Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
August 21, 2008, 10:48:02 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
184920
Posts
21469
Topics
52065
Members
Latest Member:
ErnieK
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo BOClean Anti-Malware
Major False Positive from latest update of Boclean
« previous
next »
Pages:
[
1
]
2
Author
Topic: Major False Positive from latest update of Boclean (Read 3138 times)
atomas31
Newbie
Offline
Posts: 15
Major False Positive from latest update of Boclean
«
on:
January 21, 2008, 01:49:32 PM »
Hi,
The latest update detect shadowprotectsvc.exe from Shadow Protect has a trojan
This is for sure a False positive so please rectifie this situation as soon as possible...
Thanks,
Atomas31
Logged
Arkangyal
"There is nothing impossible to him who will try." - Alexander The Great, ancient Greek King of Macedon, 356 BC-323 BC.
Global Moderator
Comodo's Hero
Offline
Posts: 837
[ Visit Hungary ] www.hungary.hu
Re: Major False Positive from latest update of Boclean
«
Reply #1 on:
January 21, 2008, 03:04:31 PM »
Hello atomas31,
Is this part of the software from
StorageCraft
? If this is a real false positive, please, use the Excluder (drop the file into the Excluder).
Ark
Logged
32bit XP Pro Hun SP3 NTFS, .NET 2.0, VB6SP6, Dx9c (Y08); Asrock mb., Intel 2,66GHz, Ati 1600 xt Pro 512MB, 2GB 400MHz DDR, 1280x1024[ at ]75Hz 32bit, realtek (built-in), belkin router (wi-fi). MSI Mega book, 64bit Vista Hun, 1gb ram, wifi (g)
atomas31
Newbie
Offline
Posts: 15
Re: Major False Positive from latest update of Boclean
«
Reply #2 on:
January 21, 2008, 03:17:10 PM »
Yes it is from storagecraft!
Why should I place it in the excluder when it is clearly a false positive shouldn't be to comodo staff to rectifie this false positive? For now, Boclean is shutdown...
Logged
G1111
Newbie
Offline
Posts: 2
Re: Major False Positive from latest update of Boclean
«
Reply #3 on:
January 21, 2008, 03:56:46 PM »
There is another false positive with today's update. It is reporting RegDefend/Ghost Security Suite gss.exe as a trojan and shuts it down. Just scanned it with KAV (latest) and A-squared. It is clean.
Logged
atomas31
Newbie
Offline
Posts: 15
Re: Major False Positive from latest update of Boclean
«
Reply #4 on:
January 21, 2008, 04:04:04 PM »
Well lucky for me that I don't use my Ghost Security suite in realtime anymore or else I would be very pissed off with this latest update... Just wondering what's going on at Comodo since Boclean never had so many false positive before it got buy by comodo???
Logged
mozart
Newbie
Offline
Posts: 14
Re: Major False Positive from latest update of Boclean
«
Reply #5 on:
January 21, 2008, 04:27:15 PM »
I have the same alert re GSS.exe and suspected this too as a FP.
What should I do now ?
BoCleann offers me the option to remove the file too. Obviously I don't want to do that thinking it is a FP. Does that mean that BoClean has only shut down GSS or has anything already been deleted? A second pc has a different alert saying that the trojan as system lock and cannot be shut down or something similar and I should immediately shut down my pc. Again, what should I do?
Logged
Arkangyal
"There is nothing impossible to him who will try." - Alexander The Great, ancient Greek King of Macedon, 356 BC-323 BC.
Global Moderator
Comodo's Hero
Offline
Posts: 837
[ Visit Hungary ] www.hungary.hu
Re: Major False Positive from latest update of Boclean
«
Reply #6 on:
January 21, 2008, 04:55:15 PM »
Founding new ways to track down the new threats may got som risks. Usually, the possibility to identify a normal program as a malware is very-very low but can happen. Happened with all virus vendors so far. An easy example:
- You write a program which will connect to the Internet
- The bad guy do the same and the codes are almost the same.
When you create a signature to identify the malware, there's a tiny risk that you'll only have the signature part from the part which establishes the connection: so both of the softwares will be identified.
Thank you for your understanding. I guess the staff will release new update for this problem as soon as possible, after they've investigated the corresponing file. Please, submit the files to let the staff analyze them:
You can email them to:
malwaresubmit [ at ] avlab.comodo.com
.
You may want to specify in the subject line "
False Positive?
" for clarity's sake.
As usual,
zip
and password protect with "infected" including that information in the body.
While there's no new update, please, use the excluder utility which is a great temporary fix for this problem.
Ark
«
Last Edit: January 21, 2008, 05:06:21 PM by Arkangyal
»
Logged
32bit XP Pro Hun SP3 NTFS, .NET 2.0, VB6SP6, Dx9c (Y08); Asrock mb., Intel 2,66GHz, Ati 1600 xt Pro 512MB, 2GB 400MHz DDR, 1280x1024[ at ]75Hz 32bit, realtek (built-in), belkin router (wi-fi). MSI Mega book, 64bit Vista Hun, 1gb ram, wifi (g)
Rednose
Comodo's Hero
Offline
Posts: 1252
Ganda's sleepy ( in his wildest dreams )
Re: Major False Positive from latest update of Boclean
«
Reply #7 on:
January 21, 2008, 05:13:14 PM »
Atomas31, maybe you should ask also what is going on with Kaspersky, NOD32, AntiVir enz. enz. because last year they all had false positives. If you had taken the effort to read the FAQ you would have known what to do m8
Greetz, Red.
