Welcome, Guest. Please login or register.
September 09, 2010, 02:58:58 AM

Login with username, password and session length

424777 Posts
46922 Topics
106447 Members

Latest Member: luciano corsini

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products & Services
| |-+  Comodo Instant Malware Analysis Online - CIMA
| | |-+  Comodo internet security fails to detect malicious website
« previous next »
Pages: [1] Go Down Print
Author Topic: Comodo internet security fails to detect malicious website  (Read 8612 times)
amitjohar
Newbie
*
Offline Offline

Posts: 7


« on: October 21, 2009, 03:03:59 AM »

I was viewing images of black labrador dog at h**p://i****s.google.com/images?hl=en&source=hp&q=black+labrador&gbv=2&aq=0&oq=black+lab&aqi=g10. I clicked on the last photo of second row which has 3 dogs. 
 
As soon as I clicked on it, a fake antivirus scan started on the browser and it wouldn't let me exit. It kept forcing me to download the fake antivirus. However, Comodo took no action whatsoever to block that malicious site. Later when i visited that same site using G-DATA antivirus it detected a virus known as Virus:    JS:Obfuscated-T [Trj] (Engine B).  But comodo antivirus fails to do anything. Why? I had comodo on real time on-access mode.

Moderator edit
Please do not post links to possible Malware on the open Forum.

If you have Malware samples please submit them here

Thank You
Dennis
« Last Edit: October 21, 2009, 04:26:47 AM by Dennis2 » Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7912


Volunteer Moderator


« Reply #1 on: October 21, 2009, 04:53:54 AM »

This FakeAV is currently under investigation of the AV Lab.
Logged

Volunteer Moderator
Any concerns? Please send me a PM and/or review the Forum Policy -  update 3rd August 2010!
Chaingun
Newbie
*
Offline Offline

Posts: 13


« Reply #2 on: November 01, 2009, 04:31:29 PM »

sthe exact thing happen to me about a month ago i was redirected to a fake online scan.it started without my permission and the av didnt detect it and im surprised that defense plus failed to alert me that a folder in program files was created sad realy and the folder name was windows police antivirus i think it was and the folder.i really dont feel secure with comodo anymore
Logged
ComoJust
Comodo Loves me
****
Online Online

Posts: 154


« Reply #3 on: November 02, 2009, 11:12:00 PM »

sthe exact thing happen to me about a month ago i was redirected to a fake online scan.it started without my permission and the av didnt detect it and im surprised that defense plus failed to alert me that a folder in program files was created sad realy and the folder name was windows police antivirus i think it was and the folder.i really dont feel secure with comodo anymore

I hope that someone would explain why did this rogue pass Defense+.

Logged
OmeletGuy
Going away for a while..
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2099


The only thing i ask for are eggs.


« Reply #4 on: November 02, 2009, 11:17:08 PM »

I have found that some exe's/files can get passed D+ in "Internet Security Mode", Proactive Mode can block them.


This is a known bug... will be fixed.
Logged
ComoJust
Comodo Loves me
****
Online Online

Posts: 154


« Reply #5 on: November 03, 2009, 10:16:41 AM »

I have found that some exe's/files can get passed D+ in "Internet Security Mode", Proactive Mode can block them.


This is a known bug... will be fixed.

Hi will it be fixed in v3 itself or we'll have to wait for v4?
This bug seems to represent a security risk for users using CIS with default configuration.

Thanks
« Last Edit: November 03, 2009, 11:44:46 AM by smage » Logged
OmeletGuy
Going away for a while..
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2099


The only thing i ask for are eggs.


« Reply #6 on: November 03, 2009, 01:59:39 PM »

As far as i know, it will be fixed in v4.
Logged
ComoJust
Comodo Loves me
****
Online Online

Posts: 154


« Reply #7 on: November 03, 2009, 02:37:25 PM »

As far as i know, it will be fixed in v4.

Ok thanks.
Keep up with the good work.
Logged
amitjohar
Newbie
*
Offline Offline

Posts: 7


« Reply #8 on: December 11, 2009, 06:26:54 PM »

One thing that I have noticed which can solve this problem is to download AVG link scanner. AVG link scanner works with any antivirus.  Combining AVG link scanner with comodo will block all fake antivirus and bad websites from loading before they do any damage.
Logged
Eric Cryptid
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1997


Security Saskquatch


« Reply #9 on: December 12, 2009, 06:56:23 PM »

Another temporary alternative is: Finjan SecureBrowsing ( http://securebrowsing.finjan.com/ )
Logged


Moderator: Any concerns? PM me and/or review the Forum Policy -  update 1st March 2010!
System: 32 bit Windows Vista SP3
Realtime Protection:CIS 4 Proactive
nickadin
Newbie
*
Offline Offline

Posts: 6


« Reply #10 on: December 28, 2009, 07:32:39 PM »

if you have firefox you can install the WOT add on
https://addons.mozilla.org/en-US/firefox/addon/3456
Logged
andrewuaic
Comodo Family Member
***
Offline Offline

Posts: 78


« Reply #11 on: January 02, 2010, 07:42:04 AM »

For extra safety you could use a sandbox program, that way all threats remain in a enclosed space.
Logged
hehomain
Comodo Family Member
***
Offline Offline

Posts: 66



« Reply #12 on: January 03, 2010, 06:58:14 AM »

as far as i am concerned. i find trend micro web protection add-on surprising . Smiley . It is an ip-blocker but based on behaviour analysis. It is the perfect complement to linkextend and comodo verification engine (don't forget no script and adblock)
Logged

La difference est une similitude universelle  Smiley
redwine
Newbie
*
Offline Offline

Posts: 2


« Reply #13 on: February 01, 2010, 01:24:21 PM »

Was this program by chance called "Total Security"?  If so good luck getting it removed.  I found that the key to removing it was to go into the Properties Box and remove the read only check marks from all of the files starting with the furthest files down the list.  Work your way back up.  Then use a really good Malware Program to eliminate this program.  Someone went to great lengths with this program to make it look just like a Microsoft Security Program.  I hope this helps.  I have some friends who are older and they got this program while doing a search on Google and I have not been able to get it off their computer yet.  It will not let me even load Malware Bytes or other like programs so that I can kill it.
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.048 seconds with 18 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com