Welcome, Guest. Please login or register.
August 21, 2008, 07:17:28 AM

Login with username, password and session length

184866 Posts
21464 Topics
52056 Members

Latest Member: bibmo

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo BOClean Anti-Malware
| | |-+  BOClean flaging KMXAGENT.SYS as ROOTKIT-VANTI.R
« previous next »
Pages: [1] Go Down Print
Author Topic: BOClean flaging KMXAGENT.SYS as ROOTKIT-VANTI.R  (Read 1825 times)
Matty_R
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 898


worse things appen at sea!


« on: April 18, 2008, 01:40:00 PM »

Hello all,

Just put BOClean on me dad`s computer and it flaged KMXAGENT.SYS as the trojan ROOTKIT-VANTI.R

Found out KMXAGENT.SYS is the HIPS driver for CA security suite,done a jotti scan and checked the MD5 of the file,also its digitally signed so i`m pretty sure its a F.P.

Anyway put it in the exclusion list,just thought i`d let you know.

Regards
Matty

ps Congrats to team,thanks all.
Logged

The only ingrediant necessary for the triumph of evil is for good people to do nothing!
CCleaner - Freeware Windows Optimization
Rednose
Comodo's Hero
*****
Offline Offline

Posts: 1252


Ganda's sleepy ( in his wildest dreams )


« Reply #1 on: April 18, 2008, 01:48:46 PM »

Matty Smiley

Please email the file to: malwaresubmit [ at ] avlab.comodo.com .
Specify in the subject line "False Positive ?".
Zip and password protect it with "infected" and include that information in the body.

Thanks m8 Smiley

Greetz, Red.
Logged

XP 32x SP3  CFP 2.4  SSM 2.0 Free  Avast! 4.8 Home  CBOClean 4.27  CMF 2.0  SAS 4.15 Free  MBAM 1.24
Matty_R
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 898


worse things appen at sea!


« Reply #2 on: April 18, 2008, 02:19:28 PM »

Will do.

Cheers
Matty  Thumb Up
Logged

The only ingrediant necessary for the triumph of evil is for good people to do nothing!
CCleaner - Freeware Windows Optimization
johnpm
Newbie
*
Offline Offline

Posts: 1


« Reply #3 on: May 02, 2008, 04:27:23 PM »

Hello:

       What was the final resolution on this? I had the same experience just now. Is it a false positive? This is important to me because i DO have a rootkit I've been trying to remove without reformatting!

Thanks
John
Logged
Kevin McAleavey
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 294


Snag a nasty? NO problem! =)


« Reply #4 on: May 03, 2008, 02:23:00 AM »

Hello:

       What was the final resolution on this? I had the same experience just now. Is it a false positive? This is important to me because i DO have a rootkit I've been trying to remove without reformatting!

Thanks
John


 For anyone who's seeing this, submit a copy of the file in question to the address up above, along with a subject line of "BOClean FP?" and my lab guys will check it out. The subject line though is extremely useful to avoid confusion as the lab input for ALL COMODO products all goes to that common lab address so that everybody in each department gets a copy of it so it's most helpful for them to pick up on it being a "BOClean issue" ... our lab folks all across the house are *so* busy lately, it's likely if it IS an FP that the file was tested, nothing found, and they simply went onto the next without realizing that it might have been an FP report ... we're THAT busy here.    Sad
Logged

"I reject your reality and substitute my own." - (Adam Savage, "MYTHBUSTERS" TV show)
Rednose
Comodo's Hero
*****
Offline Offline

Posts: 1252


Ganda's sleepy ( in his wildest dreams )


« Reply #5 on: May 04, 2008, 04:57:43 PM »

Kev, am I right the adres should be now : malwaresubmit [ at ] comodo.com  Huh

So now the procedure should be :

Email the file to: malwaresubmit [ at ] comodo.com .
Specify in the subject line " BOClean False Positive ?".
Zip and password protect it with "infected" and include that information in the body.

Greetz, Red.
Logged

XP 32x SP3  CFP 2.4  SSM 2.0 Free  Avast! 4.8 Home  CBOClean 4.27  CMF 2.0  SAS 4.15 Free  MBAM 1.24
Jrb
Comodo Member
**
Offline Offline

Posts: 42


« Reply #6 on: May 04, 2008, 05:42:14 PM »

Kev, am I right the adres should be now : malwaresubmit [ at ] comodo.com  Huh

So now the procedure should be :

Email the file to: malwaresubmit [ at ] comodo.com .
Specify in the subject line " BOClean False Positive ?".
Zip and password protect it with "infected" and include that information in the body.

Greetz, Red.

Hi Red,

I'm not Kevin -grin-
But yes, you are right Smiley
Of course the final word is up to Kevin and crew !

I'll see whether I can edit my posting here to make it a little bit more clear.

Cheers, Jan.
Logged
Baskar
Global Moderator
Newbie
*****
Offline Offline

Posts: 14



« Reply #7 on: May 05, 2008, 01:01:19 AM »

It was a false positive and it was removed last month.  If anyone is still facing any problem, please let us know.

Regards,
Baskar.
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.741 seconds with 18 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com