Welcome, Guest. Please login or register.
March 18, 2010, 12:45:00 PM

Login with username, password and session length

372467 Posts
41293 Topics
93950 Members

Latest Member: Partyboy

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  News / Announcements / Feedback - CIS
| | | |-+  This does not make sense.
« previous next »
Pages: [1] Go Down Print
Author Topic: This does not make sense.  (Read 1909 times)
schwartr
Comodo Loves me
****
Offline Offline

Posts: 103


« on: February 19, 2009, 09:39:27 PM »

I went to http://www.eicar.org/anti_virus_test_file.htm to test out the av. When I downloaded the file eicar.com the av alerted me it was a virus. However, when I downloaded eicar.com.zip and eicar2com.zip it downloaded fine. However, when I scanned it with the r-click option it revealed the virus.

What does not make sense is that cis did not catch it when it was downloaded. Doesn't cis scan all downloads. If so, it seems like cis should have caught it especially since cis can detect it as a virus with the right click scan.

So how can cis miss it when it does the download scan, but catch it with a manual scan?
Logged
John Buchanan
Behold, There be dragons beyond these walls
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2741


Behold, there be Dragons here!


« Reply #1 on: February 19, 2009, 09:46:23 PM »

No, I do not think CIS scans as files are downloaded.  Viruses need to be either on the HDD or in memory to be of any threat.  The first file was the virus (test) file and it was immediately flagged.  The other two were repackaged, so it took a manual scan to find them.  I haven't tested this yet, but I believe once the files are unzipped and loaded into memory, the AV or D+ should pick them up.
Could someone else please confirm if I am correct on this?
Logged

Please follow Comodo Forum Policy

Maximus III Formula, i7-860 [at] 3.7GHz, 8GB DDR3-1600, Win7 Ultimate x64
schwartr
Comodo Loves me
****
Offline Offline

Posts: 103


« Reply #2 on: February 19, 2009, 09:46:49 PM »

I looked into it a bit more and apparently its just cis does not have the ability to detect viruses hidden in zipped files. CIS can detect this virus, but just not in zip form.

Is this something that will be remedied in latter versions? hopefully so.
Logged
schwartr
Comodo Loves me
****
Offline Offline

Posts: 103


« Reply #3 on: February 19, 2009, 09:54:40 PM »

No, I do not think CIS scans as files are downloaded.  Viruses need to be either on the HDD or in memory to be of any threat.  The first file was the virus (test) file and it was immediately flagged.  The other two were repackaged, so it took a manual scan to find them.  I haven't tested this yet, but I believe once the files are unzipped and loaded into memory, the AV or D+ should pick them up.
Could someone else please confirm if I am correct on this?


comodo does scan downloads. I just tested it. After I dl a file it says "scan for virus" when I disable the av it does not say that.
Logged
Bad Frogger
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 936



« Reply #4 on: February 19, 2009, 10:05:52 PM »

Hi, John you're right.

The scanner is on access reads/writes.

"After I dl a file it says "scan for virus" when I disable the av it does not say that"
Partially correct, your browser is calling up the AV, if found to scan the DL.
The same as if you right click scanned them.
The behavior you see with the eicar.com file proves the scanner scans the files
as written so having the browser do it again is redundant anyway.

The zipped ones are caught on access/read so try to open, explore, or unzip and
viral executable is detected then.
The "viral" files are harmless and can not be executed from the archived state.

So there is nothing to fix, as this is the expected behavior.
There is sound reasoning behind this.

Later  Cheers


Major edit: as rambling filter was set to very low.
« Last Edit: February 19, 2009, 10:43:55 PM by Bad Frogger » Logged

CIS    Firefox  NoScript  Please remember to follow The Forum Policy.
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.051 seconds with 17 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com