Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
December 15, 2009, 06:58:48 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
342596
Posts
37851
Topics
85971
Members
Latest Member:
renata
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Virus/Malware Removal Assistance
Comodo and the malware known as 'personal antivirus'
« previous
next »
Pages:
[
1
]
Author
Topic: Comodo and the malware known as 'personal antivirus' (Read 986 times)
GiGaBaNE
Newbie
Offline
Posts: 2
Comodo and the malware known as 'personal antivirus'
«
on:
September 11, 2009, 09:31:12 AM »
Hi guys, i did a search but couldnt find a topic.
I am a big fan of Comodo and have used it for a long time, i persuade all of my friends to install it and one such friend is a bit of a muppet when it comes to safe surfing.
his previous set up was avg and comodo firewall. at some point during this time he has been infected by the 'personal antivirus'. i have updated him to the latest all in one comodo, but have as yet failed to remove this app.
had anyone else caught this malware and successfully removed it only using products supplied by Comodo?
both my own and comodo's rep are on the line with my friends at the moment.
to be fair i did say ' comodo is the only security you will ever need' so im feeling a little silly atm.
Logged
Matty_R
Global Moderator
Comodo's Hero
Offline
Posts: 1936
Nice to see you,to see you nice!
Re: Comodo and the malware known as 'personal antivirus'
«
Reply #1 on:
September 11, 2009, 09:50:43 AM »
This is one of things that is going to happen as AV software can only detect so much, these things change and evolve quite quickly so keeping up is not easy.
Anyway there is a good removal page here
http://www.bleepingcomputer.com/virus-removal/remove-personal-antivirus
which asks you to use Malwarebytes-AntiMalware, i suggest you forward the link to your friend.
Any software has limitations and used incorrectly infections can and will allways occur.
Logged
I HAD A DREAM
----But i can`t remember it......
GiGaBaNE
Newbie
Offline
Posts: 2
Re: Comodo and the malware known as 'personal antivirus'
«
Reply #2 on:
September 11, 2009, 10:05:05 AM »
Many thanks. ill use that to fix the problem.
Hopefully comodo will have a blacklist of these things in the future.
Even just a text pop up telling the user that 'the currently installing application is reported to be malware'
we love you comodo, but please just remember no matter how idiot proof you make your software, someone will always make a better idiot
Logged
tomr7
Newbie
Offline
Posts: 1
Re: Comodo and the malware known as 'personal antivirus'
«
Reply #3 on:
September 21, 2009, 04:17:52 PM »
I agree with the previous post, with a one step more: that this "malware" should be stopped by any product that claims to provide "Internet Security". I really appreciate Comodo, and have recommended to many (I use the CIS), including a few small businesses, but lately I am biting my tongue on this one. It is amazing to see that one's browser (IE or FF) can be aggressively hi-jacked by such a malware intruder (it tried to invade onto my PC through an infected site, to which I denied the installed, shutdown the browser via Task Manager, deleted all private browser files, and put its URL in the blocked list),
but today I helped a Senior Citizen (not a relative), who has the same one yr old PC model/ops that I have, get hit through an infected email from a friend (and he is running CIS). In his case, the solution to his infected PC was to install MalwareBytes product, which indeed worked. It just seems kind of pathetic to me, that we have to install yet another program to stop such malware.
For any infectious program to throw your current application basically off the screen (browser or email program) to the upper left corner and to substitute its own fake window pane up front and center, stating that AV-doctor, Personal AV (or whatever name it uses) has detected a virus on your system and you need to send them money, I would say that primary Internet Security software should stop this one dead in its tracks, not to mention the FCC should get authors behind bars.
Can't imagine the number of senior citizens getting takened in on this scheme in past few months. Please get a prevent in the CIS package for them. Thank you.
Logged
hailong.wang
Global Moderator
Comodo's Hero
Offline
Posts: 495
Re: Comodo and the malware known as 'personal antivirus'
«
Reply #4 on:
September 21, 2009, 09:21:14 PM »
Hi,
If you can find the samples,you can submit through this link:
http://internetsecurity.comodo.com/submit.php
.Then we can go to have a look at it.And blacklist is not exist for now.Thanks for ur suggestion.
