Welcome, Guest. Please login or register.
January 04, 2010, 07:33:36 AM

Login with username, password and session length

347362 Posts
38427 Topics
87325 Members

Latest Member: luke25

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Archive Boards
| |-+  Comodo Firewall
| | |-+  Help for v3
| | | |-+  False positives in V3 Malware scanner [Merged Threads]
« previous next »
Pages: 1 [2] 3 4 Go Down Print
Author Topic: False positives in V3 Malware scanner [Merged Threads]  (Read 19985 times)
Ragwing
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3451



« Reply #15 on: February 12, 2008, 10:26:59 AM »

btw, is it OK to run 2 AVs? NOD32 & AVG Huh

It's ok, but it's not recommend. Instead, use one for real-time, and the other one as an on-demand scanner.
They might conflict with eachother.

Cheers,
Ragwing
Logged

Colon
Newbie
*
Offline Offline

Posts: 4


« Reply #16 on: February 22, 2008, 10:58:59 AM »

Hello!

During Installation Comodo Firwall Pro Version 3.0.18.309 I have been scanning my System.
Comodo showed me also 2 files:
Trojan.Win32.Patched.m(ID = 0x72d15) C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
Trojan.Win32.Patched.m(ID = 0x72d15) C:\WINDOWS\system32\winlogon.exe

But ein cannot believe that this 2 files are trojans?
To delete this files may cause a incorrect working system ist my opinion.

I uploaded this 2 files to an online Scanner. The result was " no Threat".
   
Logged
sded
Guest
« Reply #17 on: February 22, 2008, 11:04:14 AM »

There are a number of false positives reported with this initial version of the cfp3 virus scanner.  Should be upgraded as we go along.  These should just be verified with a second anti-virus tool-which you would probably do anyway.  I get two false positives also.  Wink
Logged
simmikie
Comodo Member
**
Offline Offline

Posts: 35


« Reply #18 on: February 22, 2008, 11:07:52 AM »

Hello!

During Installation Comodo Firwall Pro Version 3.0.18.309 I have been scanning my System.
Comodo showed me also 2 files:
Trojan.Win32.Patched.m(ID = 0x72d15) C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
Trojan.Win32.Patched.m(ID = 0x72d15) C:\WINDOWS\system32\winlogon.exe

But ein cannot believe that this 2 files are trojans?
To delete this files may cause a incorrect working system ist my opinion.

I uploaded this 2 files to an online Scanner. The result was " no Threat".
   

you may want to take a look at this:  http://www.techsupportforum.com/security-center/hijackthis-log-help/152865-nhfenhf-dll-removal.html or you may not.


Mike
Logged
Colon
Newbie
*
Offline Offline

Posts: 4


« Reply #19 on: February 22, 2008, 11:11:40 AM »


Thank you for your prompt reply.

Is there a chance to get the Firewall 3.0  in german language?
Logged
sded
Guest
« Reply #20 on: February 22, 2008, 11:28:35 AM »

There is a forum auf Deutsch hierin-fragen sie nach es dort.  http://forums.comodo.com/deutsch_german-b79.0/ .
Logged
Colon
Newbie
*
Offline Offline

Posts: 4


« Reply #21 on: February 22, 2008, 12:56:24 PM »

There are a number of false positives reported with this initial version of the cfp3 virus scanner.  Should be upgraded as we go along.  These should just be verified with a second anti-virus tool-which you would probably do anyway.  I get two false positives also.  Wink

Yes, its correct you are right.   It is definitiv a false positives reported.
I have checked the files with "FileAlyzer". 
MD5:    2B6A0BAF33A9918F09442D873848FF72
SHA1:  E94549181CC6CDF9F5373E86C857049B73BAEE66

Both files are "C L E A N"
Logged
Carolina Senior
Newbie
*
Offline Offline

Posts: 11


« Reply #22 on: February 23, 2008, 01:09:31 PM »

I ran the Comodo Firewall scanner last evening, and it found this one item. I did not delete it yet, as I don't know if it's a FP or something I need.

