Welcome, Guest. Please login or register.
December 28, 2009, 07:11:54 AM

Login with username, password and session length

345662 Posts
38163 Topics
86700 Members

Latest Member: dannykellyjr

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Archive Boards
| |-+  Comodo Firewall
| | |-+  Help for v3
| | | |-+  Win32/AdInstaller
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: Win32/AdInstaller  (Read 3743 times)
KorruptedbyKomodo
Newbie
*
Offline Offline

Posts: 3


« on: July 19, 2008, 10:53:52 AM »

I've been using comodo since V2 on my old XP machine and I was using V3 on my newer Vista machine, The version I was using was 3.0.13.xxx and every couple of days I run the 'check for updates' function and for a few motnhs its seemed like there were no updates. I decided to visit the site and check for newer versions and have found now that its at version 3.0.25.378 which I decided to download.

I went to run the installer and of course was greeted by a message saying that Comodo firewall pro was already on my system, and did I want to uninstall it first. I uninstalled and resarted my machine and then ran the installer for the new version and was immediately Alerted by NOD32 that the firewall installer had attempted to install a variant of win32/adinstaller.

Here's the actual report from NOD32.......

"Time   Module   Object   Name   Threat   Action   User   Information
19/07/2008 16:24:09   AMON   file   C:\Users\DRUIDS~1\AppData\Local\Temp\s1.tmp   a variant of Win32/AdInstaller application   quarantined - deleted   DruidsSleep-PC\Druids Sleep   Event occurred on a new file created by the application: C:\Users\Druids Sleep\Desktop\CFP_Setup_3.0.25.378_XP_Vista_x32.exe. The file was moved to quarantine. You may close this window. "

I deleted the installer and tried downloading it again, this time using the 'DownThemAll" extension in Firefox which has the ability to check the MD5/SHA1 checksums and the file I was downloading is totally genuine but still NOD32 throws up this warning each time I try installing the newer version of the firewall.

I ran full AV and Anti-spyware scans on my machine (with NOD32 and Spyware Doctor) and my machine is clean.

Is this why Comodo is free?? the software attempts to install adware without a user's knowledge or consent??

As I said the checksums match so the file hasn't been compromised, so what's going on?? I'm now forced to use windows firewall for the moment until I can find a decent, malware free, firewall for Vista
Logged
Vettetech
Guest
« Reply #1 on: July 19, 2008, 10:57:41 AM »

Its a false positive about the new toolbar included in Comodo. Ignore it.
Logged
KorruptedbyKomodo
Newbie
*
Offline Offline

Posts: 3


« Reply #2 on: July 19, 2008, 11:04:36 AM »

Problem is I can't ignore it, NOD32 will NOT let me run the installer, it terminates the process as soon as the 'false' positive is thrown up.

Does comodo have an archive of older versions? I'd like the version I just removed back if possible, one without a toolbar.

thanks anyway
Logged
WaterWall
Guest
« Reply #3 on: July 19, 2008, 11:06:44 AM »

Disable NOD when installing Comodo  Grin And when installing make sure you won't install the toolbar  Smiley Otherwise NOD will cry again  Grin
« Last Edit: July 19, 2008, 11:08:22 AM by Commodus » Logged
KorruptedbyKomodo
Newbie
*
Offline Offline

Posts: 3


« Reply #4 on: July 19, 2008, 11:08:34 AM »

Disable NOD?  Sad not a chance!!
Logged
WaterWall
Guest
« Reply #5 on: July 19, 2008, 11:09:43 AM »

While installing ! Untick the install toolbar in Comodo and then NOD32 will be happy. Turn it on again after the installation  Wink
Logged
doktornotor
Comodo's Hero
*****
Offline Offline

Posts: 218


« Reply #6 on: July 19, 2008, 11:11:11 AM »

Problem is I can't ignore it, NOD32 will NOT let me run the installer, it terminates the process as soon as the 'false' positive is thrown up.

Right-click the NOD32 in system tray, choose Advanced Setup -> Real-time file system protection -> click the Setup button next to ThreatSense engine parameter setup -> go to Options -> uncheck Potentially unwanted applications -> OK -> OK.
Logged
gibran
Average User
Comodo's Hero
*****
Offline Offline

Posts: 5063


A bad workman always blames his tools


« Reply #7 on: July 19, 2008, 11:12:52 AM »

Is this why Comodo is free?? the software attempts to install adware without a user's knowledge or consent??

