Author Topic: Virus Name: Heur.suspicious[at]19401400  (Read 98660 times)

Offline bbsv

  • Newbie
  • *
  • Posts: 3
Virus Name: Heur.suspicious[at]19401400
« on: June 19, 2009, 09:40:00 AM »
Does anyone know what the following virus is, please?

Virus Name: Heur.suspicious[at]19401400

The free Comodo anti-virus/firewall recognizes this as a virus when installing the readplease2003 free version.

Cheers,
bbsv
« Last Edit: June 19, 2009, 09:41:36 AM by bbsv »

Offline Ionel

  • Comodo Staff
  • Comodo's Hero
  • *****
  • Posts: 790
Re: Virus Name: Heur.suspicious[at]19401400
« Reply #1 on: June 19, 2009, 10:21:53 AM »
Hi,

We will check if what you reported is malware or just false positive.

Thanks,
Ionel

Offline Ionel

  • Comodo Staff
  • Comodo's Hero
  • *****
  • Posts: 790
Re: Virus Name: Heur.suspicious[at]19401400
« Reply #2 on: June 19, 2009, 12:39:55 PM »
Hi,

The false positive was fixed with DB 1373.

Thanks,
Ionel

Offline bbsv

  • Newbie
  • *
  • Posts: 3
Re: Virus Name: Heur.suspicious[at]19401400 / NOW: 24212208
« Reply #3 on: June 20, 2009, 12:14:37 AM »
Thanks Ionel for fixing "Virus Name: Heur.Suspicious[at]19401400".

I successfully installed the free version of readplease2003.

However, after I had finished the installation I received a new virus warning:

Virus Name: Heur.Suspicious[at]24212208

This time however, I ignored it and sent it to an exclusion folder or something.

Perhaps you may want to deal with this one too, Ionel.

Cheers,
bbsv
« Last Edit: June 20, 2009, 12:16:50 AM by bbsv »

Offline Vaishnavi

  • Comodo's Hero
  • *****
  • Posts: 376
Re: Virus Name: Heur.suspicious[at]19401400 / NOW: 24212208
« Reply #4 on: June 20, 2009, 01:37:51 AM »
Hi bbsv,

Thanks Ionel for fixing "Virus Name: Heur.Suspicious[at]19401400".

I successfully installed the free version of readplease2003.

However, after I had finished the installation I received a new virus warning:

Virus Name: Heur.Suspicious[at]24212208

This time however, I ignored it and sent it to an exclusion folder or something.

Perhaps you may want to deal with this one too, Ionel.

Cheers,
bbsv

Thanks for reporting.We will get back to you after analysis.

Regards,
Vaishnavi.V.K

Offline Vaishnavi

  • Comodo's Hero
  • *****
  • Posts: 376
Virus Name: Heur.Suspicious[at]24212208
« Reply #5 on: June 20, 2009, 06:38:25 AM »
Hi bbsv,

Reported FP has been fixed in DB1378.Please update and confirm.

Regards,

Vaishnavi.V.K

Offline bbsv

  • Newbie
  • *
  • Posts: 3
Re: Virus Name: Heur.Suspicious[at]24212208
« Reply #6 on: June 20, 2009, 09:59:25 PM »
Hi bbsv,

Reported FP has been fixed in DB1378.Please update and confirm.

Regards,

Vaishnavi.V.K

Updated. I will let you know if I receive anymore of these "Heur.Suspicious[at]..." warnings.

Offline oldie

  • Newbie
  • *
  • Posts: 1
Re: Virus Name: Heur.suspicious[at]19401400
« Reply #7 on: July 12, 2009, 02:40:15 PM »
Does this mean we should just ignore "heur.suspicious [at] any number?

Offline OmeletGuy

  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 2902
  • Dragon Theme Maker
Re: Virus Name: Heur.suspicious[at]19401400
« Reply #8 on: July 12, 2009, 03:32:20 PM »
Does this mean we should just ignore "heur.suspicious [at] any number?

No dont ignore Heur.Suspicious detections, its catching way more Malware then its making FP's. :)
Comodo Dragon themes, including windows Aero options. Download  Here

System Details: W7-64bit | 4GB DDR2 | Intel Core 2 Extreme X6800 | CIS 6.3 | Geforce 560 GTX

Offline youngy

  • Newbie
  • *
  • Posts: 5
Re: Virus Name: Heur.suspicious[at]19401400
« Reply #9 on: July 13, 2009, 05:01:19 AM »
hi i have installed internet explorer 8 tday and was directed to windows update page as google toolbar was not compatible with ie8. when i downloaded google tb 6 via the link i got error virus heur.suspicious[at]25726623

is this a false positive? or do i have a problem?
i use free comodo internet security.
thanks

Offline gmohan

  • Comodo's Hero
  • *****
  • Posts: 368
Re: Virus Name: Heur.suspicious[at]19401400
« Reply #10 on: July 13, 2009, 05:34:10 AM »
Hi youngy ,
hi i have installed internet explorer 8 tday and was directed to windows update page as google toolbar was not compatible with ie8. when i downloaded google tb 6 via the link i got error virus heur.suspicious[at]25726623

is this a false positive? or do i have a problem?
i use free comodo internet security.
thanks

The mentioned detection is false positive and it will be fixed.
Thanks for reporting

-Chandra Mohan

Offline gmohan

  • Comodo's Hero
  • *****
  • Posts: 368
Re: Virus Name: Heur.suspicious[at]19401400
« Reply #11 on: July 13, 2009, 08:01:34 AM »
Hi youngy ,
hi i have installed internet explorer 8 tday and was directed to windows update page as google toolbar was not compatible with ie8. when i downloaded google tb 6 via the link i got error virus heur.suspicious[at]25726623

is this a false positive? or do i have a problem?
i use free comodo internet security.
thanks

Reported FP has been fixed in DB 1635.

-Chandra Mohan

Offline youngy

  • Newbie
  • *
  • Posts: 5
Re: Virus Name: Heur.suspicious[at]19401400
« Reply #12 on: July 14, 2009, 02:35:43 AM »
thanks for that.  :)

Offline wtdb

  • Newbie
  • *
  • Posts: 1
Re: Virus Name: Heur.suspicious[at]19401400
« Reply #13 on: July 19, 2009, 03:24:31 AM »
I got ntbackup.exe detected as HS [at] 22457478 located in %systemroot%\system32\ntbackup.exe

Windows 2003. Is that a FP?

Offline gmohan

  • Comodo's Hero
  • *****
  • Posts: 368
Re: Virus Name: Heur.suspicious[at]19401400
« Reply #14 on: July 19, 2009, 04:09:40 AM »
Hi wtdb,

I got ntbackup.exe detected as HS [at] 22457478 located in %systemroot%\system32\ntbackup.exe

Windows 2003. Is that a FP?

The reported FP is being verified.

-Chandra Mohan

 

Seo4Smf 2.0 © SmfMod.Com | Smf Destek