Welcome, Guest. Please login or register.
Did you miss your activation email?
May 25, 2013, 06:41:25 AM

Login with username, password and session length

664042 Posts
70630 Topics
145258 Members

Latest Member: AmelieKMF

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  AV False Positive/Negative Detection Reporting
| | | |-+  Post here your unfixed FP's (only after 2 days)
« previous next »
Pages: 1 ... 5 6 [7] 8 9 ... 13 Go Down Print
Author Topic: Post here your unfixed FP's (only after 2 days)  (Read 103043 times)
cavehomme
Comodo's Hero
*****
Offline Offline

Posts: 304


« Reply #90 on: July 20, 2010, 04:08:24 AM »

CIS Plus latest version is always flagging for sandboxing gfxui.exe in system32 folder for sandboxing, after logging onto Win 7 user account (admin).

This is a valid Intel graphic file. I always select not to sandbox it, but it always comes up next time i startup. Added to my safe files, but still same problem.

CIS has been re-installed and with new profile for Internet Security, but still occurs.

Screenshot attached. By the way, does not allow to select "always trust the publisher of this file"
 


* gfxui.JPG (30.31 KB, 353x305 - viewed 11 times.)
Logged

Windows 7 HP 32
Firewall: Windows
AV: CAV, Hitman Pro
Browser: Comodo IceDragon
Comodo DNS enabled
haja
First Response Group
Comodo's Hero
*****
Offline Offline

Posts: 703



« Reply #91 on: July 20, 2010, 04:40:33 AM »

Hi cavehomme,

CIS Plus latest version is always flagging for sandboxing gfxui.exe in system32 folder for sandboxing, after logging onto Win 7 user account (admin).

This is a valid Intel graphic file. I always select not to sandbox it, but it always comes up next time i startup. Added to my safe files, but still same problem.

CIS has been re-installed and with new profile for Internet Security, but still occurs.

Screenshot attached. By the way, does not allow to select "always trust the publisher of this file"
 

Please submit the file at http://www.comodo.com/home/internet-security/submit.php.

Thanks and Regards,
Haja
Logged
Dennis2
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6583



« Reply #92 on: July 20, 2010, 05:56:26 AM »

CIS Plus latest version is always flagging for sandboxing gfxui.exe in system32 folder for sandboxing, after logging onto Win 7 user account (admin).

This is a valid Intel graphic file. I always select not to sandbox it, but it always comes up next time i startup. Added to my safe files, but still same problem.

CIS has been re-installed and with new profile for Internet Security, but still occurs.

Screenshot attached. By the way, does not allow to select "always trust the publisher of this file"
 
Please read here there is a suggested cure which might work here last post in Topic.
Logged

Moderator: Aims Forum a friendly place. Any concerns? Please PM me and/or review the Forum Policy 2012Updated.
System:Windows 7 SP1(UAC)x32, LUA, CIS6.2813, Sandboxie 3.76
Vista Home P.(UAC)x32 SP2, LUA,C. 5.12.
cavehomme
Comodo's Hero
*****
Offline Offline

Posts: 304


« Reply #93 on: July 22, 2010, 03:31:07 AM »

Please read here there is a suggested cure which might work here last post in Topic.

Thanks. Tried all that, apart from playing with the registry, and added all the relevant intel files as trusted files / my safe files, adding "gfxui.exe" with quote marks....but still the same. Really annoying. D+ basically allocates it as a limited file at each startup and ignores my settings.
Logged

Windows 7 HP 32
Firewall: Windows
AV: CAV, Hitman Pro
Browser: Comodo IceDragon
Comodo DNS enabled
suhaifeng
First Response Group
Comodo Member
*****
Offline Offline

Posts: 34



« Reply #94 on: July 22, 2010, 09:05:07 PM »

Thanks. Tried all that, apart from playing with the registry, and added all the relevant intel files as trusted files / my safe files, adding "gfxui.exe" with quote marks....but still the same. Really annoying. D+ basically allocates it as a limited file at each startup and ignores my settings.
Hi cavehomme,
Please submit the file at http://www.comodo.com/home/internet-security/submit.php.

Thanks and Regards,
suhaifeng
Logged
cavehomme
Comodo's Hero
*****
Offline Offline

Posts: 304


« Reply #95 on: July 23, 2010, 02:02:14 PM »

Hi cavehomme,
Please submit the file at http://www.comodo.com/home/internet-security/submit.php.