Ran Spybot and Ewido online scan, they found nothing. It was getting late so put off running SUPERAntiSpyware and HouseCall till later today. I also did a Google, and found a couple posts on the Wilders Forums, but they really didn't tell me much. What is it and should it be deleted?

Thanks.
Larry
Logged

Windows XP Home
SP2
Firefox Browser
Firewall: Comodo Firewall Pro
Anti Virus: AVG PRO
Anti Trojan: Comodo BOClean
Anti Spyware: Spyware Terminator
Anti Spyware on Demand: AVG Anti Spyware, Ad-Aware SE, Spybot S&D
Vettetech
Guest
« Reply #23 on: February 23, 2008, 02:41:48 PM »

You can see when the file was created. It sounds like a false positive to me. The Comodo scanner still has a ways to grow. I use SuperAntiSpyware and Spybot once a week only on demand. If its a file that has been in your pc for years then its safe. You can quarantine it rather then delete it.
Logged
jalobservateur
Newbie
*
Offline Offline

Posts: 1


« Reply #24 on: February 24, 2008, 04:45:06 AM »

Hi folks ! Thinking
Sorry for my english  Angry
Since 12 hours , i was surching for and alert on my comodo Pro 3 scan on my 2 cumputers.
About : Trojan Win 32.Patched.m, at Winlogon and Winlogon .exe.
I am working on computer security and i tried about everything !
Nothing told me that trojan isi true .
Absolutetly nothing goes wrong whit my 2 machcines except this indication ?
Somebody have a idea ?
Thank you
 jal Cheers
« Last Edit: February 24, 2008, 04:46:42 AM by jalobservateur » Logged
GYL
Newbie
*
Offline Offline

Posts: 3


« Reply #25 on: February 24, 2008, 05:51:01 AM »

hello,i've exactly the same problem ;i've tested with virustotal and jotti nothing.Je pense que tu es français,surtout,ne vires pas winlogon,tu ne pourras plus redemarrer,cele m"est arrivé avec une fp de dr web
Logged
GYL
Newbie
*
Offline Offline

Posts: 3


« Reply #26 on: February 24, 2008, 05:56:14 AM »

http://forums.comodo.com/help_for_v3/winlogonexe-t20095.0.html    the fp was already signified with older version and nothing has been done:not very serious Angry
« Last Edit: February 24, 2008, 05:57:47 AM by GYL » Logged
fidmas
Comodo Member
**
Offline Offline

Posts: 30


« Reply #27 on: February 24, 2008, 10:35:35 AM »

There are a load of Legacy and DOS programs on this box that are being falsely called VBS.ka.\\.A, Worm.Win9x.LJacker.4352 and Chill.544 threats by "Defense+ Common Tasks > Scan My System".  Is there any way to:

- Ignore a threat
- Get COMODO to stop making these mistakes

short of just not using this feature?

Thanks.
Logged
fidmas
Comodo Member
**
Offline Offline

Posts: 30


« Reply #28 on: February 24, 2008, 01:50:48 PM »

I hope I'm not posting twice, but I ca't find the previous post. :-/

So here it is again if anyone can help.
-----
There are a load of Legacy and DOS programs on this box that are being falsely called VBS.ka.\\.A, Worm.Win9x.LJacker.4352 and Chill.544 threats by "Defense+ Common Tasks > Scan My System".  Is there any way to:

- Ignore a threat
- Get COMODO to stop making these mistakes

short of just not using this feature?

Thanks.
Logged
sded
Guest
« Reply #29 on: February 24, 2008, 01:59:03 PM »

Probably will need to wait for the next revison of the on-demand scanner.  Unfortunately, don't know when that is scheduled.  I just got a couple of false postives, and after checking them with another anti-virus program just ignore them.  The main purpose of the scanner is to remind you to make sure that when you install CFP and tell it you have a clean PC, that you really do and haven't accumulated some virus along the way that you didn't know about.  After that, assuming you have a good antivirus program, that should take care of you as usual along with the HIPS capabilities in D+.
Logged
Tags:
Pages: 1 [2] 3 4 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.043 seconds with 18 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com