Welcome, Guest. Please login or register.
Did you miss your activation email?
May 25, 2013, 01:26:46 PM

Login with username, password and session length

664066 Posts
70633 Topics
145262 Members

Latest Member: EricNorris

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  AV False Positive/Negative Detection Reporting
| | | |-+  Comodo FAILS to stop "Smart Fortress"
« previous next »
Pages: [1] Go Down Print
Author Topic: Comodo FAILS to stop "Smart Fortress"  (Read 2898 times)
fantab
Comodo Member
**
Offline Offline

Posts: 42


« on: May 31, 2012, 09:22:34 AM »

I was shocked today to find my Win-VISTA PC infected with a 'rouge'ware SMART FORTRESS, a fake anti-malware application.

Comodo failed to prevent this intrusion. I have latest Comodo [CIS Free] which is up to date, I use Comodo DNS and my Defense + is set to 'proactive'.

I eventually removed the said intruder with Malwarebytes Anti-malware following the instructions on  http://forums.malwarebytes.org/index.php?showtopic=107384.

I hope Comodo will rectify their shortcomings and see to it that such intrusions do not by pass CIS in future.

Logged
Siketa
Comodo's Hero
*****
Online Online

Posts: 3161


ZIG ZAG


« Reply #1 on: May 31, 2012, 09:34:04 AM »

Did you allow it to install or it bypassed sandbox/Defense+?
Any screenshot would be of great help.
Logged
Chiron
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5589



« Reply #2 on: May 31, 2012, 11:55:05 AM »

Can you please upload the sample to VirusTotal and post a link to the results?

Thanks.
Logged

morphiusz
Star Group
Comodo's Hero
*****
Online Online

Posts: 2197


Comodo's śmieć :)


WWW
« Reply #3 on: May 31, 2012, 12:05:00 PM »

With correct installation of CIS there is no way for SmartFortress to bypass that. Whether it was sandboxed - after restart it should be gone. I bet you have even not restarted the system Smiley
Logged
Seany007
Comodo's Hero
*****
Offline Offline

Posts: 1904


Comodo Commando


« Reply #4 on: May 31, 2012, 12:57:52 PM »

You prob made a mistake somewhere mate. Also who said that Comodo is bulletproof? LOL! Comodo can be beaten.  
Logged

Proud Comodo User (CIS, CD, CID and CMS)
Siketa
Comodo's Hero
*****
Online Online

Posts: 3161


ZIG ZAG


« Reply #5 on: May 31, 2012, 01:02:31 PM »

Right! There are rare cases of trusted malware....
Maybe this is one of them...
Logged
morphiusz
Star Group
Comodo's Hero
*****
Online Online

Posts: 2197


Comodo's śmieć :)


WWW
« Reply #6 on: May 31, 2012, 01:27:56 PM »

You prob made a mistake somewhere mate. Also who said that Comodo is bulletproof? LOL! Comodo can be beaten.  

I know how this malware works, I tested it few times. I'm behind the experience, I think you make just a guess. It is not sophisticated malware.

That is true it can be whitelisted.  But that is another problem.
Logged
Seany007
Comodo's Hero
*****
Offline Offline

Posts: 1904


Comodo Commando


« Reply #7 on: May 31, 2012, 05:41:53 PM »

I know how this malware works, I tested it few times. I'm behind the experience, I think you make just a guess. It is not sophisticated malware.

That is true it can be whitelisted.  But that is another problem.

Sure it is a guess. Sophisticated malware is another matter. Could be white-listed, could be that on his PC Comodo don't function properly, could be that he is using other things, could be anything.
Logged

Proud Comodo User (CIS, CD, CID and CMS)
fantab
Comodo Member
**
Offline Offline

Posts: 42


« Reply #8 on: June 02, 2012, 10:21:04 PM »

With correct installation of CIS there is no way for SmartFortress to bypass that. Whether it was sandboxed - after restart it should be gone. I bet you have even not restarted the system Smiley

Seriously, what is the "correct installation of CIS"? I am afraid to say that SMART Fortress bypassed everything. After I discovered it on my PC/Desktop I ran a scan with Comodo a couple of times and needless to say, I restarted my PC a couple of times.

Unfortunately, I cannot upload any more information about the 'Malware' as I have cleaned it all with Malwarebytes. By the way, there is no other protection on my Vista. And as far as I know, CIS is configured properly and it has served me well in the past years.

I never said Comodo was 100% foolproof. I did not intend to bad mouth CIS but to bring the fact to the forum's notice. I am still a fan of CIS.

I hope CIS will not disappoint me in future, at least not big time.
« Last Edit: June 02, 2012, 10:26:06 PM by fantab » Logged
languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3943



« Reply #9 on: June 02, 2012, 10:29:43 PM »

how did it get installed? Rogues usually need user interaction they don't just do it.
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.049 seconds with 22 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com