Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 21, 2010, 08:10:57 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
373421
Posts
41422
Topics
94154
Members
Latest Member:
Quiksilver93
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products & Services
Comodo Internet Security - CIS
News / Announcements / Feedback - CIS
False positive. When will it stop?
« previous
next »
Pages:
[
1
]
2
3
...
6
Author
Topic: False positive. When will it stop? (Read 10371 times)
MJ.nfl
Product Translator
Comodo Loves me
Offline
Posts: 168
False positive. When will it stop?
«
on:
August 22, 2009, 03:56:27 AM »
I can't believe the number of false positives that Comodo detects.
Comodo detected maybe 2-3 viruses in my PC, but it also detected more than a 100 FP.
I uploaded one FP a month ago and it was fixed. Now a month or more later, the same FP comes back again.
So my question is, when will it stop, when will Comodo fix this problem?
Logged
dave1234
Comodo's Hero
Offline
Posts: 222
Re: False positive. When will it stop?
«
Reply #1 on:
August 22, 2009, 05:32:38 AM »
Hello. My estimation as to when will fps stop will be, never!. I say this because no matter what av you have there will always be an fp problem due to new programs and software constantly changing.. I think you mean that the number of fps have been horrendous. I will agree there and say i reckon when the data base is dramatically reduced via the intro of family sigs to say around 1.5million (if thats possible) then i think we will see a reduction . I also feel it may take until version 4 and the intro of Cima which may finally solve the problem of an extrodinary ammount of fps.
Regards
Dave1234.
Logged
smage
Comodo Family Member
Offline
Posts: 90
Re: False positive. When will it stop?
«
Reply #2 on:
August 22, 2009, 09:17:01 AM »
I hope that it will improve with v4.
«
Last Edit: August 22, 2009, 12:08:48 PM by smage
»
Logged
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 5838
Re: False positive. When will it stop?
«
Reply #3 on:
August 22, 2009, 08:31:26 PM »
Did you notch up the Heuristics setting to anything higher than Low? With settings higher than Low you will get lots of FP's. Just stick to the default Low setting.
Logged
Please read:
Introduction to the Sandbox
Using CIS v4 and always the latest snapshot of Opera browser.
AMD Phenom 925 quad core with 4 GB RAM on MSI 785G E53
umesh
Global Moderator
Comodo's Hero
Offline
Posts: 644
Re: False positive. When will it stop?
«
Reply #4 on:
August 22, 2009, 08:44:55 PM »
Hi MJ,
Quote from: MJ.nfl on August 22, 2009, 03:56:27 AM
I can't believe the number of false positives that Comodo detects.
Comodo detected maybe 2-3 viruses in my PC, but it also detected more than a 100 FP.
I uploaded one FP a month ago and it was fixed. Now a month or more later, the same FP comes back again.
So my question is, when will it stop, when will Comodo fix this problem?
If you can give details of FP you are seeing, it will help.
Thanks
-umesh
Logged
hailong.wang
Global Moderator
Comodo's Hero
Offline
Posts: 612
Re: False positive. When will it stop?
«
Reply #5 on:
August 22, 2009, 09:12:44 PM »
Quote from: MJ.nfl on August 22, 2009, 03:56:27 AM
I can't believe the number of false positives that Comodo detects.
Comodo detected maybe 2-3 viruses in my PC, but it also detected more than a 100 FP.
I uploaded one FP a month ago and it was fixed. Now a month or more later, the same FP comes back again.
So my question is, when will it stop, when will Comodo fix this problem?
Hi MJ.nfl,
Sorry for the inconvenience.
If you can find the FP file,you can submit through this link:http://internetsecurity.comodo.com/submit.php.Then we can go to have a look at it.And if it's not an FP,we will send a mail to u.
Thanks and Regards,
hailong.wang
Logged
MJ.nfl
Product Translator
Comodo Loves me
Offline
Posts: 168
Re: False positive. When will it stop?
«
Reply #6 on:
August 23, 2009, 07:48:12 AM »
[at]EricJH
It is the default Low setting.
[at]umesh
Here is a screenshot.
[at]hailong.wang
I submitted FP.
Virus total result (it doesn't show that Comodo detects it)
http://www.virustotal.com/analisis/6cbbaa2159a019fdbd8ce4a39970ddf112b2abd195fc4cf74e1cabbfa8ee8e89-1251031855
PS: Sorry for late reply. Had to go to job.
Logged
MJ.nfl
Product Translator
Comodo Loves me
Offline
Posts: 168
Re: False positive. When will it stop?
«
Reply #7 on:
August 23, 2009, 08:34:11 AM »
I got Email answer.
Reported False-Positive Can Not Be Processed: SignSIS-GUI.exe (SHA1:e2f72b48b995003085ef54935759274978d4877e)
Hi,
This is to inform you that we have scanned SignSIS-GUI.exe (SHA1:e2f72b48b995003085ef54935759274978d4877e) with latest antivirus
database version 2068 of Comodo Internet Security Version
5.10.102194.531 and have not found this file being detected.
