Welcome, Guest. Please login or register.
November 11, 2009, 12:20:37 AM

Login with username, password and session length

333920 Posts
36883 Topics
83668 Members

Latest Member: binodkoomar

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Bug Report - CIS
| | | |-+  False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
| | | | |-+  New FP with CIS 3.10 - cltest.exe
« previous next »
Pages: [1] Go Down Print
Author Topic: New FP with CIS 3.10 - cltest.exe  (Read 174 times)
puddingpants
Comodo Member
**
Offline Offline

Posts: 31


« on: July 05, 2009, 05:10:55 PM »


Hi all.  Just upgraded from CIS 3.9.95478.509 to 3.10.102194.530 yesterday, and found what is probably another false positive.  Path on my machine:

C:\Program Files\Cyberlink\PowerDVD\cltest.exe

File desc: "CLTest"
File size: 167,936 bytes
File mod date: Wednesday, November 03, 2004, 12:24:46 AM

Detected by CIS 3.10 AV as: "Heur.Suspicious[at]25545169"
Virus Signature Database Version: 1550

CIS 3.9's AV never complained about this file, and CIS 3.10 didn't either, until today's Virus signature database was used.  The file has apparently been there quite awhile.  I ran this file through virscan.org, and it came back clean from ALL the scanning engines, including Comodo AV 3.9 (the most recent version virscan.org has, apparently).  Windows Defender says it's fine, too.

Given all this, I'm almost completely sure it's an FP.  Can someone at Comodo have a look?

I've submitted the file for Comodo's analysis, via the Quarantine screen.

Thanks guys!

Logged
hailong.wang
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 453



« Reply #1 on: July 05, 2009, 08:40:54 PM »

Hi all.  Just upgraded from CIS 3.9.95478.509 to 3.10.102194.530 yesterday, and found what is probably another false positive.  Path on my machine:

C:\Program Files\Cyberlink\PowerDVD\cltest.exe

File desc: "CLTest"
File size: 167,936 bytes
File mod date: Wednesday, November 03, 2004, 12:24:46 AM

Detected by CIS 3.10 AV as: "Heur.Suspicious[at]25545169"
Virus Signature Database Version: 1550

CIS 3.9's AV never complained about this file, and CIS 3.10 didn't either, until today's Virus signature database was used.  The file has apparently been there quite awhile.  I ran this file through virscan.org, and it came back clean from ALL the scanning engines, including Comodo AV 3.9 (the most recent version virscan.org has, apparently).  Windows Defender says it's fine, too.

Given all this, I'm almost completely sure it's an FP.  Can someone at Comodo have a look?

I've submitted the file for Comodo's analysis, via the Quarantine screen.

Thanks guys!



Hi   puddingpants,

We are going to have a look at it and will get back to you after investigation.

Regards,
hailong.wang
Logged
hailong.wang
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 453



« Reply #2 on: July 05, 2009, 10:09:19 PM »

Hi   puddingpants,

This FP has been fixed.Please check in virus signature database 1555.

Regards,
hailong.wang
Logged
puddingpants
Comodo Member
**
Offline Offline

Posts: 31


« Reply #3 on: July 06, 2009, 01:21:08 AM »

Fix confirmed with virus signature database 1558.

Thanks!

Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.033 seconds with 18 queries.
Powered by SMF 1.1.10 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com