessed.
Contrary to what some may think, there is absolutely no risk in having inert malware sitting in an archive on your HD for any length of time. The only thing that matters is whether or not the AV can grab the malware when it actually runs.
EICARCaught.png
(18.06 KB, 395x246 - viewed 24 times.)
Logged
Please read the
Forum Policy
!
Breast Cancer Awareness
American Cancer Society
clockwork
Comodo's Hero
Offline
Posts: 1922
Oxygen requires Chuck Norris to live
Re: AV real-time does not detect viruses downloaded in Chrome and Firefox
«
Reply #5 on:
October 24, 2010, 04:31:28 AM »
there is a risk if you have a virus on your drive... one day it might be copy pasted on a stick, you bring it to another pc, and ...
one day you might have comodo on trainings mode to let a game work, and ...
i dont want a virus on my drive at all.
Logged
"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
brucine
Comodo's Hero
Offline
Posts: 1533
Re: AV real-time does not detect viruses downloaded in Chrome and Firefox
«
Reply #6 on:
October 24, 2010, 04:40:40 AM »
Whatever the mode is, you cannot, even if Comodo was not installed at all, run an executable from a compressed folder without opening the said folder.
Scanning compressed archives somehow makes no sense, as only their access is relevant.
Logged
clockwork
Comodo's Hero
Offline
Posts: 1922
Oxygen requires Chuck Norris to live
Re: AV real-time does not detect viruses downloaded in Chrome and Firefox
«
Reply #7 on:
October 24, 2010, 07:12:13 AM »
"i dont want a virus on my drive at all."
Logged
"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
HeffeD
Global Moderator
Comodo's Hero
Offline
Posts: 6588
Re: AV real-time does not detect viruses downloaded in Chrome and Firefox
«
Reply #8 on:
October 24, 2010, 09:29:17 AM »
Again, as hard as it may be to believe, a virus sitting in an archive is as good as having no virus on your drive...
Logged
Please read the
Forum Policy
!
Breast Cancer Awareness
American Cancer Society
Chiron
Global Moderator
Comodo's Hero
Offline
Posts: 5563
Re: AV real-time does not detect viruses downloaded in Chrome and Firefox
«
Reply #9 on:
October 24, 2010, 10:49:35 AM »
A manual scan will check inside archives and catch it anyway. I believe the reason that real-time does not is to save system resources.
Logged
How To Install Comodo Firewall
How To Stay Safe While Online
jay2007tech
Malware Research Group
Global Moderator
Comodo's Hero
Offline
Posts: 1795
Re: AV real-time does not detect viruses downloaded in Chrome and Firefox
«
Reply #10 on:
October 25, 2010, 01:29:21 PM »
Quote
Scanning compressed archives somehow makes no sense, as only their access is relevant.
+ 1 I agree
Logged
It's hard being a crooked Admin when the files won't pass an md5checksum test. But like any other good crooked Admin it can be done, it just takes time(and lots of it) and a few aspirins
Hikertrash
Comodo's Hero
Offline
Posts: 420
Re: AV real-time does not detect viruses downloaded in Chrome and Firefox
«
Reply #11 on:
June 30, 2012, 12:25:38 PM »
Since I recently started using Chrome, I was curious about dowloads being scanned for virus. Happy to confirm, CIS caught a eicar.com, text and a zip from Eicar.
«
Last Edit: June 30, 2012, 12:34:11 PM by Hikertrash
»
Logged
Dell Vostro 3500 | Windows 7 Pro 32bit | 500GB HD [at] 7200 rpm | 4 GB ram | Intel i5 | CIS v5.10|CTC|
clockwork
Comodo's Hero
Offline
Posts: 1922
Oxygen requires Chuck Norris to live
Re: AV real-time does not detect viruses downloaded in Chrome and Firefox
«
Reply #12 on:
July 01, 2012, 06:47:39 AM »
"Caught eicar"
Because it knows it.
I see eicar as a test "if your antivirus is switched on"
Logged
"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
Seany007
Comodo's Hero
Offline
Posts: 1884
Comodo Commando
Re: AV real-time does not detect viruses downloaded in Chrome and Firefox
«
Reply #13 on:
July 04, 2012, 07:53:17 PM »
Don't use old or beta versions. They are not stable and you risk massive security problems.
Logged
Proud Comodo User (CIS, CD, CID and CMS)
HeffeD
Global Moderator
Comodo's Hero
Offline
Posts: 6588
Re: AV real-time does not detect viruses downloaded in Chrome and Firefox
«
Reply #14 on:
July 04, 2012, 08:07:28 PM »
Quote from: Seany007 on July 04, 2012, 07:53:17 PM
Don't use old or beta versions. They are not stable and you risk massive security problems.
What is this reply in regards to?
Logged
Please read the
Forum Policy
!
Breast Cancer Awareness
American Cancer Society
Tags:
Chrome
eicar
firefox
av
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.048 seconds with 23 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com