Welcome, Guest. Please login or register.
March 22, 2010, 12:53:20 AM

Login with username, password and session length

373598 Posts
41458 Topics
94207 Members

Latest Member: Toontwister

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Virus/Malware Removal Assistance
| | |-+  False/positive
« previous next »
Pages: [1] Go Down Print
Author Topic: False/positive  (Read 675 times)
Wacker
Newbie
*
Offline Offline

Posts: 11


« on: August 19, 2009, 12:10:05 PM »

Starting from stracth,  (3.10), & after updating it's now running a system scan. So far it has  found;  "TrojWare.Win32.Trojan.Agent.¬(ID =0x659b9c)  location C:\program Files\Mozilla Firefox\runner  Huh

I ran Ad-Aware the other day as well as running regular scans from AVG but it has never picked this up? Any ideas.

TIA
Logged
commanding the celsius
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 1401


^^^^


« Reply #1 on: August 19, 2009, 12:17:55 PM »

I use mozilla firexox myself and have no file/folder there called runner..

What version of Firefox do you use? Mine is 3.5.2.. Perhaps if possible you should send the file to virustotal.com and see what the other scanners thinks about it..  Thumb Up Thumb Up
Logged
Wacker
Newbie
*
Offline Offline

Posts: 11


« Reply #2 on: August 19, 2009, 12:35:58 PM »

I use mozilla firexox myself and have no file/folder there called runner..

What version of Firefox do you use? Mine is 3.5.2.. Perhaps if possible you should send the file to virustotal.com and see what the other scanners thinks about it..  Thumb Up Thumb Up

My version is also 3.5.2
It has finished scanning and reported 5 files infected. Here they are;

TrojWare.Win32.Trojan.Agent.~(ID = 0x659b9c) C:\Users\*name\AppData\Local\Temp\Temp1_Runner.zip\Runner\lt-runner.exe
TrojWare.Win32.Trojan.Agent.~(ID = 0x659b9c) C:\Users\*name\Downloads\Runner\Runner\lt-runner.exe
TrojWare.Win32.Trojan.Agent.~(ID = 0x659b9c) C:\Users\*name\Downloads\Runner.zip:Runner/lt-runner.exe
Application.Win32.LeakTest.~LT(ID = 0x90b95f) C:\Program Files\COMODO\COMODO Internet Security\Quarantine\LeakTest.exe:UPX
TrojWare.Win32.Trojan.Agent.~(ID = 0x659b9c) C:\Program Files\Mozilla Firefox\runner


what do you think? delete?? report???
Logged
commanding the celsius
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 1401


^^^^


« Reply #3 on: August 19, 2009, 02:27:57 PM »

Sorry for the slow reply..

I think you got a genuine infection.. But I might be wrong.. Quarantine would be my pick.. And if you don't notice any problems with firefox leave the files quarantined.. Thumb Up Thumb Up
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.068 seconds with 16 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com