Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
July 25, 2008, 12:57:37 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
177021
Posts
20930
Topics
50746
Members
Latest Member:
shell64
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo BOClean Anti-Malware
Comodo BOClean Anti-Malware FAQ
False Positives...where to send? [Resolved]
« previous
next »
Pages:
[
1
]
Author
Topic: False Positives...where to send? [Resolved] (Read 3256 times)
Jbob
Comodo Member
Offline
Posts: 37
False Positives...where to send? [Resolved]
«
on:
May 05, 2007, 09:51:32 AM »
I've looked and I'm sure I've overlooked but where do we send the files that are being alerted on that we suspect are FPs?
«
Last Edit: May 08, 2007, 06:32:26 PM by Soya
»
Logged
mike6688
Global Moderator
Comodo's Hero
Offline
Posts: 2013
Re: False Positives...where to send?
«
Reply #1 on:
May 05, 2007, 12:03:23 PM »
[edit] sorry, misread the post, please see ~cats~ reply below. [/edit]
«
Last Edit: May 05, 2007, 03:57:10 PM by mike6688
»
Logged
C.O.M.O.D.O: CFP3 & Defence+ | CMF | VEngine | TrustConnect | CAVS 3 (soon)
XP SP3 32bit | 2.16GHz | 2GB Ram
~cat~
Global Moderator
Comodo's Hero
Offline
Posts: 964
CBO "...there is nothing better."
Re: False Positives...where to send?
«
Reply #2 on:
May 05, 2007, 01:39:29 PM »
Hi Jbob,
You can email them to:
malwaresubmit [ at ] avlab.comodo.com
.
You may want to specify in the subject line "False Positive?" for clarity's sake.
As usual, zip and password protect with "infected" including that information in the body.
Edited for new submissions address.
«
Last Edit: November 18, 2007, 01:06:12 PM by ~cat~
»
Logged
Parched dry and thirsty, knee deep in the river of life.
Jbob
Comodo Member
Offline
Posts: 37
Re: False Positives...where to send?
«
Reply #3 on:
May 05, 2007, 08:36:57 PM »
Ok thanks Cat, that's what I was looking for.
In this case the alert was on the file npad.exe in my system32 folder. The alert occured on bootup this morning. No alerts before and this file has been on my computers for a while now. This file is called by a startup command and has something to do with Notepad. If I'm not mistaken it has to do with NotePad2. This file is loaded as part of a RyanVM install of WinXP and was created by dgelwin. I trust his sources. It is part of one of the extra Cab installers that is designed to load NotePad2 during the windows install. It is called from HKCU.../run. The description shows Notepad Shortcut Replacement.
I am almost 100% this file is ok however I think it uses UPX so might be part of the issue. I sent the file to both Jotti and Virustotal. Jotti found nothing but did say UPX packers detected. Virustotal has three vendors, eSafe, Panda and Prevx1 show a result of suspicious Trojan/Worm, Suspicious file and Win32.Malware.gen. I presume that is just an alert on the UPX packer used.
The BOC alert was:(of which this is still BOC version 4.22.002)
MSNSC Malware Stopped by BOCLEAN along with the file name and the usual gui info.
What is strange about this alert is even though I told it to NOT delete the file each time I clicked on the file it alerted me again. I had thought that with BOC once you told it to not delete the file it ignored the detection until a restart?
Logged
~cat~
Global Moderator
Comodo's Hero
Offline
Posts: 964
CBO "...there is nothing better."
Re: False Positives...where to send? [Resolved]
«
Reply #4 on:
June 06, 2007, 03:42:16 PM »
Jbob,
I'm going to assume this was a FP and it was resolved..?
I'll lock it and mark as resolved unless I hear back otherwise.
Thanks!
Logged
Parched dry and thirsty, knee deep in the river of life.
Tags:
False Positives
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.077 seconds with 20 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com