Thanks and Regards,
hailong.wang
Logged
SinchuHaneefa
Newbie
Offline
Posts: 6
Re: Comodo and the malware known as 'personal antivirus'
«
Reply #5 on:
September 29, 2009, 03:14:43 AM »
Hi,
Personal Antivirus is a rogue anti-spyware created by company named Innovagest 2000 and is a clone of General Antivirus and Internet Antivirus Pro. This program is advertised through the use of Trojans that display fake security alerts on your computer.I have trouble shooted many computers infected with PAV, which also contained ( installed) with latest Symantec's Norton AV,NIS and N360 editions, as well as Mcafee , Trendmicro etc..avast, kaspersky etc..None of it has detected or able to quarantine it.
You guys will download and install Malware- Anti malware and it removes the some of the following entries , PAV had created. But it cannot remove those hidden malware setup files, that will executed later..
So a manual fix is needed some times..
Once get installed it creates the following entries..
c:\Documents and Settings\All Users\Desktop\Personal Antivirus.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus
c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus Home Page.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus\Purchase License.lnk
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Personal Antivirus.lnk
%UserProfile%\Application Data\Personal Antivirus
%UserProfile%\Application Data\Personal Antivirus\settings.ini
%UserProfile%\Application Data\Personal Antivirus\uill.ini
%UserProfile%\Application Data\Personal Antivirus\unins000.exe
%UserProfile%\Application Data\Personal Antivirus\Uninstall Personal Antivirus.lnk
%UserProfile%\Application Data\Personal Antivirus\db
%UserProfile%\Application Data\Personal Antivirus\db\config.cfg
%UserProfile%\Application Data\Personal Antivirus\db\Timeout.inf
%UserProfile%\Application Data\Personal Antivirus\db\Urls.inf
%UserProfile%\Local Settings\Application Data\Microsoft\Windows\log.txt
%UserProfile%\Local Settings\Application Data\Microsoft\Windows\pguard.ini
%UserProfile%\Local Settings\Application Data\Microsoft\Windows\services.exe
c:\Program Files\Personal Antivirus
c:\Program Files\Personal Antivirus\activate.ico
c:\Program Files\Personal Antivirus\Explorer.ico
c:\Program Files\Personal Antivirus\PerAvir.exe
c:\Program Files\Personal Antivirus\unins000.dat
c:\Program Files\Personal Antivirus\uninstall.ico
c:\Program Files\Personal Antivirus\working.log
c:\Program Files\Personal Antivirus\db
c:\Program Files\Personal Antivirus\db\DBInfo.ver
c:\Program Files\Personal Antivirus\db\ia080614.db
c:\Program Files\Personal Antivirus\db\ia080618x.db
c:\Program Files\Personal Antivirus\Languages
c:\Program Files\Personal Antivirus\Languages\IAEs.lng
c:\Program Files\Personal Antivirus\Languages\IAFr.lng
c:\Program Files\Personal Antivirus\Languages\IAGer.lng
c:\Program Files\Personal Antivirus\Languages\IAIt.lng
c:\WINDOWS\system32\log.txt
%UserProfile%\Application Data\Microsoft\Windows\winlogon.exe
%UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iGSh.png
%UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iMSh.png
%UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iPSh.png
%UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iv.exe
%UserProfile%\Local Settings\Application Data\Microsoft\Windows\log.txt
%UserProfile%\Local Settings\Application Data\Microsoft\Windows\pguard.ini
%UserProfile%\Local Settings\Application Data\Microsoft\Windows\services.exe
Associated Personal Antivirus Windows Registry Information:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Personal Antivirus_is1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ITGRDENGINE
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ITGrdEngine
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "PrS"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Personal Antivirus"
These are files related to it, many variations are available.. most of them are hidden and can remain inactive for long time..
AntiVirus_Pro.exe
Uninstall Internet Antivirus Pro.lnk
Internet Antivirus Pro Home Page.lnk
Internet Antivirus Pro.lnk
InternetAntivirusPro.exe
ska.exe
ska.dll
IAPro.exe
Internet Antivirus Pro
%PROGRAMFILES%\Internet Antivirus Pro\IAPro.exe
CIS pro package has Live PC Support service available...this service includes manual removal of Virus or malwares by expert comodo techs. It helps not only senior citizens but people of any age in computer trouble shooting..Comodo is always one step ahead in providing security!
«
Last Edit: September 29, 2009, 03:23:15 AM by SinchuHaneefa
»
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.078 seconds with 19 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com