Welcome, Guest. Please login or register.
Did you miss your activation email?
June 19, 2013, 12:06:56 AM

Login with username, password and session length

668810 Posts
71126 Topics
145740 Members

Latest Member: sushil kumar

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  Help - CIS
| | | |-+  AntiVirus Help - CIS
| | | | |-+  Windows 7 backup fails: Shadow copy problem and false positive
« previous next »
Pages: [1] Go Down Print
Author Topic: Windows 7 backup fails: Shadow copy problem and false positive  (Read 10237 times)
rurikc
Newbie
*
Offline Offline

Posts: 8


Windows 7 backup fails: Shadow copy problem and false positive
« on: February 21, 2010, 07:53:16 PM »

Hi,

I am trying to make backups of my Windows 7 system using the native system backup.

One of the cygwin binaries has been detected — falsely I'd say — as being infected.
(cygwin\usr\X11R6\bin\xdvi-xaw.bin.exe as having Heur.Dual.Extensions)

I added an exclusion but it still appears in the shadow copy area and I don't know how to "remove" it from there (\Device\HarddiskVolumeShadowCopy<NN>).

It appears that this causes the backup to fail if the directory containing the file is included in the backup (backup completes successfully if directory is excluded).

So how do I tell Comodo that the shadow copy file is OK ?

(it does not appear in "quarantined items", and the original file is already marked as safe in "my own safe files")

Cheers,
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 16990



Re: Windows 7 backup fails: Shadow copy problem and false positive
« Reply #1 on: February 22, 2010, 09:55:52 PM »

Do you see the event in View Defense + Events (Defense +  --> Common Tasks)? Can you post a screenshot of it?
Logged

rurikc
Newbie
*
Offline Offline

Posts: 8


Re: Windows 7 backup fails: Shadow copy problem and false positive
« Reply #2 on: February 22, 2010, 10:20:45 PM »

Do you see the event in View Defense + Events (Defense +  --> Common Tasks)?

No.

The only place I saw it is in the main screen, Virus Defense -> <##> threat(s) detected so far

Can you post a screenshot of it?


* Capture.PNG (37.25 KB, 869x441 - viewed 12 times.)
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 16990



Re: Windows 7 backup fails: Shadow copy problem and false positive
« Reply #3 on: February 25, 2010, 04:31:15 PM »

Good catch by also checking the AV logs. Thumb Up

How is your heuristics level set in the AV? If it is set higher than Low heuristics will become much more chatty with higher chances of false positive; then try setting it to low.

If Heuristics was set to low add the offending file to the Exclusions.
Logged

rurikc
Newbie
*
Offline Offline

Posts: 8


Re: Windows 7 backup fails: Shadow copy problem and false positive
« Reply #4 on: February 25, 2010, 06:07:26 PM »

If Heuristics was set to low add the offending file to the Exclusions.

The file is already in the exclusion list (as I specified in my first post).

The way I think it works is:
- Windows 7 takes a snapshot via shadow copy then starts to backup the shadow copy.
- Comodo catches the shadow copy and flags it as infected.
- Windows 7 finishes the backup but marks it as bad because it could not backup the flagged file.

The snapshot location appear to vary each time (postfixed with <NN> two numbers), i.e. windows 7 creates a new shadow copy each time.

I don't even know if it's possible to add files from the shadow copy to the exclusion list, I guess it's not possible and makes little sense to me anyway as it's just a filesystem snapshot.

The backup fails even if Comodo is shut down (does it need a reboot to deactivate ? then it would be a major pain)

At this point I believe it's a Comodo bug: if a file is "excluded" from the disk then it should be automatically "excluded" from the shadow copy as well.

Regards.
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 16990



Re: Windows 7 backup fails: Shadow copy problem and false positive
« Reply #5 on: February 25, 2010, 08:56:13 PM »

What happens when you add \Device\HarddiskVolumeShadowCopy* to the exclusions?
Logged

_JoeCool_
Comodo Family Member
***
Offline Offline

Posts: 58


Re: Windows 7 backup fails: Shadow copy problem and false positive
« Reply #6 on: March 28, 2010, 10:41:20 AM »

I also had this problem and I can confirm that creating the Exception solves my Backup woes...

Thanks, this should be included as a default value...
Logged
Tags: Windows 7  Backup  shadow copy 
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.283 seconds with 22 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com