Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
January 05, 2010, 11:50:47 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
348001
Posts
38490
Topics
87507
Members
Latest Member:
easthg
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archived Boards
Comodo Firewall
Bug Reports
Malwarebytes antimalware cannot remove all test files it creates in cleanpc modes(3.0.16 x32)
« previous
next »
Pages:
[
1
]
2
Author
Topic: Malwarebytes antimalware cannot remove all test files it creates in cleanpc modes(3.0.16 x32) (Read 9294 times)
lurkingatu2
Comodo Family Member
Offline
Posts: 69
Malwarebytes antimalware cannot remove all test files it creates in cleanpc modes(3.0.16 x32)
«
on:
February 10, 2008, 11:47:45 PM »
hello
ok this has been going on for the past like 3 versions of comodo v3 but i beta tested
for malwarebytes anti-malware and it's been releast and not beta no more but every time
i do a scan with it or any av,as program i use i scan offline and exit comodo before
i scan and when i scan with ewido 4(avg antispyware) or superantispy or avria antivir pe classic
it doin't leave files in my pending files list but when i scan with malwarebytes antimalware
it leaves like 191 files in my pending files and the files are not on my pc but it still finds
them some how in my pending files list here is what it finds
i'm using comodo v3.0.16.295 with defense+ in clean mode and firewall in train with safe mode
thanks
[Edit: Long list of pending files was replaced by *.txt attachment.
Please post such things as *.txt attachments.]
«
Last Edit: February 11, 2008, 01:02:45 PM by goodbrazer
»
Logged
avira antivir pe classic winpatrol counterspy v2.5 superantispyware pro sandboxie spywareblaster zonedout for ie-spyad hostman with mvp hp host file 1.30ghz amd 256 mem xp pro sp2
Thunderbear
Comodo's Hero
Offline
Posts: 219
A little sense of humour makes everything easier.
Re: Malwarebytes antimalware cannot remove all test files it creates in cleanpc modes(3.0.16 x32)
«
Reply #1 on:
February 11, 2008, 10:08:12 AM »
Hi!
You have all those files on your computer, but you can't see them because they are in hidden directories.
To see them, you have to open Explorer, go to Tools -> Map Settings -> tab Show and check 'Show hidden files' (can't remember names exactly co's my XP isn't in english, but I hope you understand), you also have some other settings there to show some other hidden files if you wish.
I've found out that some security programs leave harmless traces into 'My pending files', you can turn it off and get rid of them if you set Defense to 'Train with Safe Mode'.
Hope this will help.
Logged
Don't be afraid, I'm very nice sometimes. And also absent-minded.
CIS 3.13.-574 (full), nLited XP3 Pro 32bit swe hidden behind a router.
lurkingatu2
Comodo Family Member
Offline
Posts: 69
Re: Malwarebytes antimalware cannot remove all test files it creates in cleanpc modes(3.0.16 x32)
«
Reply #2 on:
February 11, 2008, 01:02:48 PM »
hello
will i guess i worded it wrong for here thanks
thank you snowhawk i understand that but the thing is between the two something is leaving
some of these files behind on my pc Rubber Ducky the maker of malwarebytes antimalware says this
MBAM attempts to create these files and then delete them to make sure they do not exist and are hidden (like a rootkit). Why Comodo retains this information is beyond me.
thanks
Logged
avira antivir pe classic winpatrol counterspy v2.5 superantispyware pro sandboxie spywareblaster zonedout for ie-spyad hostman with mvp hp host file 1.30ghz amd 256 mem xp pro sp2
SS26
Comodo's Hero
Offline
Posts: 1505
Re: Malwarebytes antimalware cannot remove all test files it creates in cleanpc modes(3.0.16 x32)
«
Reply #3 on:
February 11, 2008, 01:05:24 PM »
Hi, lurkingatu2
You can try train w/safe mode for Defense+ instead of clean pc mode if you don't want to deal with "my pending files".
Logged
Rafel
Product Translator
Comodo's Hero
Offline
Posts: 355
I use only the best, I use Comodo firewall
Re: Malwarebytes antimalware cannot remove all test files it creates in cleanpc modes(3.0.16 x32)
«
Reply #4 on:
February 11, 2008, 01:45:49 PM »
I don't like walware bytes, i formated my PC, installed all micrsoft updates and CFP. I installed malwarebytes antimalware, i scaned my PC and found five objects,hehehe.
