Welcome, Guest. Please login or register.
October 11, 2008, 02:33:07 PM

Login with username, password and session length

199331 Posts
22897 Topics
54958 Members

Latest Member: kefik

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Anti-Viruspyware (CAVS)
| | |-+  Feedback/Comments/Announcements/News about CAVS
| | | |-+  CAV missed 2 Trojans
« previous next »
Pages: [1] Go Down Print
Author Topic: CAV missed 2 Trojans  (Read 3433 times)
rrcole
Newbie
*
Offline Offline

Posts: 7


« on: October 11, 2007, 07:09:39 AM »

I noticed yesterday that some weird things started happening to my computer, such as the regedit and control panels where locked out by the admin. My account has admin privilages so I suspected a virus. I ram CAV and it came up clean. I then ran some online scanners and they all got hits for a virus infection. I downloaded AVG and ran it. It tagged and removed 3 viruses Trojan Horse Generic8.jdu, Obfustat.swa and Trojan Horse Generic5.HHS.  Why did CAV not catch these?
Logged
ganda
newbie hunter
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3163


counting newbies


« Reply #1 on: October 11, 2007, 07:43:35 AM »

hi rrcole
 Wave
i should say CAVS is still a BETA, the detection rate ain't the best yet, and there's no AV that can detects 100% malwares out there.
could you pls send the virus/trojan sample to comodo? it will help comodo enlarge its database.

welcome to the forum
 Hug
Ganda
Logged

Current Goals;
* get a new piggy doll
* become a superhero
* raise my level to 45
* learn lightning base magic
rrcole
Newbie
*
Offline Offline

Posts: 7


« Reply #2 on: October 11, 2007, 07:57:31 AM »

not to sound stupid, but how do I do that?


hi rrcole
 Wave
i should say CAVS is still a BETA, the detection rate ain't the best yet, and there's no AV that can detects 100% malwares out there.
could you pls send the virus/trojan sample to comodo? it will help comodo enlarge its database.

welcome to the forum
 Hug
Ganda
Logged
ganda
newbie hunter
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3163


counting newbies


« Reply #3 on: October 11, 2007, 11:41:04 AM »

on CAVS quarantine tab, there's a "submit files" button. then browse & send the suspected file.
and you can email the samples too, but i forgot the email address  Grin (now THIS is sound stupid  Tongue ), maybe someone know it? help me please.

P.S. and what about the CAVS HIPS, it doesn't give any warning when these trojans execute?

Ganda
Logged

Current Goals;
* get a new piggy doll
* become a superhero
* raise my level to 45
* learn lightning base magic
Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6017



« Reply #4 on: October 11, 2007, 02:25:39 PM »

You can email them to: malwaresubmit [ at ] avlab.comodo.com .
You may want to specify in the subject line "possible malware" for clarity's sake.
Compress to a zip archive and password protect with "infected" - including that information in the body.

All of this, of course, is predicated on you still having a copy of the malware.  AVG probably has them in its quarantine.

LM

Logged

date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
MJ1988
Comodo Loves me
****
Offline Offline

Posts: 135


« Reply #5 on: December 25, 2007, 02:57:14 AM »

Every Antivirus is different. They all have different virus definitions, same for spyware.

Those trojans could have been false positives, AVG is notorious for detecting them.
Logged

Call me Matt. =P
Burillo
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 324


Bunghole


« Reply #6 on: December 25, 2007, 06:19:39 AM »

maybe you could try some other online scanners - like Trend Micro Housecall or KAV online scanner...

PS definitely not a false positive.
Logged

Some people are dumb... (c) Butt-head

Remember! CIA is watching you!
xergxies
Newbie
*
Offline Offline

Posts: 2


« Reply #7 on: March 31, 2008, 10:25:36 AM »

happen to me also today... my registry, folder option, task manager and cmd been disable after inserting my friend thumb drive. Even i block when CAV HIPS tell me there's a program execution when i insert the thumb drive, the virus still manage to attack. maybe because i leave HIPS to default setting. Already submit the file to comodo lab.. hope it will include in database soon.

Been using beta for about a month and i never encounter technical problem such as BSOD and lock program. No problem while uninstalling also. Hope CAV will get better after leave beta.

For now i change back using Avast! Thanks to Avast! boot time scan i manage to get rid all 300+ virus which some of them reside in memory and can't delete while Windows run. Looking forward to CAV 3..
 Viva Comodo Comodo Rocks
Logged
3xist
Guest
« Reply #8 on: May 31, 2008, 03:24:52 AM »

Locked.

Reason: Out-Dated post.

Josh
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.279 seconds with 19 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com