Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
May 17, 2008, 02:37:25 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
155185
Posts
19179
Topics
47326
Members
Latest Member:
mazukka
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo BOClean Anti-Malware
Comodo BOClean Anti-Malware FAQ
False Positives...where to send? [Resolved]
« previous
next »
Pages:
[
1
]
Author
Topic: False Positives...where to send? [Resolved] (Read 2638 times)
Jbob
Comodo Member
Offline
Posts: 34
False Positives...where to send? [Resolved]
«
on:
May 05, 2007, 09:51:32 AM »
I've looked and I'm sure I've overlooked but where do we send the files that are being alerted on that we suspect are FPs?
«
Last Edit: May 08, 2007, 06:32:26 PM by Soya
»
Logged
mike6688
Global Moderator
Comodo's Hero
Offline
Posts: 1993
Re: False Positives...where to send?
«
Reply #1 on:
May 05, 2007, 12:03:23 PM »
[edit] sorry, misread the post, please see ~cats~ reply below. [/edit]
«
Last Edit: May 05, 2007, 03:57:10 PM by mike6688
»
Logged
C.O.M.O.D.O: CFP3 & Defence+ | CMF | VEngine | TrustConnect | CAVS 3 (soon)
XP SP3 32bit | 2.16GHz | 2GB Ram
~cat~
Global Moderator
Comodo's Hero
Offline
Posts: 964
CBO "...there is nothing better."
Re: False Positives...where to send?
«
Reply #2 on:
May 05, 2007, 01:39:29 PM »
Hi Jbob,
You can email them to:
malwaresubmit [ at ] avlab.comodo.com
.
You may want to specify in the subject line "False Positive?" for clarity's sake.
As usual, zip and password protect with "infected" including that information in the body.
Edited for new submissions address.
«
Last Edit: November 18, 2007, 01:06:12 PM by ~cat~
»
Logged
Parched dry and thirsty, knee deep in the river of life.
Jbob
Comodo Member
Offline
Posts: 34
Re: False Positives...where to send?
«
Reply #3 on:
May 05, 2007, 08:36:57 PM »
Ok thanks Cat, that's what I was looking for.
In this case the alert was on the file npad.exe in my system32 folder. The alert occured on bootup this morning. No alerts before and this file has been on my computers for a while now. This file is called by a startup command and has something to do with Notepad. If I'm not mistaken it has to do with NotePad2. This file is loaded as part of a RyanVM install of WinXP and was created by dgelwin. I trust his sources. It is part of one of the extra Cab installers that is designed to load NotePad2 during the windows install. It is called from HKCU.../run. The description shows Notepad Shortcut Replacement.
I am almost 100% this file is ok however I think it uses UPX so might be part of the issue. I sent the file to both Jotti and Virustotal. Jotti found nothing but did say UPX packers detected. Virustotal has three vendors, eSafe, Panda and Prevx1 show a result of suspicious Trojan/Worm, Suspicious file and Win32.Malware.gen. I presume that is just an alert on the UPX packer used.
The BOC alert was:(of which this is still BOC version 4.22.002)
MSNSC Malware Stopped by BOCLEAN along with the file name and the usual gui info.
What is strange about this alert is even though I told it to NOT delete the file each time I clicked on the file it alerted me again. I had thought that with BOC once you told it to not delete the file it ignored the detection until a restart?
Logged
~cat~
Global Moderator
Comodo's Hero
Offline
Posts: 964
CBO "...there is nothing better."
Re: False Positives...where to send? [Resolved]
«
Reply #4 on:
June 06, 2007, 03:42:16 PM »
Jbob,
I'm going to assume this was a FP and it was resolved..?
I'll lock it and mark as resolved unless I hear back otherwise.
Thanks!
Logged
Parched dry and thirsty, knee deep in the river of life.
Tags:
False Positives
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> General Discussion (off topic) Anything and everything...
-----------------------------
Desktop Security Products
-----------------------------
===> Help for v2
=> AntiSpam
=> Comodo Anti-Viruspyware (CAVS)
=> Backup
-----------------------------
Free Services for End Users
-----------------------------
=> Hacker Guardian
-----------------------------
Desktop Security Products
-----------------------------
=> i-Vault
=> Launch Pad
-----------------------------
Free Services for End Users
-----------------------------
=> Comodo Meet (Web Conferencing Product)
-----------------------------
Web Server Products
-----------------------------
=> Trustlogo
-----------------------------
Desktop Security Products
-----------------------------
=> Trusttoolbar
=> Verification Engine (allows you to verify what you see on the Internet)
-----------------------------
Digital Certificates
-----------------------------
=> SSL Certificate
=> Email Certificate
=> Content Verification Certificate
=> Code Signing Certificate
-----------------------------
Free Services for End Users
-----------------------------
=> Trustfax (free Trial) (online faxing)
-----------------------------
Infrastructure Products
-----------------------------
=> Trustix Enterprise Firewall
-----------------------------
Want to help Comodo?
-----------------------------
===> Help spread the word! (Please read and help)
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
-----------------------------
General Category
-----------------------------
=> Which Product do you want Comodo to develop next?
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> Italiano / Italian
===> ελληνικά / Greek
===> Turkce / Turkish
-----------------------------
Desktop Security Products
-----------------------------
===> Frequently Asked Questions (FAQ) for Comodo firewall
-----------------------------
Want to help Comodo?
-----------------------------
=> Please tell us your views and Vote here!
-----------------------------
Free Services for End Users
-----------------------------
=> User Anywhere (Remote Access product)
-----------------------------
International Comodo Forums
-----------------------------
===> Espanol / Spanish
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
-----------------------------
International Comodo Forums
-----------------------------
===> Português/Portuguese
-----------------------------
Want to help Comodo?
-----------------------------
=> How can you help Comodo? (Please we do need you!)
-----------------------------
International Comodo Forums
-----------------------------
===> Nihongo / Japanese
-----------------------------
Desktop Security Products
-----------------------------
===> FAQ for Comodo Anti-ViruSpyware
-----------------------------
Want to help Comodo?
-----------------------------
===> Comodo website issues for submitting website problems only
-----------------------------
General Category
-----------------------------
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Desktop Security Products
-----------------------------
===> Virus/Malware Removal Assistance
===> Comodo Firewall Translations
-----------------------------
International Comodo Forums
-----------------------------
===> Svenska / Swedish
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Anti Phishing solutions
=> HIPS (Host Intrusion Prevention Systems)
=> Digital Certificates, Encryption and Digital Signing
-----------------------------
International Comodo Forums
-----------------------------
===> Francais / French
===> По-русски / Russian
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Magyar / Hungarian
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
-----------------------------
International Comodo Forums
-----------------------------
===> Deutsch / German
===> Polski / Polish
===> Norsk / Norwegian
===> Українська / Ukrainian
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo BOClean Anti-Malware
===> Comodo BOClean Anti-Malware FAQ
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments (not product related)
-----------------------------
Desktop Security Products
-----------------------------
===> Help for Comodo AntiVirus
-----------------------------
International Comodo Forums
-----------------------------
===> tiếng Việt / Vietnamese
-----------------------------
Desktop Security Products
-----------------------------
===> Announcements
===> Feedback/Comments/Announcements/News about CAVS
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> FAQ for Comodo Backup
=> Comodo TrustConnect - Securing the Wireless world!
===> Help
===> Help for v3
===> Bug Reports
===> Feedback/Comments/Announcements/News
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Vulnerability Analyzer
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
Page created in 0.25 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com