Welcome, Guest. Please login or register.
March 21, 2010, 08:49:32 PM

Login with username, password and session length

373569 Posts
41451 Topics
94200 Members

Latest Member: shchen22

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  AV False Positive/Negative Detection Reporting
| | | |-+  False positive: ApplicUnsaf.Win32.HAckTool.Agent.~BACB[at]731140
« previous next »
Pages: [1] Go Down Print
Author Topic: False positive: ApplicUnsaf.Win32.HAckTool.Agent.~BACB[at]731140  (Read 2940 times)
EricJH
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 5848



« on: November 29, 2008, 09:05:53 PM »

I believe this to be a false positive. It is a key generator and that makes it a potentially dangerous program.

I have CIS installed with Proactive settings and get 340/340 score on the Comodo Leak Test program. The program runs as isolated application. When watching it step by step it only gets flagged by CIS once for starting its self.

Here is the Virus Total analysis: http://www.virustotal.com/analisis/6e4305c1a379c3af75a28fb0d6ff4613 .

I submitted it by email.
Logged

Please read: Introduction to the Sandbox

Using CIS v4 and always the latest snapshot of Opera browser.

AMD Phenom 925 quad core with 4 GB RAM on MSI 785G E53
idem
Global Moderator
Newbie
*****
Offline Offline

Posts: 17



« Reply #1 on: December 03, 2008, 08:15:57 AM »

Hello.
This is not false positive.
This is key generator for Ahead Nero products developed by one of hackers groups, main purpose of this program - break software copy protection of legitimate commercial applications - so it was properly calssified as ApplicUnsaf.Win32.HackTool.Agent.
You can use it on your own risk.
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 5848



« Reply #2 on: December 03, 2008, 11:01:11 AM »

Thank you for your reply. I can see why it can be classified as riskware or potentially unsafe given the very background of the tool.

The name suggests it to be a hacktool (Which it is not as far as my assessment goes (it even works happily as limited application)).

May be I am misunderstanding the name of the category. Is the category a broad one for riskware in general even if the program is not compromising the system's integrity?

Logged

Please read: Introduction to the Sandbox

Using CIS v4 and always the latest snapshot of Opera browser.

AMD Phenom 925 quad core with 4 GB RAM on MSI 785G E53
JNavas
Guest
« Reply #3 on: December 16, 2008, 02:04:39 PM »

Thank you for your reply. I can see why it can be classified as riskware or potentially unsafe given the very background of the tool.
The name suggests it to be a hacktool (Which it is not as far as my assessment goes (it even works happily as limited application)).
May be I am misunderstanding the name of the category. Is the category a broad one for riskware in general even if the program is not compromising the system's integrity?

I think that's the idea (hackware included in malware), and I personally think it compromises the malware mission to mix in other issues like hackware, but there you have it.

John
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.051 seconds with 17 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com