Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 19, 2010, 12:38:47 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
372698
Posts
41327
Topics
93977
Members
Latest Member:
fleetmech
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archived Boards
Discontinued Products
Comodo Firewall
Help for v3
False positives in V3 Malware scanner [Merged Threads]
« previous
next »
Pages:
1
[
2
]
3
4
Author
Topic: False positives in V3 Malware scanner [Merged Threads] (Read 21164 times)
Ragwing
Global Moderator
Comodo's Hero
Offline
Posts: 3454
Re: Should I delete this threat that appear at CFP scan?
«
Reply #15 on:
February 12, 2008, 10:26:59 AM »
Quote from: ganda on February 12, 2008, 12:04:29 AM
btw, is it OK to run 2 AVs? NOD32 & AVG
It's ok, but it's not recommend. Instead, use one for real-time, and the other one as an on-demand scanner.
They might conflict with eachother.
Cheers,
Ragwing
Logged
Forum Policy
FAQs
Colon
Newbie
Offline
Posts: 4
Questions about v3 scan results [Merged Threads]
«
Reply #16 on:
February 22, 2008, 10:58:59 AM »
Hello!
During Installation Comodo Firwall Pro Version 3.0.18.309 I have been scanning my System.
Comodo showed me also 2 files:
Trojan.Win32.Patched.m(ID = 0x72d15) C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
Trojan.Win32.Patched.m(ID = 0x72d15) C:\WINDOWS\system32\winlogon.exe
But ein cannot believe that this 2 files are trojans?
To delete this files may cause a incorrect working system ist my opinion.
I uploaded this 2 files to an online Scanner. The result was " no Threat".
Logged
sded
Guest
Re: winlogon.exe
«
Reply #17 on:
February 22, 2008, 11:04:14 AM »
There are a number of false positives reported with this initial version of the cfp3 virus scanner. Should be upgraded as we go along. These should just be verified with a second anti-virus tool-which you would probably do anyway. I get two false positives also.
Logged
simmikie
Comodo Member
Offline
Posts: 35
Re: winlogon.exe
«
Reply #18 on:
February 22, 2008, 11:07:52 AM »
Quote from: Colon on February 22, 2008, 10:58:59 AM
Hello!
During Installation Comodo Firwall Pro Version 3.0.18.309 I have been scanning my System.
Comodo showed me also 2 files:
Trojan.Win32.Patched.m(ID = 0x72d15) C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
Trojan.Win32.Patched.m(ID = 0x72d15) C:\WINDOWS\system32\winlogon.exe
But ein cannot believe that this 2 files are trojans?
To delete this files may cause a incorrect working system ist my opinion.
I uploaded this 2 files to an online Scanner. The result was " no Threat".
you may want to take a look at this:
http://www.techsupportforum.com/security-center/hijackthis-log-help/152865-nhfenhf-dll-removal.html
or you may not.
Mike
Logged
Colon
Newbie
Offline
Posts: 4
Re: winlogon.exe
«
Reply #19 on:
February 22, 2008, 11:11:40 AM »
Thank you for your prompt reply.
Is there a chance to get the Firewall 3.0 in german language?
Logged
sded
Guest
Re: winlogon.exe
«
Reply #20 on:
February 22, 2008, 11:28:35 AM »
There is a forum auf Deutsch hierin-fragen sie nach es dort.
http://forums.comodo.com/deutsch_german-b79.0/
.
Logged
Colon
Newbie
Offline
Posts: 4
Re: winlogon.exe
«
Reply #21 on:
February 22, 2008, 12:56:24 PM »
Quote from: sded on February 22, 2008, 11:04:14 AM
There are a number of false positives reported with this initial version of the cfp3 virus scanner. Should be upgraded as we go along. These should just be verified with a second anti-virus tool-which you would probably do anyway. I get two false positives also.
Yes, its correct you are right. It is definitiv a false positives reported.
I have checked the files with "FileAlyzer".
MD5: 2B6A0BAF33A9918F09442D873848FF72
SHA1: E94549181CC6CDF9F5373E86C857049B73BAEE66
Both files are "C L E A N"
Logged
Carolina Senior
Newbie
Offline
Posts: 11
MSRSTRT.EXE....Question
«
Reply #22 on:
February 23, 2008, 01:09:31 PM »
I ran the Comodo Firewall scanner last evening, and it found this one item. I did not delete it yet, as I don't know if it's a FP or something I need.
