Welcome, Guest. Please login or register.
March 18, 2010, 06:32:08 AM

Login with username, password and session length

372351 Posts
41267 Topics
93919 Members

Latest Member: petelomax

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  AV False Positive/Negative Detection Reporting
| | | |-+  FP Google toorbar (AGAIN!)
« previous next »
Pages: [1] Go Down Print
Author Topic: FP Google toorbar (AGAIN!)  (Read 1654 times)
patrice58
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 513


« on: November 25, 2009, 09:45:51 AM »

C:\Users\Smile\AppData\Local\Temp\Low\Google Toolbar\gtbFD44.tmp.exe Heur.Dual.Extensions thanks Smiley
Logged

Vista Home Premium 32 bit (user account) CIS 3.14.130099.587 + CAV (On Access),V-Engine 2.7.0.37, SpywareBlaster 4.2, SAS (free), a-squared(free) MBAM (free) Finjan Secure Browsing, Windows Defender (scanner only) Sandboxie 3.44, Zemana AntiLogger 1.9.2.172,
Ionel
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 422



« Reply #1 on: November 25, 2009, 10:03:50 AM »

Hi Patrice58,

C:\Users\Smile\AppData\Local\Temp\Low\Google Toolbar\gtbFD44.tmp.exe Heur.Dual.Extensions thanks Smiley

Files having two extensions are commonly used by malware creators to mislead users into executing them. For example, a file named "picture.jpg.exe" can trick user into opening it believing it's an image file format when, in fact, it's a malware executable. Giving this scenario, a heuristic approach was necessary to notify users of such files, therefore allowing them to further choose to allow the execution of such files (if he's aware of it and fully knows the implications and purpose of files) or deny the execution of files if he's not aware of the purpose of the applications.

For this particular case, if you were trying to install "Google Toolbar" application and the warning came up during this procedure, it means you can further allow the file to be executed.

In order to fix this, please submit the file as false-positive at http://internetsecurity.comodo.com/submit.php. Until a fix will be available, to avoid CIS denying access to file, you can either add it to exclusion list or lower heuristic levels.

Thanks and regards,
Ionel
« Last Edit: November 25, 2009, 10:05:40 AM by ionelp » Logged
patrice58
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 513


« Reply #2 on: November 25, 2009, 01:43:02 PM »

I tried to submit the file but it came up with some blah blah about it being a 0mb file so it did not send it, but anyhow I have upgraded CIS since the FP so I don't know if that means anything, but more to the point why can't that file be put in the whitelist?
Logged

Vista Home Premium 32 bit (user account) CIS 3.14.130099.587 + CAV (On Access),V-Engine 2.7.0.37, SpywareBlaster 4.2, SAS (free), a-squared(free) MBAM (free) Finjan Secure Browsing, Windows Defender (scanner only) Sandboxie 3.44, Zemana AntiLogger 1.9.2.172,
Ionel
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 422



« Reply #3 on: November 25, 2009, 02:29:15 PM »

Hi Patrice58,

The very reason which lead to 0kb warning on submission webpage is that CIS denies access to file unconditionally so no program/human can interact with it (neither the browser). Please add the file to exclusion list and after you'll be able to submit it.

We do add such files to white list, but there are cases when a single file have more than one variant (multiple build versions, multiple languages, etc) so we need the file itself that caused the false-positive in order to verify it and add the specific entry to white list.

Thanks and regards,
Ionel
Logged
patrice58
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 513


« Reply #4 on: November 25, 2009, 03:21:25 PM »

I can't upload the file as I am told I need permissions or whatnot so I logged in as a admin (I am typing this as a admin) and yet it still stays I needs permission to open the file. The real time scanner now sees it as a virus. Tho it's still classed as a Heur.Dual.Extensions but oddly in my last set up of CIS I had all heuristics on high, but with the new build I have not changed the heuristic setting so it is still on low.  So something is wrong somewhere.
« Last Edit: November 25, 2009, 03:35:52 PM by patrice58 » Logged

Vista Home Premium 32 bit (user account) CIS 3.14.130099.587 + CAV (On Access),V-Engine 2.7.0.37, SpywareBlaster 4.2, SAS (free), a-squared(free) MBAM (free) Finjan Secure Browsing, Windows Defender (scanner only) Sandboxie 3.44, Zemana AntiLogger 1.9.2.172,
hailong.wang
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 612



« Reply #5 on: November 25, 2009, 09:33:07 PM »

Hi Patrice58,

could you please tell me what the virus name reported by CIS ?
Logged
patrice58
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 513


« Reply #6 on: November 26, 2009, 07:56:43 AM »

Heur.Dual.Extensions
Logged

Vista Home Premium 32 bit (user account) CIS 3.14.130099.587 + CAV (On Access),V-Engine 2.7.0.37, SpywareBlaster 4.2, SAS (free), a-squared(free) MBAM (free) Finjan Secure Browsing, Windows Defender (scanner only) Sandboxie 3.44, Zemana AntiLogger 1.9.2.172,
shaogang.he
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 267



« Reply #7 on: November 26, 2009, 09:19:01 PM »

Hi Patrice58
Before upload the file,pls disable real time scanner,Defense+ ,and firewall.
if the sampls has been quarantined,pls recovey it from quarantine zone,and then upload.
Thanks
Shaogang
Logged
patrice58
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 513


« Reply #8 on: November 27, 2009, 01:03:59 PM »

So disable all my security to send you a file................... Shocked
Logged

Vista Home Premium 32 bit (user account) CIS 3.14.130099.587 + CAV (On Access),V-Engine 2.7.0.37, SpywareBlaster 4.2, SAS (free), a-squared(free) MBAM (free) Finjan Secure Browsing, Windows Defender (scanner only) Sandboxie 3.44, Zemana AntiLogger 1.9.2.172,
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.066 seconds with 19 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com