Welcome, Guest. Please login or register.
December 22, 2009, 01:14:28 AM

Login with username, password and session length

344303 Posts
38045 Topics
86352 Members

Latest Member: flyingpies

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Instant Malware Analysis Online - CIMA
| | |-+  Comodo internet security fails to detect malicious website
« previous next »
Pages: [1] Go Down Print
Author Topic: Comodo internet security fails to detect malicious website  (Read 1961 times)
amitjohar
Newbie
*
Offline Offline

Posts: 7


« on: October 21, 2009, 03:03:59 AM »

I was viewing images of black labrador dog at h**p://i****s.google.com/images?hl=en&source=hp&q=black+labrador&gbv=2&aq=0&oq=black+lab&aqi=g10. I clicked on the last photo of second row which has 3 dogs. 
 
As soon as I clicked on it, a fake antivirus scan started on the browser and it wouldn't let me exit. It kept forcing me to download the fake antivirus. However, Comodo took no action whatsoever to block that malicious site. Later when i visited that same site using G-DATA antivirus it detected a virus known as Virus:    JS:Obfuscated-T [Trj] (Engine B).  But comodo antivirus fails to do anything. Why? I had comodo on real time on-access mode.

Moderator edit
Please do not post links to possible Malware on the open Forum.

If you have Malware samples please submit them here

Thank You
Dennis
« Last Edit: October 21, 2009, 04:26:47 AM by Dennis2 » Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5183



« Reply #1 on: October 21, 2009, 04:53:54 AM »

This FakeAV is currently under investigation of the AV Lab.
Logged

Forum Volunteer - Any concerns? Please send me a PM and/or review the Forum Policy !
Chaingun
Newbie
*
Offline Offline

Posts: 11


« Reply #2 on: November 01, 2009, 04:31:29 PM »

sthe exact thing happen to me about a month ago i was redirected to a fake online scan.it started without my permission and the av didnt detect it and im surprised that defense plus failed to alert me that a folder in program files was created sad realy and the folder name was windows police antivirus i think it was and the folder.i really dont feel secure with comodo anymore
Logged
smage
Comodo Family Member
***
Offline Offline

Posts: 80


« Reply #3 on: November 02, 2009, 11:12:00 PM »

sthe exact thing happen to me about a month ago i was redirected to a fake online scan.it started without my permission and the av didnt detect it and im surprised that defense plus failed to alert me that a folder in program files was created sad realy and the folder name was windows police antivirus i think it was and the folder.i really dont feel secure with comodo anymore

I hope that someone would explain why did this rogue pass Defense+.

Logged
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 1664


The only thing i ask for are eggs.


WWW
« Reply #4 on: November 02, 2009, 11:17:08 PM »

I have found that some exe's/files can get passed D+ in "Internet Security Mode", Proactive Mode can block them.


This is a known bug... will be fixed.
Logged

Happy New Year and Holidays
Please follow forum policy. Thank you.
smage
Comodo Family Member
***
Offline Offline

Posts: 80


« Reply #5 on: November 03, 2009, 10:16:41 AM »

I have found that some exe's/files can get passed D+ in "Internet Security Mode", Proactive Mode can block them.


This is a known bug... will be fixed.

Hi will it be fixed in v3 itself or we'll have to wait for v4?
This bug seems to represent a security risk for users using CIS with default configuration.

Thanks
« Last Edit: November 03, 2009, 11:44:46 AM by smage » Logged
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 1664


The only thing i ask for are eggs.


WWW
« Reply #6 on: November 03, 2009, 01:59:39 PM »

As far as i know, it will be fixed in v4.
Logged

Happy New Year and Holidays
Please follow forum policy. Thank you.
smage
Comodo Family Member
***
Offline Offline

Posts: 80


« Reply #7 on: November 03, 2009, 02:37:25 PM »

As far as i know, it will be fixed in v4.

Ok thanks.
Keep up with the good work.
Logged
amitjohar
Newbie
*
Offline Offline

Posts: 7


« Reply #8 on: December 11, 2009, 06:26:54 PM »

One thing that I have noticed which can solve this problem is to download AVG link scanner. AVG link scanner works with any antivirus.  Combining AVG link scanner with comodo will block all fake antivirus and bad websites from loading before they do any damage.
Logged
Eric Cryptid
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1743


Security Saskquatch


« Reply #9 on: December 12, 2009, 06:56:23 PM »

Another temporary alternative is: Finjan SecureBrowsing ( http://securebrowsing.finjan.com/ )
Logged


Moderator: forum policy.
System: 32 bit Windows Vista SP3
Realtime Protection:Comodo Internet Security 3.13 Internet Security
On Demand: MBAM & SAS
Other: CSC,CBU,CEVPN,CDragon.
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.04 seconds with 18 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com