Thanks and Regards,
suhaifeng

Hi submitted it a few days ago together with screenshot. Thanks
Logged

Windows 7 HP 32
Firewall: Windows
AV: CAV, Hitman Pro
Browser: Comodo IceDragon
Comodo DNS enabled
steve_21
Newbie
*
Offline Offline

Posts: 1


« Reply #96 on: August 07, 2010, 01:38:58 AM »

DB 5671, still detected rtcshare.exe.

http://www.virustotal.com/zh-tw/analisis/0e15ec8ffa104dc5e7dad2daf13a1b7ab3487648ac83169fd4cb100db0c7efd0-1281154659

Heur.Suspicious C:\WINDOWS\system32\rtcshare.exe
Logged
Vaishnavi
Comodo's Hero
*****
Offline Offline

Posts: 376



« Reply #97 on: August 07, 2010, 03:53:01 AM »

Hi steve_21,

DB 5671, still detected rtcshare.exe.

http://www.virustotal.com/zh-tw/analisis/0e15ec8ffa104dc5e7dad2daf13a1b7ab3487648ac83169fd4cb100db0c7efd0-1281154659

Heur.Suspicious C:\WINDOWS\system32\rtcshare.exe

Thanks for reporting.Fix will be available in next few updates.

Regards,
Vaishnavi.V.K
Logged
meidan
First Response Group
Comodo's Hero
*****
Offline Offline

Posts: 1179



« Reply #98 on: August 07, 2010, 12:39:00 PM »

DB 5671, still detected rtcshare.exe.

http://www.virustotal.com/zh-tw/analisis/0e15ec8ffa104dc5e7dad2daf13a1b7ab3487648ac83169fd4cb100db0c7efd0-1281154659

Heur.Suspicious C:\WINDOWS\system32\rtcshare.exe

Hi steve_21,

This is to inform you that reported false-positive has been fixed.
You can update to AV database Version <5672> of  Comodo Internet Security
Version<4.1.150349.920> and confirm it.
Thanks.

Kind Regards,
Erik M.
Comodo AntiVirus Lab
Logged
Syl
Comodo's Hero
*****
Offline Offline

Posts: 512



« Reply #99 on: August 14, 2010, 03:38:39 AM »

I've got a lot of FP with the latest Win7 update (x64).
I got one with dotNetFx40LP_Client_x86_x64fr.exe, do you want me to submit this file ?
What happen when I click "ignore" then "submit" in the popup ?
Logged

Router: WRT54GL with TomatoUSB k24 VPN with Adblock
Windows 7 x64: CIS 5, Quick Start Guide
Vaishnavi
Comodo's Hero
*****
Offline Offline

Posts: 376



« Reply #100 on: August 14, 2010, 03:42:54 AM »

Hi Syl,

I've got a lot of FP with the latest Win7 update (x64).
I got one with dotNetFx40LP_Client_x86_x64fr.exe, do you want me to submit this file ?


Please submit the detected file using http://internetsecurity.comodo.com/submit.php.

Regards,
Vaishnavi.V.K
Logged
meidan
First Response Group
Comodo's Hero
*****
Offline Offline

Posts: 1179



« Reply #101 on: August 14, 2010, 11:17:11 AM »

I've got a lot of FP with the latest Win7 update (x64).
I got one with dotNetFx40LP_Client_x86_x64fr.exe, do you want me to submit this file ?
What happen when I click "ignore" then "submit" in the popup ?

Hi Syl,

This is to inform you that reported false-positive has been fixed.
You can update to AV database Version <5739> of  Comodo Internet Security
Version<4.1.150349.920> and confirm it.
Thanks.

Kind Regards,
Erik M.
Comodo AntiVirus Lab
Logged
Syl
Comodo's Hero
*****
Offline Offline

Posts: 512



« Reply #102 on: August 14, 2010, 11:25:01 AM »

thank you.
Logged

Router: WRT54GL with TomatoUSB k24 VPN with Adblock
Windows 7 x64: CIS 5, Quick Start Guide
Ronny
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 13184


Volunteer Moderator


« Reply #103 on: September 03, 2010, 06:35:12 AM »

Reported several times before (web-interface)....

WinSCP file
Source here:
http://winscp.net/download/winscp428setup.exe

Heur.Suspicious[at]113873906

Pass = infected

* WinSCP.7z (34.49 KB - downloaded 2 times.)
Logged

Volunteer Moderator
Any concerns? Please send me a PM or review the Forum Policy -  update Jan 3rd 2013!
Ionel
Comodo Staff
Comodo's Hero
*****
Offline Offline

Posts: 667



« Reply #104 on: September 03, 2010, 06:55:34 AM »

Hi Ronny,

Reported several times before (web-interface)....

WinSCP file
Source here:
http://winscp.net/download/winscp428setup.exe

Heur.Suspicious[at]113873906

Pass = infected

We'll verify this and get back to you when reaching a conclusion.

Regards,
Ionel
Logged
Tags:
Pages: 1 ... 5 6 [7] 8 9 ... 13 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.124 seconds with 21 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com