Welcome, Guest. Please login or register.
October 07, 2008, 01:24:18 PM

Login with username, password and session length

197862 Posts
22775 Topics
54732 Members

Latest Member: xcvii90

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo BOClean Anti-Malware
| | |-+  BOClean flaging KMXAGENT.SYS as ROOTKIT-VANTI.R
« previous next »
Pages: [1] Go Down Print
Author Topic: BOClean flaging KMXAGENT.SYS as ROOTKIT-VANTI.R  (Read 2200 times)
Matty_R
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1016


Nice to see you,to see you nice!


« on: April 18, 2008, 01:40:00 PM »

Hello all,

Just put BOClean on me dads computer and it flaged KMXAGENT.SYS as the trojan ROOTKIT-VANTI.R

Found out KMXAGENT.SYS is the HIPS driver for CA security suite,done a jotti scan and checked the MD5 of the file,also its digitally signed so im pretty sure its a F.P.

Anyway put it in the exclusion list,just thought id let you know.

Regards
Matty

ps Congrats to team,thanks all.
Logged

Apart from......what did the "ROMANS" ever do for us........!!!
CCleaner - Freeware Windows Optimization
Rednose
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 1323


Ganda's sleepy ( in his wildest dreams )


« Reply #1 on: April 18, 2008, 01:48:46 PM »

Matty Smiley

Please email the file to: malwaresubmit [ at ] avlab.comodo.com .
Specify in the subject line "False Positive ?".
Zip and password protect it with "infected" and include that information in the body.

Thanks m8 Smiley

Greetz, Red.
Logged

XP 32x SP3  CFP 2.4  SSM 2.0 Free  Avast! 4.8 Home  CBOClean 4.27  CMF 2.0  SAS 4.21 Free  MBAM 1.28
Matty_R
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1016


Nice to see you,to see you nice!


« Reply #2 on: April 18, 2008, 02:19:28 PM »

Will do.

Cheers
Matty  Thumb Up
Logged

Apart from......what did the "ROMANS" ever do for us........!!!
CCleaner - Freeware Windows Optimization
johnpm
Newbie
*
Offline Offline

Posts: 1


« Reply #3 on: May 02, 2008, 04:27:23 PM »

Hello:

       What was the final resolution on this? I had the same experience just now. Is it a false positive? This is important to me because i DO have a rootkit I've been trying to remove without reformatting!

Thanks
John
Logged
Kevin McAleavey
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 309


Snag a nasty? NO problem! =)


« Reply #4 on: May 03, 2008, 02:23:00 AM »

Hello:

       What was the final resolution on this? I had the same experience just now. Is it a false positive? This is important to me because i DO have a rootkit I've been trying to remove without reformatting!

Thanks
John


 For anyone who's seeing this, submit a copy of the file in question to the address up above, along with a subject line of "BOClean FP?" and my lab guys will check it out. The subject line though is extremely useful to avoid confusion as the lab input for ALL COMODO products all goes to that common lab address so that everybody in each department gets a copy of it so it's most helpful for them to pick up on it being a "BOClean issue" ... our lab folks all across the house are *so* busy lately, it's likely if it IS an FP that the file was tested, nothing found, and they simply went onto the next without realizing that it might have been an FP report ... we're THAT busy here.    Sad
Logged

"I reject your reality and substitute my own." - (Adam Savage, "MYTHBUSTERS" TV show)
Rednose
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 1323


Ganda's sleepy ( in his wildest dreams )


« Reply #5 on: May 04, 2008, 04:57:43 PM »

Kev, am I right the adres should be now : malwaresubmit [ at ] comodo.com  Huh

So now the procedure should be :

Email the file to: malwaresubmit [ at ] comodo.com .
Specify in the subject line " BOClean False Positive ?".
Zip and password protect it with "infected" and include that information in the body.

Greetz, Red.
Logged

XP 32x SP3  CFP 2.4  SSM 2.0 Free  Avast! 4.8 Home  CBOClean 4.27  CMF 2.0  SAS 4.21 Free  MBAM 1.28
Jrb
Guest
« Reply #6 on: May 04, 2008, 05:42:14 PM »

Kev, am I right the adres should be now : malwaresubmit [ at ] comodo.com  Huh

So now the procedure should be :

Email the file to: malwaresubmit [ at ] comodo.com .
Specify in the subject line " BOClean False Positive ?".
Zip and password protect it with "infected" and include that information in the body.

Greetz, Red.

Hi Red,

I'm not Kevin -grin-
But yes, you are right Smiley
Of course the final word is up to Kevin and crew !

I'll see whether I can edit my posting here to make it a little bit more clear.

Cheers, Jan.
Logged
Baskar
Global Moderator
Comodo Member
*****
Online Online

Posts: 42



« Reply #7 on: May 05, 2008, 01:01:19 AM »

It was a false positive and it was removed last month.  If anyone is still facing any problem, please let us know.

Regards,
Baskar.
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.546 seconds with 18 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com