Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 18, 2010, 06:32:08 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
372351
Posts
41267
Topics
93919
Members
Latest Member:
petelomax
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products & Services
Comodo Internet Security - CIS
AV False Positive/Negative Detection Reporting
FP Google toorbar (AGAIN!)
« previous
next »
Pages:
[
1
]
Author
Topic: FP Google toorbar (AGAIN!) (Read 1654 times)
patrice58
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 513
FP Google toorbar (AGAIN!)
«
on:
November 25, 2009, 09:45:51 AM »
C:\Users\Smile\AppData\Local\Temp\Low\Google Toolbar\gtbFD44.tmp.exe Heur.Dual.Extensions thanks
Logged
Vista Home Premium 32 bit (user account) CIS 3.14.130099.587 + CAV (On Access),V-Engine 2.7.0.37, SpywareBlaster 4.2, SAS (free), a-squared(free) MBAM (free) Finjan Secure Browsing, Windows Defender (scanner only) Sandboxie 3.44, Zemana AntiLogger 1.9.2.172,
Ionel
Global Moderator
Comodo's Hero
Offline
Posts: 422
Re: FP Google toorbar (AGAIN!)
«
Reply #1 on:
November 25, 2009, 10:03:50 AM »
Hi Patrice58,
Quote from: patrice58 on November 25, 2009, 09:45:51 AM
C:\Users\Smile\AppData\Local\Temp\Low\Google Toolbar\gtbFD44.tmp.exe Heur.Dual.Extensions thanks
Files having two extensions are commonly used by malware creators to mislead users into executing them. For example, a file named "picture.jpg.exe" can trick user into opening it believing it's an image file format when, in fact, it's a malware executable. Giving this scenario, a heuristic approach was necessary to notify users of such files, therefore allowing them to further choose to allow the execution of such files (if he's aware of it and fully knows the implications and purpose of files) or deny the execution of files if he's not aware of the purpose of the applications.
For this particular case, if you were trying to install "Google Toolbar" application and the warning came up during this procedure, it means you can further allow the file to be executed.
In order to fix this, please submit the file as false-positive at
http://internetsecurity.comodo.com/submit.php
. Until a fix will be available, to avoid CIS denying access to file, you can either add it to exclusion list or lower heuristic levels.
Thanks and regards,
Ionel
«
Last Edit: November 25, 2009, 10:05:40 AM by ionelp
»
Logged
patrice58
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 513
Re: FP Google toorbar (AGAIN!)
«
Reply #2 on:
November 25, 2009, 01:43:02 PM »
I tried to submit the file but it came up with some blah blah about it being a 0mb file so it did not send it, but anyhow I have upgraded CIS since the FP so I don't know if that means anything, but more to the point why can't that file be put in the whitelist?
Logged
Vista Home Premium 32 bit (user account) CIS 3.14.130099.587 + CAV (On Access),V-Engine 2.7.0.37, SpywareBlaster 4.2, SAS (free), a-squared(free) MBAM (free) Finjan Secure Browsing, Windows Defender (scanner only) Sandboxie 3.44, Zemana AntiLogger 1.9.2.172,
Ionel
Global Moderator
Comodo's Hero
Offline
Posts: 422
Re: FP Google toorbar (AGAIN!)
«
Reply #3 on:
November 25, 2009, 02:29:15 PM »
Hi Patrice58,
The very reason which lead to 0kb warning on submission webpage is that CIS denies access to file unconditionally so no program/human can interact with it (neither the browser). Please add the file to exclusion list and after you'll be able to submit it.
We do add such files to white list, but there are cases when a single file have more than one variant (multiple build versions, multiple languages, etc) so we need the file itself that caused the false-positive in order to verify it and add the specific entry to white list.
Thanks and regards,
Ionel
Logged
patrice58
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 513
Re: FP Google toorbar (AGAIN!)
«
Reply #4 on:
November 25, 2009, 03:21:25 PM »
I can't upload the file as I am told I need permissions or whatnot so I logged in as a admin (I am typing this as a admin) and yet it still stays I needs permission to open the file. The real time scanner now sees it as a virus. Tho it's still classed as a Heur.Dual.Extensions but oddly in my last set up of CIS I had all heuristics on high, but with the new build I have not changed the heuristic setting so it is still on low. So something is wrong somewhere.
«
Last Edit: November 25, 2009, 03:35:52 PM by patrice58
»
Logged
Vista Home Premium 32 bit (user account) CIS 3.14.130099.587 + CAV (On Access),V-Engine 2.7.0.37, SpywareBlaster 4.2, SAS (free), a-squared(free) MBAM (free) Finjan Secure Browsing, Windows Defender (scanner only) Sandboxie 3.44, Zemana AntiLogger 1.9.2.172,
hailong.wang
Global Moderator
Comodo's Hero
Offline
Posts: 612
Re: FP Google toorbar (AGAIN!)
«
Reply #5 on:
November 25, 2009, 09:33:07 PM »
Hi Patrice58,
could you please tell me what the virus name reported by CIS ?
Logged
patrice58
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 513
Re: FP Google toorbar (AGAIN!)
«
Reply #6 on:
November 26, 2009, 07:56:43 AM »
Heur.Dual.Extensions
Logged
Vista Home Premium 32 bit (user account) CIS 3.14.130099.587 + CAV (On Access),V-Engine 2.7.0.37, SpywareBlaster 4.2, SAS (free), a-squared(free) MBAM (free) Finjan Secure Browsing, Windows Defender (scanner only) Sandboxie 3.44, Zemana AntiLogger 1.9.2.172,
shaogang.he
Global Moderator
Comodo's Hero
Offline
Posts: 267
Re: FP Google toorbar (AGAIN!)
«
Reply #7 on:
November 26, 2009, 09:19:01 PM »
Hi Patrice58
Before upload the file,pls disable real time scanner,Defense+ ,and firewall.
if the sampls has been quarantined,pls recovey it from quarantine zone,and then upload.
Thanks
Shaogang
Logged
patrice58
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 513
Re: FP Google toorbar (AGAIN!)
«
Reply #8 on:
November 27, 2009, 01:03:59 PM »
So disable all my security to send you a file...................
Logged
Vista Home Premium 32 bit (user account) CIS 3.14.130099.587 + CAV (On Access),V-Engine 2.7.0.37, SpywareBlaster 4.2, SAS (free), a-squared(free) MBAM (free) Finjan Secure Browsing, Windows Defender (scanner only) Sandboxie 3.44, Zemana AntiLogger 1.9.2.172,
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 0.066 seconds with 19 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com