Welcome, Guest. Please login or register.
Did you miss your activation email?
June 19, 2013, 05:15:45 AM

Login with username, password and session length

668842 Posts
71128 Topics
145742 Members

Latest Member: sravanthi

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  AV False Positive/Negative Detection Reporting
| | | |-+  update.exe
« previous next »
Pages: [1] Go Down Print
Author Topic: update.exe  (Read 4439 times)
Luc[y]
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 667



update.exe
« on: November 20, 2010, 03:09:45 AM »

flagged as unclassifiedmalware :

Removed the attachment just in case (i have a copy if anyone needs it). Matty_R

CAMAS is a bit vague on it  Roll Eyes http://camas.comodo.com/cgi-bin/submit?file=bf232753f3ddd42e151009c407a65879b37f84775884f5e87ee5edb54862f67a
« Last Edit: November 20, 2010, 06:39:06 AM by Matty_R » Logged
languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3943



Re: update.exe
« Reply #1 on: November 20, 2010, 03:12:26 AM »

I don't think it is a FP http://www.virustotal.com/file-scan/report.html?id=bf232753f3ddd42e151009c407a65879b37f84775884f5e87ee5edb54862f67a-1279914865
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
Vaishnavi
Comodo's Hero
*****
Offline Offline

Posts: 376



Re: update.exe
« Reply #2 on: November 20, 2010, 04:45:00 AM »

Hi MOVEAX,

flagged as unclassifiedmalware :


Thanks for reporting.We will check that and get back to you shortly.

Regards,
Vaishnavi.V.K
Logged
meidan
First Response Group
Comodo's Hero
*****
Offline Offline

Posts: 1208



Re: update.exe
« Reply #3 on: November 20, 2010, 12:03:38 PM »

flagged as unclassifiedmalware :

Removed the attachment just in case (i have a copy if anyone needs it). Matty_R

CAMAS is a bit vague on it  Roll Eyes http://camas.comodo.com/cgi-bin/submit?file=bf232753f3ddd42e151009c407a65879b37f84775884f5e87ee5edb54862f67a

Hi,

This is to inform you that false-positive has been fixed.
You can update to AV database Version <6785> of  Comodo Internet Security
Version<5.0.162636.1135> and confirm it.

Thanks.

Kind Regards,
Comodo AntiVirus Lab
Erik M.
Logged
languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3943



Re: update.exe
« Reply #4 on: November 20, 2010, 04:50:39 PM »

so wait you are telling me that Symantec, pc tools, prevx, bitdefender are all wrong?
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
SiberLynx
Comodo's Hero
*****
Offline Offline

Posts: 2163



Re: update.exe
« Reply #5 on: November 20, 2010, 05:48:35 PM »

so wait you are telling me that Symantec, pc tools, prevx, bitdefender are all wrong?
Hi languy99,

1st, why not ?  Wink  That's very usual story

Then, I have 253 instances of the file called update.exe on XP
147 of them belong to Microsoft updates
It's quite possible to find the same file as the file in question amongst those, if there is a bit more info about the file
(sure the file name itself doesn't matter)

Anyway, the FP was confirmed already

Cheers!
« Last Edit: November 20, 2010, 06:49:13 PM by SiberLynx » Logged

admin; XP Pro, SP3 (32bit); CIS 3.14.130099.587 (firewall only; Proactive with Defense+)- that is the only Comodo's thing I need; Emsisoft - Mamutu Behavioural Blocker or Full EAM
Win 7 x64: Comodo Firewall 3.14; Emsisoft Anti-Malware
languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3943



Re: update.exe
« Reply #6 on: November 20, 2010, 05:58:53 PM »

You can't go by names on files, only SHA keys, a file could be called many things and still be the same one over and over.
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
SiberLynx
Comodo's Hero
*****
Offline Offline

Posts: 2163



Re: update.exe
« Reply #7 on: November 20, 2010, 06:25:01 PM »

You can't go by names on files, only SHA keys, a file could be called many things and still be the same one over and over.
Who would argue?
Yes, & that's what is written in brackets
Quote from: SiberLynx
It's quite possible to find the same file as the file in question amongst those, if there is a bit more info about the file
(sure the file name itself doesn't matter)
by info I meant precisely MD5 & SHA / Software it belongs to /file location (just in case  Wink) /etc.
otherwise it is quite a job to check all 253 of them on XP (less though on Win7 ... Avira's update.exe is one of those)

Needless to say, that the initial request doesn't contain any info about the system & platform, which is important when investigating FPs.

Cheers!
« Last Edit: November 20, 2010, 06:35:42 PM by SiberLynx » Logged

admin; XP Pro, SP3 (32bit); CIS 3.14.130099.587 (firewall only; Proactive with Defense+)- that is the only Comodo's thing I need; Emsisoft - Mamutu Behavioural Blocker or Full EAM
Win 7 x64: Comodo Firewall 3.14; Emsisoft Anti-Malware
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.048 seconds with 21 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com