Logged
XP 32x SP3 CFP 2.4 SSM 2.0 Free Avast! 4.8 Home CBOClean 4.27 CMF 2.0 SAS 4.15 Free MBAM 1.24
fphall
Newbie
Offline
Posts: 9
Re: Major False Positive from latest update of Boclean
«
Reply #8 on:
January 21, 2008, 06:04:20 PM »
The difference is that in the old days with Kev and Nancy it would have been fixed in about an hour. :-(
(If it ever occurred in the first place.)
Logged
atomas31
Newbie
Offline
Posts: 15
Re: Major False Positive from latest update of Boclean
«
Reply #9 on:
January 21, 2008, 08:03:16 PM »
Quote from: Rednose on January 21, 2008, 05:13:14 PM
Atomas31, maybe you should ask also what is going on with Kaspersky, NOD32, AntiVir enz. enz. because last year they all had false positives. If you had taken the effort to read the FAQ you would have known what to do m8
Greetz, Red.
Hi Rednose,
I don't know what you are talking about since I have NOD32 for more than 2 years and I don't recall any false positive last year or at least, no one that might screw my backup utilities... For your information, Boclean never had so much false positive since his acquisition by Comodo. Also, sorry for not reading the FAQ because I am little lost with all the forums and subforums... Also, I am an old user of Boclean and I was use to deal with Kevin. Like fphall said, before comodo buy Boclean the support was a lot better and certainly a lot faster.
Best regards,
Atomas31
Logged
Rednose
Comodo's Hero
Offline
Posts: 1252
Ganda's sleepy ( in his wildest dreams )
Re: Major False Positive from latest update of Boclean
«
Reply #10 on:
January 21, 2008, 08:50:38 PM »
Hi Atomas31
If you don't beleve me
Here an example were an update of NOD32 destroyed the Telebanking software of one of the biggest Dutch banks last year :
http://www.security.nl/article/16333/1/Foute_update_NOD32_sloopt_Rabobank_software_
*update*.html
I am sorry it is in Dutch, but I am sure you know how to translate it
Greetz, Red.
«
Last Edit: January 21, 2008, 09:00:00 PM by Rednose
»
Logged
XP 32x SP3 CFP 2.4 SSM 2.0 Free Avast! 4.8 Home CBOClean 4.27 CMF 2.0 SAS 4.15 Free MBAM 1.24
mozart
Newbie
Offline
Posts: 14
Re: Major False Positive from latest update of Boclean
«
Reply #11 on:
January 22, 2008, 01:19:53 AM »
Coming back to the original point about the FP - I submitted my file (GSS.exe) and just received a confirmation that this indeed was a FP now fixed in the latest update.
I can't say any re Shadowprotect though.
Logged
atomas31
Newbie
Offline
Posts: 15
Re: Major False Positive from latest update of Boclean
«
Reply #12 on:
January 22, 2008, 10:15:40 AM »
Quote from: mozart on January 22, 2008, 01:19:53 AM
Coming back to the original point about the FP - I submitted my file (GSS.exe) and just received a confirmation that this indeed was a FP now fixed in the latest update.
I can't say any re Shadowprotect though.
Hi,
I submit my file (shadowprotectsvc.exe) and like you I received a confirmation that this false positive was fix in the latest update. So, I downloaded the last update but the false positive still there except that now it is call Bkdr-Bifrose?
No congratulation there!
Man, do I miss Kevin and Nancy
Best regards,
Atomas31
Logged
atomas31
Newbie
Offline
Posts: 15
Re: Major False Positive from latest update of Boclean
«
Reply #13 on:
January 22, 2008, 10:22:26 AM »
Quote from: Rednose on January 21, 2008, 08:50:38 PM
Hi Atomas31
If you don't beleve me
Here an example were an update of NOD32 destroyed the Telebanking software of one of the biggest Dutch banks last year :
http://www.security.nl/article/16333/1/Foute_update_NOD32_sloopt_Rabobank_software_
*update*.html
I am sorry it is in Dutch, but I am sure you know how to translate it
Greetz, Red.
Hi Rednose,
Well, that's a pitty! But I was talking more about home user and not there commercial customer...
I also know (and expected) a security software to have sometimes false positive but then it depends what is targetting as a nasties and how long it takes for the compagnie to rectifie the situation. In this case, it could have screw my backup utilities (and a security software making you vulnerables to nasties). I have to add that like mention before I received a email confirmation that the F/P was rectified and it is not. Let's just say that it is kind of upsetting when you were use to an excellent support before when Boclean was still belonging to Kevin and Nancy (in less than one hour this problem will have been solved, now who knows!)...
Best regards,
Atomas31
Logged
redwolfe_98
Comodo Loves me
Offline
Posts: 179
Re: Major False Positive from latest update of Boclean
«
Reply #14 on:
January 22, 2008, 11:52:33 AM »
the "gss.exe" false-positive was fixed with the update, last nite, but it is back, now, with the latest new update, dated 2008-1-22 14:04:58 UTC.. i sent an email to comodo, notifying them about the false-positive..
i added the "gss.exe" file to BOClean's "excluder" so BOC is not flagging the file, now..
update: well, that was f-a-s-t! after i finished posting, i ran the updater again and there was a new update, dated 2008-1-22 16:37:34 UTC, which fixed the false-positive!
thanks, Comodo!
you know, maybe the reason we saw the false-positive is because comodo is on the cutting-edge with the malware-definitions..
i have a feeling that kevin mcaleavey is working on them, lately, which is a GOOD thing, if he is..
«
Last Edit: January 22, 2008, 12:10:30 PM by redwolfe_98
»
Logged
Win XP SP2, Kerio 2.15; Antivir Premium; a2 antimalware, BOClean, System Safety Monitor
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.821 seconds with 18 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com