MBW AM hfind FP with CPF.
Logged
gibran
Average User
Comodo's Hero
Offline
Posts: 5063
A bad workman always blames his tools
Re: Malwarebytes antimalware cannot remove all test files it creates in cleanpc modes(3.0.16 x32)
«
Reply #5 on:
February 11, 2008, 01:56:35 PM »
If someone is going to reproduce this issue with a barebone installation with only CFP and malwarebytes I'm going to move this topic to bugreporting board.
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
lurkingatu2
Comodo Family Member
Offline
Posts: 69
Re: Malwarebytes antimalware cannot remove all test files it creates in cleanpc modes(3.0.16 x32)
«
Reply #6 on:
February 11, 2008, 02:04:09 PM »
hello
thanks goodbrazer that seems to work and i will leave d+ in train with safe mode and
see how it go's i just found it odd that comodo found these things even when i exit
comodo and some how something was leaving things behind
and thanks Rafel thats your opinion but i have found f/p's with many other programs
also not just mbam thats why i doin't let nothing clean but quarantine then look them up
thanks
Logged
avira antivir pe classic winpatrol counterspy v2.5 superantispyware pro sandboxie spywareblaster zonedout for ie-spyad hostman with mvp hp host file 1.30ghz amd 256 mem xp pro sp2
gaslad
Comodo Family Member
Offline
Posts: 55
Re: Malwarebytes antimalware cannot remove all test files it creates in cleanpc modes(3.0.16 x32)
«
Reply #7 on:
February 11, 2008, 09:01:04 PM »
I can confirm that there is this conflict between CFP and MBAM.
I also beta tested MBAM, and reported this conflict in their forum. Basically, whenever I scan with MBAM, more than 100 0 byte files are placed in CFP's Pending files. Unless they are purged, a subsequent scan with MBAM detects them as FP infections.
The workaround, of course, is to purge one's Pending Files after every MBAM scan.
I don't know if the cause of this conflict resides with CFP, or with MBAM. Either way, it is a major nuisance!
Logged
gibran
Average User
Comodo's Hero
Offline
Posts: 5063
A bad workman always blames his tools
Re: Malwarebytes antimalware cannot remove all test files it creates in cleanpc modes(3.0.16 x32)
«
Reply #8 on:
February 11, 2008, 09:08:17 PM »
Quote from: gaslad on February 11, 2008, 09:01:04 PM
snip
Unless they are purged, a subsequent scan with MBAM detects them as FP infections.
snip
Infections? can you post a screenshoot for curiosity sake?
How did MBAM call them?
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
gaslad
Comodo Family Member
Offline
Posts: 55
Re: Malwarebytes antimalware cannot remove all test files it creates in cleanpc modes(3.0.16 x32)
«
Reply #9 on:
February 11, 2008, 11:54:59 PM »
Okay, here's what I just now experienced:
1) I confirm my Pending Files list in CFP is empty
2) I run MBAM, which reports no infection
3) I open my Pending Files, and find there are now 213 files listed. Most of these are files created, then deleted by MBAM, and thus no longer exist
4) I hit the Purge button, which removes all the invalid entries, but in this case 2 "valid" files remain:
5) I confirm these files exist, were created during the MBAM scan, and are 0 byte files (from the file properties).
6) I run another MBAM scan, and during its heuristic scan it finds these:
These are clearly false positive detections of the files created during the first MBAM scan.
As I understand it, MBAM creates, then deletes all these files during its scan. Subsequent scans should not pick them up.
The question is, is there some conflict between CFP and MBAM that is preventing this for some of the files? Users of MBAM who do not also use CFP are not reporting this.
«
Last Edit: February 11, 2008, 11:58:05 PM by gaslad
»
Logged
gibran
Average User
Comodo's Hero
Offline
Posts: 5063
A bad workman always blames his tools
Re: Malwarebytes antimalware cannot remove all test files it creates in cleanpc modes(3.0.16 x32)
«
Reply #10 on:
February 12, 2008, 05:01:39 AM »
From what you say it may be these file were not created by MBAM.