Ran Spybot and Ewido online scan, they found nothing. It was getting late so put off running SUPERAntiSpyware and HouseCall till later today. I also did a Google, and found a couple posts on the Wilders Forums, but they really didn't tell me much. What is it and should it be deleted?
Thanks.
Larry
Logged
Windows XP Home
SP2
Firefox Browser
Firewall: Comodo Firewall Pro
Anti Virus: AVG PRO
Anti Trojan: Comodo BOClean
Anti Spyware: Spyware Terminator
Anti Spyware on Demand: AVG Anti Spyware, Ad-Aware SE, Spybot S&D
Vettetech
Guest
Re: MSRSTRT.EXE....Question
«
Reply #23 on:
February 23, 2008, 02:41:48 PM »
You can see when the file was created. It sounds like a false positive to me. The Comodo scanner still has a ways to grow. I use SuperAntiSpyware and Spybot once a week only on demand. If its a file that has been in your pc for years then its safe. You can quarantine it rather then delete it.
Logged
jalobservateur
Newbie
Offline
Posts: 1
About fals or true ?
«
Reply #24 on:
February 24, 2008, 04:45:06 AM »
Hi folks !
Sorry for my english
Since 12 hours , i was surching for and alert on my comodo Pro 3 scan on my 2 cumputers.
About : Trojan Win 32.Patched.m, at Winlogon and Winlogon .exe.
I am working on computer security and i tried about everything !
Nothing told me that trojan isi true .
Absolutetly nothing goes wrong whit my 2 machcines except this indication ?
Somebody have a idea ?
Thank you
jal
«
Last Edit: February 24, 2008, 04:46:42 AM by jalobservateur
»
Logged
GYL
Newbie
Offline
Posts: 3
Re: About fals or true ?
«
Reply #25 on:
February 24, 2008, 05:51:01 AM »
hello,i've exactly the same problem ;i've tested with virustotal and jotti nothing.Je pense que tu es français,surtout,ne vires pas winlogon,tu ne pourras plus redemarrer,cele m"est arrivé avec une fp de dr web
Logged
GYL
Newbie
Offline
Posts: 3
Re: About fals or true ?
«
Reply #26 on:
February 24, 2008, 05:56:14 AM »
http://forums.comodo.com/help_for_v3/winlogonexe-t20095.0.html
the fp was already signified with older version and nothing has been done:not very serious
«
Last Edit: February 24, 2008, 05:57:47 AM by GYL
»
Logged
fidmas
Comodo Member
Offline
Posts: 30
Scan My System - False alarms
«
Reply #27 on:
February 24, 2008, 10:35:35 AM »
There are a load of Legacy and DOS programs on this box that are being falsely called VBS.ka.\\.A, Worm.Win9x.LJacker.4352 and Chill.544 threats by "Defense+ Common Tasks > Scan My System". Is there any way to:
- Ignore a threat
- Get COMODO to stop making these mistakes
short of just not using this feature?
Thanks.
Logged
fidmas
Comodo Member
Offline
Posts: 30
False positives in V3 Malware scanner [Merged Threads]
«
Reply #28 on:
February 24, 2008, 01:50:48 PM »
I hope I'm not posting twice, but I ca't find the previous post. :-/
So here it is again if anyone can help.
-----
There are a load of Legacy and DOS programs on this box that are being falsely called VBS.ka.\\.A, Worm.Win9x.LJacker.4352 and Chill.544 threats by "Defense+ Common Tasks > Scan My System". Is there any way to:
- Ignore a threat
- Get COMODO to stop making these mistakes
short of just not using this feature?
Thanks.
Logged
sded
Guest
Re: Scan My System - False alarms
«
Reply #29 on:
February 24, 2008, 01:59:03 PM »
Probably will need to wait for the next revison of the on-demand scanner. Unfortunately, don't know when that is scheduled. I just got a couple of false postives, and after checking them with another anti-virus program just ignore them. The main purpose of the scanner is to remind you to make sure that when you install CFP and tell it you have a clean PC, that you really do and haven't accumulated some virus along the way that you didn't know about. After that, assuming you have a good antivirus program, that should take care of you as usual along with the HIPS capabilities in D+.
Logged
Tags:
Pages:
1
[
2
]
3
4
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 0.053 seconds with 21 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com