Welcome, Guest. Please login or register.
March 18, 2010, 06:46:31 PM

Login with username, password and session length

372610 Posts
41314 Topics
93964 Members

Latest Member: noladoug

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Virus/Malware Removal Assistance
| | |-+  Heur.
« previous next »
Pages: [1] Go Down Print
Author Topic: Heur.  (Read 1081 times)
Pastore
Newbie
*
Offline Offline

Posts: 2


« on: May 24, 2009, 09:31:05 AM »

 Smiley hi!

Sorry for my english...

today Comodo finds the 2 problems attached: what shall I do?
Logged
Ragwing
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3454



« Reply #1 on: May 24, 2009, 10:49:38 AM »

Hello!

From what I can find, winmx353.exe is the installer for WinMX 3.53. Do you use it? If yes, it's nothing to worry about. If no, it might be an actual malware. MSCONFIG.EX_ is a compressed version of msconfig.exe, which is a Windows file. The folder I386 holds the files used to install, repair, modify, update and rebuild Windows. If you believe that those two files are safe, please report them as false positives. Please see this topic for how to report a false positive:
https://forums.comodo.com/false_positivenegative_reporting_is_this_a_malware_that_cis_hasnot_detected/how_to_report_false_positivessuspicious_files_how_to_submit_them-t36051.0.html
Logged

Pastore
Newbie
*
Offline Offline

Posts: 2


« Reply #2 on: May 24, 2009, 02:08:10 PM »

I don't really know if they are safe...there isn't any problem with the computer, Undecided but i don't use winmx...i don't know when I use it the last time!! years ago!

so, have I to ignor them? have I to report them as suspicious or as FP? if the second, shall I follow both the 2 ways??  ???some information (the 2 way in particular) are too technical for me...
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 5750



« Reply #3 on: May 25, 2009, 06:17:57 PM »

You should report them as FP.

The winmx FP is for a suspected packer; I am not sure if they will change that.

The other one is more than likely for a windows system file. Zip the two files and send them as described in the "How to report False Positives/Suspicious Files & How to Submit them" guide.
Logged

Please read: Introduction to the Sandbox

Using CIS v4 and always the latest snapshot of Opera browser.

AMD Phenom 925 quad core with 4 GB RAM on MSI 785G E53
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 18.315 seconds with 18 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com