If those files are really 0 bytes files and not
ADS placeholders
I guess it would be enough to create two 0 bytes files with those names to see if MBAM give the same results.
It's a bit strange for a software to dynamically create many files in windows directory tree.
EDIT:
I was completely off track
A
complete explanation
can be found just below
«
Last Edit: February 13, 2008, 03:52:20 AM by gibran
»
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
Malwarebytes
Newbie
Offline
Posts: 3
Re: Malwarebytes antimalware cannot remove all test files it creates in cleanpc modes(3.0.16 x32)
«
Reply #11 on:
February 12, 2008, 10:06:59 PM »
Hello everybody, I see some familiar faces here. Perhaps I can explain a bit how these files are created.
During a scan MBAM creates those and then deletes them. If they are created successfully, nothing happens. If they can not be created, and Windows returns an error "File already exists", it is a rootkit and we flag it for removal.
This is a common method used by other anti-malware utilities. Most also do this for service keys with the same results. If a rootkit has a lock on a registry key, when the anti-malware utility calls RegCreateKeyEx and REG_CREATED_NEW_KEY is returned, the key did not previously exist.
This is just one of our many advanced methods that we use. It does appear however that there is a conflict here.
Marcin Kleczynski
Logged
gaslad
Comodo Family Member
Offline
Posts: 55
Re: Malwarebytes antimalware cannot remove all test files it creates in cleanpc modes(3.0.16 x32)
«
Reply #12 on:
February 12, 2008, 11:00:50 PM »
Thanks Marcin (author of MBAM).
I should have read this thread more carefully. When I switched D+ from
Clean PC Mode
to
Train with Safe Mode
, this conflict disappears, at least for me.
It seems that
Clean PC Mode
detects and lists in Pending Files all those files MBAM creates, and somehow prevents at least some of them from being deleted by MBAM, resulting in persistant 0 byte files, which a subsequent MBAM scan detects as false positives.
For whatever reason, this does not happen in
Train with Safe Mode
.
Logged
MiguelAngelXP
Guest
Re: Malwarebytes antimalware cannot remove all test files it creates in cleanpc modes(3.0.16 x32)
«
Reply #13 on:
February 12, 2008, 11:39:10 PM »
Hi everyone :
I had Malwarebytes (installed a few days ago), very good program, so thanks a lot Marcin. Well I had none the trouble that lurkingatu2 has.
To Lurkin : As the others forumers said and its posted in the COMODO's release note, My Pending Files will fill up
ONLY
as said GoodBrazer, so try in Train in Safe Mode
Regards
MiguelAngelXP
Logged
lurkingatu2
Comodo Family Member
Offline
Posts: 69
Re: Malwarebytes antimalware cannot remove all test files it creates in cleanpc modes(3.0.16 x32)
«
Reply #14 on:
February 13, 2008, 12:06:49 AM »
hello
and thanks to marcin and everybody
and i'm in train with safe mode now and it works so far but i did not mind
clean pc mode with the pending files ethier and i just found it odd that this was
happening so i reported it in bugs
thanks
Logged
avira antivir pe classic winpatrol counterspy v2.5 superantispyware pro sandboxie spywareblaster zonedout for ie-spyad hostman with mvp hp host file 1.30ghz amd 256 mem xp pro sp2
Tags:
CFP 3.0.17 BUG
CFP 3.0.16 BUG
CFP COMPATIBILITY ISSUE
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to Help Comodo?
-----------------------------
=> Help Spread the Word - Banners and Logos
=> How Can I Help Comodo? (Please We Need You!)
===> Help Spread the Word! (Please Read and Help)
===> Report Comodo Forum / Web Site Issues
=> Please Tell Us Your Views and Vote Here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Help - CIS
=====> AntiVirus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> AntiVirus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> AntiVirus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> AntiVirus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> Graphical User Interface (GUI) Wishlist
===> Bug Report - CIS
=====> AntiVirus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> GUI / Miscellaneous / Other Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
===> Help - CTM
===> Feedback/Comments/Announcements/News - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless World!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to You)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Other Security Products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
=> Other Firewalls
=> Host Intrusion Prevention Systems (HIPS)
=> AntiPhishing Solutions
Page created in 0.05 seconds with 18 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com