Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
December 23, 2009, 11:55:02 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
344635
Posts
38081
Topics
86427
Members
Latest Member:
dexxroull
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archive Boards
Comodo Firewall
Help for v3
False positives in V3 Malware scanner [Merged Threads]
« previous
next »
Pages:
1
[
2
]
3
4
Author
Topic: False positives in V3 Malware scanner [Merged Threads] (Read 19698 times)
Ragwing
Global Moderator
Comodo's Hero
Offline
Posts: 3451
Re: Should I delete this threat that appear at CFP scan?
«
Reply #15 on:
February 12, 2008, 10:26:59 AM »
Quote from: ganda on February 12, 2008, 12:04:29 AM
btw, is it OK to run 2 AVs? NOD32 & AVG
It's ok, but it's not recommend. Instead, use one for real-time, and the other one as an on-demand scanner.
They might conflict with eachother.
Cheers,
Ragwing
Logged
Forum Policy
FAQs
Colon
Newbie
Offline
Posts: 4
Questions about v3 scan results [Merged Threads]
«
Reply #16 on:
February 22, 2008, 10:58:59 AM »
Hello!
During Installation Comodo Firwall Pro Version 3.0.18.309 I have been scanning my System.
Comodo showed me also 2 files:
Trojan.Win32.Patched.m(ID = 0x72d15) C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
Trojan.Win32.Patched.m(ID = 0x72d15) C:\WINDOWS\system32\winlogon.exe
But ein cannot believe that this 2 files are trojans?
To delete this files may cause a incorrect working system ist my opinion.
I uploaded this 2 files to an online Scanner. The result was " no Threat".
Logged
sded
Guest
Re: winlogon.exe
«
Reply #17 on:
February 22, 2008, 11:04:14 AM »
There are a number of false positives reported with this initial version of the cfp3 virus scanner. Should be upgraded as we go along. These should just be verified with a second anti-virus tool-which you would probably do anyway. I get two false positives also.
Logged
simmikie
Comodo Member
Offline
Posts: 35
Re: winlogon.exe
«
Reply #18 on:
February 22, 2008, 11:07:52 AM »
Quote from: Colon on February 22, 2008, 10:58:59 AM
Hello!
During Installation Comodo Firwall Pro Version 3.0.18.309 I have been scanning my System.
Comodo showed me also 2 files:
Trojan.Win32.Patched.m(ID = 0x72d15) C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
Trojan.Win32.Patched.m(ID = 0x72d15) C:\WINDOWS\system32\winlogon.exe
But ein cannot believe that this 2 files are trojans?
To delete this files may cause a incorrect working system ist my opinion.
I uploaded this 2 files to an online Scanner. The result was " no Threat".
you may want to take a look at this:
http://www.techsupportforum.com/security-center/hijackthis-log-help/152865-nhfenhf-dll-removal.html
or you may not.
Mike
Logged
Colon
Newbie
Offline
Posts: 4
Re: winlogon.exe
«
Reply #19 on:
February 22, 2008, 11:11:40 AM »
Thank you for your prompt reply.
Is there a chance to get the Firewall 3.0 in german language?
Logged
sded
Guest
Re: winlogon.exe
«
Reply #20 on:
February 22, 2008, 11:28:35 AM »
There is a forum auf Deutsch hierin-fragen sie nach es dort.
http://forums.comodo.com/deutsch_german-b79.0/
.
Logged
Colon
Newbie
Offline
Posts: 4
Re: winlogon.exe
«
Reply #21 on:
February 22, 2008, 12:56:24 PM »
Quote from: sded on February 22, 2008, 11:04:14 AM
There are a number of false positives reported with this initial version of the cfp3 virus scanner. Should be upgraded as we go along. These should just be verified with a second anti-virus tool-which you would probably do anyway. I get two false positives also.
Yes, its correct you are right. It is definitiv a false positives reported.
I have checked the files with "FileAlyzer".
MD5: 2B6A0BAF33A9918F09442D873848FF72
SHA1: E94549181CC6CDF9F5373E86C857049B73BAEE66
Both files are "C L E A N"
Logged
Carolina Senior
Newbie
Offline
Posts: 11
MSRSTRT.EXE....Question
«
Reply #22 on:
February 23, 2008, 01:09:31 PM »
I ran the Comodo Firewall scanner last evening, and it found this one item. I did not delete it yet, as I don't know if it's a FP or something I need.
