Welcome, Guest. Please login or register.
November 18, 2008, 06:20:32 PM

Login with username, password and session length

212228 Posts
24530 Topics
57713 Members

Latest Member: desertrat2143

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Virus/Malware Removal Assistance
| | | |-+  results from bit defender online scan??
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: results from bit defender online scan??  (Read 4707 times)
soulman
Comodo Member
**
Offline Offline

Posts: 25



« on: October 27, 2007, 02:02:44 PM »


Hello to you.

Please could someone tell me any info on these results from bit defender


C:\Documents and Settings\shaun wade\Local Settings\Application Data\Comodo\Comodo Firewall\Temp\CPF5.tmp=>(gzip)=>(Embedded EXE g)
   

Infected with: Trojan.Peed.Gen

C:\Documents and Settings\shaun wade\Local Settings\Application Data\Comodo\Comodo Firewall\Temp\CPF5.tmp=>(gzip)=>(Embedded EXE g)
   

Disinfection failed

C:\Documents and Settings\shaun wade\Local Settings\Application Data\Comodo\Comodo Firewall\Temp\CPF5.tmp=>(gzip)=>(Embedded EXE g)
   

Deleted

C:\Documents and Settings\shaun wade\Local Settings\Application Data\Comodo\Comodo Firewall\Temp\CPF5.tmp=>(gzip)

MANY THANKS.
Logged
Ragwing
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3199


« Reply #1 on: October 27, 2007, 02:19:21 PM »

Greetings,

It's most likely a false positive. I can't find that file in the same directory tho, mine's empty, but I use CPF 3 and not CPF 2.4.
Too bad you deleted it, else you could've uploaded it on VrusTotal and see if it was a false positive or some virus hiding in the Comodo folder.


Ragwing
Logged

Forum Policy
FAQ's

If you should need help or have a question, feel free to PM me.
soulman
Comodo Member
**
Offline Offline

Posts: 25



« Reply #2 on: October 28, 2007, 12:40:47 AM »

Good morning to you, and thanks for your help Ragwing.

I have just checked and the CPF5.tmp file is still there? Do you think its worth sending to virus total.

MANY thanks,

Soulman.
Logged
aladinonl
Comodo's Hero
*****
Offline Offline

Posts: 331



« Reply #3 on: October 28, 2007, 03:41:54 AM »

sure u should send it to virus total!
and post da result.
If only Bitdefender reports it as mal-ware, its sure a false positive and we need to inform BD abt dis.
Logged

small minds discuss people, normal minds discuss events, great minds discuss ideas
andyman35
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 734


« Reply #4 on: October 30, 2007, 01:09:15 PM »

Having Googled it,that does appear to be genuine malware,rather than a false positive,since it's listed by a few vendors. It appears to be a nasty malware that's able to resurrect itself if it isn't completely removed.
My suggestion would be to install Bitdefender AV free edition,which is an on demand scanner and won't interfere with your existing AV.It also happens to be an excellent product and is great for a second opinion on suspect files.

http://www.bitdefender.com/PRODUCT-14-en--BitDefender-8-Free-Edition.html
« Last Edit: October 30, 2007, 01:17:52 PM by andyman35 » Logged
Info-Sec
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 587



« Reply #5 on: October 30, 2007, 01:45:23 PM »

COMODO firewall is not a piece of malware.

So there is several possibilities.

1) False posititve
2) A virus infected a file in the CPF directory
Logged

*Vista *CFP V3 *Avira * Avast *Spyware Doctor
*XP *Zone Alarm PRO *NOD32 V2.7 *Spysweeper
andyman35
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 734


« Reply #6 on: October 30, 2007, 09:32:25 PM »

I wasn't suggesting for a minute that Comodo Firewall is malware!

The location of the suspect file,a Temp folder,would appear to correspond with it being a drive by download malware rather than an authorised download.The information is that it exploits security flaws in IE or MSN messenger etc. in order to infect a system.

