Welcome, Guest. Please login or register.
November 29, 2009, 12:31:21 PM

Login with username, password and session length

338539 Posts
37468 Topics
85027 Members

Latest Member: jroemer72

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Bug Report - CIS
| | | |-+  False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
| | | | |-+  New FP with CIS 3.10 - sm56unst.exe
« previous next »
Pages: [1] Go Down Print
Author Topic: New FP with CIS 3.10 - sm56unst.exe  (Read 279 times)
puddingpants
Comodo Member
**
Offline Offline

Posts: 41


« on: July 05, 2009, 12:05:42 AM »


Hi all.  Just upgraded from CIS 3.9.95478.509 to 3.10.102194.530, and found what is probably a false positive.  Path on my machine:

C:\drv\Modem0\sm56unst.exe

File desc: "Motorola SM56 Uninstall Utility"
File size: 258,048 bytes
File mod date: Monday, June 06, 2005, 10:40:44 PM

Detected by CIS 3.10 AV as: "TrojWare.Win32.Inject.~AA[at]25568513"
Virus Signature Database Version: 1544

CIS 3.9's AV never complained about this file, and it's apparently been there quite awhile.  I ran this file through virscan.org, and it came back clean from ALL the scanning engines, including Comodo AV 3.9 (the most recent version virscan.org has, apparently).

Given all this, I'm almost completely sure it's an FP.  Can someone at Comodo have a look?  I'm going to "quarantine" the file in the meantime, since a modem uninstall program is unlikely to be something I, or Windows, will need in the immediate future.

Thanks guys!

Logged
puddingpants
Comodo Member
**
Offline Offline

Posts: 41


« Reply #1 on: July 05, 2009, 12:10:38 AM »


More info: My copy of Windows Defender has never complained about this file, either.

Also, I've submitted the file to Comodo (using CIS' Submit feature).

Hope that helps.  Thanks.

Logged
hailong.wang
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 474



« Reply #2 on: July 05, 2009, 12:54:14 AM »

Hi all.  Just upgraded from CIS 3.9.95478.509 to 3.10.102194.530, and found what is probably a false positive.  Path on my machine:

C:\drv\Modem0\sm56unst.exe

File desc: "Motorola SM56 Uninstall Utility"
File size: 258,048 bytes
File mod date: Monday, June 06, 2005, 10:40:44 PM

Detected by CIS 3.10 AV as: "TrojWare.Win32.Inject.~AA[at]25568513"
Virus Signature Database Version: 1544

CIS 3.9's AV never complained about this file, and it's apparently been there quite awhile.  I ran this file through virscan.org, and it came back clean from ALL the scanning engines, including Comodo AV 3.9 (the most recent version virscan.org has, apparently).

Given all this, I'm almost completely sure it's an FP.  Can someone at Comodo have a look?  I'm going to "quarantine" the file in the meantime, since a modem uninstall program is unlikely to be something I, or Windows, will need in the immediate future.

Thanks guys!




Hi   puddingpants,

We are going to have a look at it and will get back to you after investigation.

Regards,
hailong.wang
Logged
hailong.wang
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 474



« Reply #3 on: July 05, 2009, 02:14:45 AM »

Hi   puddingpants,

This FP has been fixed.Please check in virus signature database 1545.

Regards,
hailong.wang
Logged
puddingpants
Comodo Member
**
Offline Offline

Posts: 41


« Reply #4 on: July 05, 2009, 12:36:06 PM »

Fix confirmed.  Thanks!

Logged
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Online Online

Posts: 8267



WWW
« Reply #5 on: July 05, 2009, 01:25:23 PM »

FP reported at 11:05:42 PM
Fix provided by 01:14:45 AM

around 2 hours and 9 minutes....

welldone guys! Keep improving the speed pls...

Melih
Logged

Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.041 seconds with 19 queries.
Powered by SMF 1.1.10 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com