Ran Spybot and Ewido online scan, they found nothing. It was getting late so put off running SUPERAntiSpyware and HouseCall till later today. I also did a Google, and found a couple posts on the Wilders Forums, but they really didn't tell me much. What is it and should it be deleted?
Thanks.
Larry
Logged
Windows XP Home
SP2
Firefox Browser
Firewall: Comodo Firewall Pro
Anti Virus: AVG PRO
Anti Trojan: Comodo BOClean
Anti Spyware: Spyware Terminator
Anti Spyware on Demand: AVG Anti Spyware, Ad-Aware SE, Spybot S&D
Vettetech
Guest
Re: MSRSTRT.EXE....Question
«
Reply #23 on:
February 23, 2008, 02:41:48 PM »
You can see when the file was created. It sounds like a false positive to me. The Comodo scanner still has a ways to grow. I use SuperAntiSpyware and Spybot once a week only on demand. If its a file that has been in your pc for years then its safe. You can quarantine it rather then delete it.
Logged
jalobservateur
Newbie
Offline
Posts: 1
About fals or true ?
«
Reply #24 on:
February 24, 2008, 04:45:06 AM »
Hi folks !
Sorry for my english
Since 12 hours , i was surching for and alert on my comodo Pro 3 scan on my 2 cumputers.
About : Trojan Win 32.Patched.m, at Winlogon and Winlogon .exe.
I am working on computer security and i tried about everything !
Nothing told me that trojan isi true .
Absolutetly nothing goes wrong whit my 2 machcines except this indication ?
Somebody have a idea ?
Thank you
jal
«
Last Edit: February 24, 2008, 04:46:42 AM by jalobservateur
»
Logged
GYL
Newbie
Offline
Posts: 3
Re: About fals or true ?
«
Reply #25 on:
February 24, 2008, 05:51:01 AM »
hello,i've exactly the same problem ;i've tested with virustotal and jotti nothing.Je pense que tu es français,surtout,ne vires pas winlogon,tu ne pourras plus redemarrer,cele m"est arrivé avec une fp de dr web
Logged
GYL
Newbie
Offline
Posts: 3
Re: About fals or true ?
«
Reply #26 on:
February 24, 2008, 05:56:14 AM »
http://forums.comodo.com/help_for_v3/winlogonexe-t20095.0.html
the fp was already signified with older version and nothing has been done:not very serious
«
Last Edit: February 24, 2008, 05:57:47 AM by GYL
»
Logged
fidmas
Comodo Member
Offline
Posts: 30
Scan My System - False alarms
«
Reply #27 on:
February 24, 2008, 10:35:35 AM »
There are a load of Legacy and DOS programs on this box that are being falsely called VBS.ka.\\.A, Worm.Win9x.LJacker.4352 and Chill.544 threats by "Defense+ Common Tasks > Scan My System". Is there any way to:
- Ignore a threat
- Get COMODO to stop making these mistakes
short of just not using this feature?
Thanks.
Logged
fidmas
Comodo Member
Offline
Posts: 30
False positives in V3 Malware scanner [Merged Threads]
«
Reply #28 on:
February 24, 2008, 01:50:48 PM »
I hope I'm not posting twice, but I ca't find the previous post. :-/
So here it is again if anyone can help.
-----
There are a load of Legacy and DOS programs on this box that are being falsely called VBS.ka.\\.A, Worm.Win9x.LJacker.4352 and Chill.544 threats by "Defense+ Common Tasks > Scan My System". Is there any way to:
- Ignore a threat
- Get COMODO to stop making these mistakes
short of just not using this feature?
Thanks.
Logged
sded
Guest
Re: Scan My System - False alarms
«
Reply #29 on:
February 24, 2008, 01:59:03 PM »
Probably will need to wait for the next revison of the on-demand scanner. Unfortunately, don't know when that is scheduled. I just got a couple of false postives, and after checking them with another anti-virus program just ignore them. The main purpose of the scanner is to remind you to make sure that when you install CFP and tell it you have a clean PC, that you really do and haven't accumulated some virus along the way that you didn't know about. After that, assuming you have a good antivirus program, that should take care of you as usual along with the HIPS capabilities in D+.
Logged
Tags:
Pages:
1
[
2
]
3
4
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.043 seconds with 18 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com