Welcome, Guest. Please login or register.
Did you miss your activation email?
May 18, 2013, 05:00:43 PM

Login with username, password and session length

662896 Posts
70571 Topics
145145 Members

Latest Member: lodec

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  Help - CIS
| | | |-+  AntiVirus Help - CIS
| | | | |-+  New False Positive
« previous next »
Pages: [1] Go Down Print
Author Topic: New False Positive  (Read 2285 times)
Koskiloskaz
Newbie
*
Offline Offline

Posts: 3


« on: May 01, 2012, 01:03:02 PM »

Found a new false positive. The program is a trainer for a pc game, Fable: the lost chapters. Tried several different versions, all of which were picked up for the same reason. Apparently has something to do with how the program uses hotkeys. Would appreciate it if you could fix this somehow. Sending an image of the report.


* fable trainer false.png (89.84 KB, 1224x467 - viewed 15 times.)
Logged
HeffeD
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6588



« Reply #1 on: May 01, 2012, 01:29:14 PM »

If it's a trainer, I don't believe this is a false positive, but the application would instead fall under the 'potentially unwanted' umbrella.

Trainers do tend to mimic malware behavior, such as accessing/modifying an open applications processes in memory.

Have you added this application to your exclusions and trusted files list?
Logged

Koskiloskaz
Newbie
*
Offline Offline

Posts: 3


« Reply #2 on: May 01, 2012, 01:32:56 PM »

I'm not given the chance to. The moment I export the .exe from the .rar file, Comodo activates, says that it's stopped a Trojan, identifies and quarantines the file. I don't have a basis to put it into my trusted files, because they remove the file automatically. Since adding a trusted file requires me to browse and select it physically, rather than entering the name, I can't put it in. At least, that's how far my knowledge on it goes.
Logged
HeffeD
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6588



« Reply #3 on: May 01, 2012, 01:52:01 PM »

Sounds like you have the option Do not show antivirus alerts enabled.

Disable this option (Antivirus -> Scanner Settings -> Real Time Scanning) and you will be shown an alert which lets you decide what to do with the file. You can choose to ignore the detection and move the file to where you want it to exist. Then you can exclude it in its respective directory.
Logged

Koskiloskaz
Newbie
*
Offline Offline

Posts: 3


« Reply #4 on: May 01, 2012, 02:02:49 PM »

Ah, thanks for the help, even though this was in the wrong section. You have my gratitude.
Logged
HeffeD
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6588



« Reply #5 on: May 01, 2012, 02:43:18 PM »

You're welcome. Smiley

I've moved this post to the AV Help forum.
Logged

Qiuhui.Wang
First Response Group
Comodo's Hero
*****
Offline Offline

Posts: 389



« Reply #6 on: May 01, 2012, 04:28:57 PM »

Found a new false positive. The program is a trainer for a pc game, Fable: the lost chapters. Tried several different versions, all of which were picked up for the same reason. Apparently has something to do with how the program uses hotkeys. Would appreciate it if you could fix this somehow. Sending an image of the report.

Hi Koskiloskaz,

Thanks for reporting.
Could you please submit the detected file at
http://internetsecurity.comodo.com/submit.php.

Regards
Qiuhui.Wang
Logged
Tags: false  positive  fable  trainer 
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.312 seconds with 23 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com