Welcome, Guest. Please login or register.
January 01, 2010, 11:29:42 AM

Login with username, password and session length

346620 Posts
38320 Topics
87029 Members

Latest Member: Rezina Rittenhouse

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Archive Boards
| |-+  Comodo BOClean Anti-Malware
| | |-+  false positive??
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: false positive??  (Read 4684 times)
Toxteth O'Grady
Comodo's Hero
*****
Offline Offline

Posts: 538


« on: April 22, 2007, 08:20:07 AM »

To my surprise giFTl.exe, which is part of KCEasy, is reported to be a trojan horse. I have had this program for years. Who knows what damage it has done, if this alarm is correct. How do I know whether it is or not?
Logged
TonyKlein
Comodo Family Member
***
Offline Offline

Posts: 85



« Reply #1 on: April 22, 2007, 10:32:39 AM »

It has to be a False Positive,  I should think.  Hopefully Kevin or someone else will be around before long to comment.  Smiley
Logged

Toxteth O'Grady
Comodo's Hero
*****
Offline Offline

Posts: 538


« Reply #2 on: April 22, 2007, 10:47:37 AM »

I hope (and think) you're right about it being a false positive. I never had the impression that the programmer of KCeasy was one of the bad guys.

Anyway, lets consider this incident to be something positive. Now I have experienced myself how effective BOclean stops something (bad) from launching.    Bounce
Logged
TonyKlein
Comodo Family Member
***
Offline Offline

Posts: 85



« Reply #3 on: April 22, 2007, 10:51:58 AM »

Well,  I'm not familiar with KCeasy myself,  but I Googled around a little,  and I could not find any information to suggest that it is bad news. 

I suggest you add the KCeasy executable to BOClean's program excluder for the time being (if you haven't done so already.)
Logged

Toxteth O'Grady
Comodo's Hero
*****
Offline Offline

Posts: 538


« Reply #4 on: April 22, 2007, 11:07:23 AM »

Thanks for the suggestion. I'll do that.
Logged
dwax
Comodo Family Member
***
Offline Offline

Posts: 62



« Reply #5 on: April 22, 2007, 11:37:11 AM »

I have had BoClean for about 5 years now, and if BoClean caught something you can pretty well be sure it was a bad guy. There are not many false positives. Tongue
Logged

TonyKlein
Comodo Family Member
***
Offline Offline

Posts: 85



« Reply #6 on: April 22, 2007, 11:43:31 AM »

I have had BoClean for about 5 years now, and if BoClean caught something you can pretty well be sure it was a bad guy. There are not many false positives. Tongue

I agree,  but they do occur,  and I do believe this probably is one of those cases,  as I believe KCeasy has been around for quite some time as well.

If it were indeed malware,   I'm sure that by now there would be ample information to that effect.

... this is of course assuming you downloaded KCeasy from a reputable source,  and that the executable in question is indeed located in the Program Files\KCeasy directory ...

But let's wait for Kevin or someone else to drop by.
Logged

Toxteth O'Grady
Comodo's Hero
*****
Offline Offline

Posts: 538


« Reply #7 on: April 22, 2007, 11:58:45 AM »

Straight from the source. In fact, I just downloaded and installed it again. The same warning popped up with the new version\installation.
Logged
TonyKlein
Comodo Family Member
***
Offline Offline

Posts: 85



« Reply #8 on: April 22, 2007, 12:05:44 PM »

Thought it might;  alrighty,  let's wait for someone who'll be able to shed some light on the phenomenon.. Smiley
Logged

Kevin McAleavey
Comodo's Hero
*****
Offline Offline

Posts: 369


Snag a nasty? NO problem! =)


« Reply #9 on: April 22, 2007, 12:40:04 PM »

To my surprise giFTl.exe, which is part of KCEasy, is reported to be a trojan horse. I have had this program for years. Who knows what damage it has done, if this alarm is correct. How do I know whether it is or not?

Can you tell me what it's being reported as? That'd help in tracking down where the problem definition is. I'm no longer doing the whole nine yards myself, so need to find out what we've got and get my guys on fixing it ...
Logged

"I reject your reality and substitute my own." - (Adam Savage, "MYTHBUSTERS" TV show)
Toxteth O'Grady
Comodo's Hero
*****
Offline Offline

Posts: 538


« Reply #10 on: April 22, 2007, 01:11:09 PM »

This is the message:
------------------------------------------------------------------
Location of startup: FILE
D:\SOFTWARE\KCEASY\GIFT\GIFTL.EXE

This trojan horse program was found on your machine.
It has been shut down, but the FILE from which it
started still remains and can be started up again.

Do you want the file removed also?
-------------------------------------------------------------------------


The file from which it started would be kceasy.exe itself. At least, that is where the shortcut to the program points to.
Logged
~cat~
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 969


CBO "...there is nothing better."


« Reply #11 on: April 22, 2007, 01:20:25 PM »

It's detecting it as Safeshare.
Logged

Parched dry and thirsty, knee deep in the river of life.
TonyKlein
Comodo Family Member
***
Offline Offline

Posts: 85



« Reply #12 on: April 22, 2007, 01:23:35 PM »

Incidentally,  I just came across this forum thread in which AVG Anti-Spyware detected the same file as "Not-A-Virus.PornTool.Win32.Porn2Peer.a"

Now AVG FP or not,  could there be a relation?
 
 
Logged

Toxteth O'Grady
Comodo's Hero
*****
Offline Offline

Posts: 538


« Reply #13 on: April 22, 2007, 01:32:43 PM »

It says it's not a virus, but Porn2Peer. That's why I use this program.   Cheers   Laugh

I just checked and none of the scanners over at http://virusscan.jotti.org/ found anything. It must be safe. I hope...
« Last Edit: April 22, 2007, 01:35:21 PM by user4 » Logged
Kevin McAleavey
Comodo's Hero
*****
Offline Offline

Posts: 369


Snag a nasty? NO problem! =)


« Reply #14 on: April 22, 2007, 09:32:03 PM »

[edited]

My error ... it was reported as malware but apparently the variant you have is just "not a good idea." Based on reports from other antimalware vendors, I'll have that one removed. However the detect was not a false positive - it dates back a ways and definitely wasn't clean at the time ...
« Last Edit: April 22, 2007, 09:36:42 PM by Kevin McAleavey » Logged

"I reject your reality and substitute my own." - (Adam Savage, "MYTHBUSTERS" TV show)
Tags:
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.039 seconds with 16 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com