As I said the checksums match so the file hasn't been compromised, so what's going on?? I'm now forced to use windows firewall for the moment until I can find a decent, malware free, firewall for Vista

Please read Comodo Forum policy before continuing further.

As for CFP installation read Analysis of COMODO toolbar by BOClean standards

I would like to suggest to change your forum display name as well.

As for Nod32 results like Vettetech said it can be considered a false positive.

Anyway please scan other toolbar installers (google, yahoo, ms live search, alexa) and please report back Nod32 results.
« Last Edit: July 19, 2008, 11:16:10 AM by gibran » Logged

"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."- Douglas Adams
Vettetech
Guest
« Reply #8 on: July 19, 2008, 11:15:45 AM »

You are only disabling so you can install Comodo. Nothing is going to happen. As in matter of fact when you install things such as games they tell you to shut off any virus scanner. You do not have to install the toolbar. I also use NOD32.
Logged
Vettetech
Guest
« Reply #9 on: July 19, 2008, 11:19:09 AM »

Odd thing is I have NOD32 3.0.669.0 and it doesn't find Comodo toolbar to be an infecting unless you have Threat Sense set to find Potentially unsafe applications which can also lead to false positives. Uncheck that option if you have it checked off.
Logged
WaterWall
Guest
« Reply #10 on: July 19, 2008, 11:21:56 AM »

And I say leave the Potentially Unsafe apps ticked. I can save your butt. Just disable NOD while installing Comodo and do not choose to install Comodo Toolbar. After the install - turn NOD back on.  Smiley
Logged
Matty_R
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1952


Nice to see you,to see you nice!


« Reply #11 on: July 19, 2008, 11:24:20 AM »

You can get previous versions HERE if you wish.
Logged

I HAD A DREAM----But i can`t remember it......
gibran
Average User
Comodo's Hero
*****
Offline Offline

Posts: 5063


A bad workman always blames his tools


« Reply #12 on: July 19, 2008, 11:25:37 AM »

Odd thing is I have NOD32 3.0.669.0 and it doesn't find Comodo toolbar to be an infecting unless you have Threat Sense set to find Potentially unsafe applications which can also lead to false positives. Uncheck that option if you have it checked off.

Can you check if this happens with other toolbars as well, if this does not happen I guess eset will have to fix this.
Logged

"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."- Douglas Adams
doktornotor
Comodo's Hero
*****
Offline Offline

Posts: 218


« Reply #13 on: July 19, 2008, 11:30:22 AM »

And I say leave the Potentially Unsafe apps ticked. I can save your butt. Just disable NOD while installing Comodo and do not choose to install Comodo Toolbar. After the install - turn NOD back on.  Smiley

It actually detects the Ask.com toolbar and will wipe it... Already been discussed months ago. You can only re-enable it once you've uninstaled the toolbar via Add/Remove programs after you are finished w/ CPF install, so that only actually useful components will be left...

You'll get the same "trouble" with ZA Free, Spy Sweeper or whatever else that bundles this thing (even Nero 8.0) - and no, it's not a false positive, the Ask.com thing IS a potentially unwanted app.

Lessons learnt:

- Ask.com has been a horrible choice of an engine
- make a separate checkbox for the toolbar if you really insist on having it there, instead of pretending the functionality can't exist without it.
« Last Edit: July 19, 2008, 11:32:36 AM by doktornotor » Logged
Vettetech
Guest
« Reply #14 on: July 19, 2008, 11:32:58 AM »

And I say leave the Potentially Unsafe apps ticked. I can save your butt. Just disable NOD while installing Comodo and do not choose to install Comodo Toolbar. After the install - turn NOD back on.  Smiley

Not true cause its unticked by default. With it ticked it leads to more false positives. You still have plenty of great protection with it unticked. I have come across many false positives with it checked off. Thats why its unchecked by default. I should know cause I have NIOD32 on 2 pc's. Others arent using it. I know first hand.
« Last Edit: July 19, 2008, 11:34:59 AM by Vettetech » Logged
Tags:
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in -0 seconds with 18 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com