Please check again. If the problem u found, occurs again, Please report
in comodo forum with more details that you can give about the detection
such as screenshot of the detection, etc.
Forum link:
http://forums.comodo.com/false_positivenegative_reporting_is_this_a_malware_that_cis_hasnot_detected-b154.0/
Regards,
Chandra Mohan G
Comodo Anti-Virus Lab.
PS: It is still detected
Logged
MJ.nfl
Product Translator
Comodo Loves me
Offline
Posts: 168
Re: False positive. When will it stop?
«
Reply #8 on:
August 23, 2009, 10:19:36 AM »
FP while updating Utorrent
Logged
hailong.wang
Global Moderator
Comodo's Hero
Offline
Posts: 612
Re: False positive. When will it stop?
«
Reply #9 on:
August 23, 2009, 09:47:04 PM »
Quote from: MJ.nfl on August 23, 2009, 07:48:12 AM
[at]EricJH
It is the default Low setting.
[at]umesh
Here is a screenshot.
[at]hailong.wang
I submitted FP.
Virus total result (it doesn't show that Comodo detects it)
http://www.virustotal.com/analisis/6cbbaa2159a019fdbd8ce4a39970ddf112b2abd195fc4cf74e1cabbfa8ee8e89-1251031855
PS: Sorry for late reply. Had to go to job.
Hi MJ.nfl,
We have checked the file,of which the sha is "e2f72b48b995003085ef54935759274978d4877e" in our latest DB 2075 V(3.10.102363.531) and found not detected.Pls check the version of CIS whether it's latest or not.If anything wrong,pls let us know.
Thanks and Regards,
hailong.wang
Logged
hailong.wang
Global Moderator
Comodo's Hero
Offline
Posts: 612
Re: False positive. When will it stop?
«
Reply #10 on:
August 23, 2009, 09:51:46 PM »
Quote from: MJ.nfl on August 23, 2009, 10:19:36 AM
FP while updating Utorrent
Hi MJ.nfl,
This is not an FP.As the file has two suffix,so it's detected as Heur.Dual.Extensions.If you really want to continue use this file, You can add the file to the exclusion list.
Thanks and Regards,
hailong.wang
Logged
rlshosting
Newbie
Offline
Posts: 4
Re: False positive. When will it stop?
«
Reply #11 on:
August 24, 2009, 01:19:04 AM »
I have never kept this anti-virus on my computer. My computer has detected Cool Speech Installation as a virus and winrar and flash player as a virus. I have Heuristics off. The amount of FP is nuts. Its a turn off seeing common every day programs including flash player as a virus!
Logged
MJ.nfl
Product Translator
Comodo Loves me
Offline
Posts: 168
Re: False positive. When will it stop?
«
Reply #12 on:
August 24, 2009, 05:20:15 AM »
hailong.wang, thanks for trying.
I checked again now and it is still detected.
1. CPU Athlon 64 X2 4600+
2. Windows XP pro, service pack 3, 32 bit
3. CIS 3.10.102363.531
4. Antivirus - default settings
5. Firewall - custom policy mode
6. Defense+ - clean PC mode
7. Administrator account
Virus database version 2079
Logged
Ionel
Global Moderator
Comodo's Hero
Offline
Posts: 429
Re: False positive. When will it stop?
«
Reply #13 on:
August 24, 2009, 08:35:44 AM »
Hi MJ.nfl,
The file is detected by CIS because it has two extensions. Multiple extensions is one of the procedures used by malware writers to trick the users into running the file. Heuristics implemented with CIS do warn about double extension of file and let user decide whether to continue or to remove it.
We are constantly building our list of safe files so heuristics will recognize the files which do not represent any kind of threat. Situations when files are misdetected by heuristics appear due to version change/update of programs. If a file is added to our safe list, only that specific file is considered safe, any change like replacing, updating or modifying the file in any way or using any method will not be considered safe and therefore, if some conditions are met, heuristics might be triggered until we confirm that file is ok and we add it to safe list.
You can submit any files you encounter that you believe are misdetected by CIS and we will add them to our safe list after confirming they're safe to use. This can be done by following this link
http://internetsecurity.comodo.com/submit.php
.
Thanks and regards,
Ionel
Logged
MJ.nfl
Product Translator
Comodo Loves me
Offline
Posts: 168
Re: False positive. When will it stop?
«
Reply #14 on:
August 24, 2009, 12:27:35 PM »
Hello,
This is to inform you that false-positive with SignSIS-GUI.exe (SHA1: e2f72b48b995003085ef54935759274978d4877e) has been fixed. You can update to AV database Version 2082 of Comodo Internet Security Version 3.10.102363.531 and confirm it.
Regards,
Sonia Botezatu
Comodo Antivirus Lab.
Still detected
1. CPU Athlon 64 X2 4600+
2. Windows XP pro, service pack 3, 32 bit
3. CIS 3.10.102363.531
4. Antivirus - default settings
5. Firewall - custom policy mode
6. Defense+ - clean PC mode
7. Administrator account
Virus database version 2082
Logged
Tags:
Pages:
[
1
]
2
3
...
6
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 0.061 seconds with 19 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com