Having infected a system it acts as  a mass mailer on a botnet,this communication will be logged by Comodo firewall.

It might be a false positive,but since it's listed by multiple vendors,under various names, it is probably a genuine malware.

http://www.iss.net/threats/W32.Worm.Nuwar.Gen.html
« Last Edit: October 30, 2007, 09:44:54 PM by andyman35 » Logged
N.T.T.W.
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1124


A minute of your time can help many.


« Reply #7 on: October 31, 2007, 03:10:32 AM »

I suspect it is a false positive, I have a file with the same name (CPF5.tmp) in that folder and have scanned it with multiple online scanners (including VirusTotal) and all came back negative. Bit defender has been reported in some reviews as giving a lot of false positives.

 Smiler
Logged

Post proelia praemia.
Die dulci fruere.
andyman35
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 734


« Reply #8 on: October 31, 2007, 10:05:32 AM »

It isn't just reported by Bitdefender though,it appears under various names with products such as NOD32 and Kaspersky and others.

Perhaps someone could find out off Melih what exactly CPF5.tmp is,then we'd know better.Is it some form of repository for downloaded files perhaps? It isn't the CPF5.tmp itself that's the malware since it is obviously generated by Comodo Firewall,it is the content within it that's suspect.
« Last Edit: October 31, 2007, 10:19:28 AM by andyman35 » Logged
N.T.T.W.
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1124


A minute of your time can help many.


« Reply #9 on: October 31, 2007, 11:09:07 AM »

It isn't just reported by Bitdefender though,it appears under various names with products such as NOD32 and Kaspersky and others.

It isn't the CPF5.tmp itself that's the malware since it is obviously generated by Comodo Firewall,it is the content within it that's suspect.

As you have said  "Trojan.Peed.Gen" is reported by these other products, not CPF5.tmp.

I have looked at two computers with CFP on them, one just has a file called "CPF8D.tmp" and the other has the same file plus CPF5.tmp, CPF11.tmp and CPF14.tmp. I have scanned all of these files on virustotal and all came back negative.  Perhaps yours is infected but I think it more likely a false positive - perhaps you could submit the file to Bitdefender for them to check.
I am sure someone from Comodo will tell us what the temp files are for but I suspect they are pretty busy with various Betas so response may not be immediate. I will ask and see if someone will post some comments about these files.

 Smiler 
« Last Edit: October 31, 2007, 11:10:40 AM by N.T.T.W. » Logged

Post proelia praemia.
Die dulci fruere.
andyman35
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 734


« Reply #10 on: October 31, 2007, 11:40:34 AM »

As you have said  "Trojan.Peed.Gen" is reported by these other products, not CPF5.tmp.

I have looked at two computers with CFP on them, one just has a file called "CPF8D.tmp" and the other has the same file plus CPF5.tmp, CPF11.tmp and CPF14.tmp. I have scanned all of these files on virustotal and all came back negative.  Perhaps yours is infected but I think it more likely a false positive - perhaps you could submit the file to Bitdefender for them to check.
I am sure someone from Comodo will tell us what the temp files are for but I suspect they are pretty busy with various Betas so response may not be immediate. I will ask and see if someone will post some comments about these files.

 Smiler 

I don't have any of those files on my system but that's probably due to the fact that I use Returnil.I hope this does turn out to be a false alarm for the sake of Soulman,but from what I can work out this trojan could be related to the Storm malware.I can't think of what these temp files might be used for unless it's as some sort of  'holding area' before analysis.Of course this may mean that any malware has been isolated by Comodo,which has anti-trojan protocols built in,hopefully this is the case.Plus it would explain why the file couldn't be removed by Bitdefender if it's been quarantined.

Rumour has it that Melih works 23 hours a day so hopefully he can spare a minute or two  Smiler
« Last Edit: October 31, 2007, 11:56:26 AM by andyman35 » Logged
aladinonl
Comodo's Hero
*****
Offline Offline

Posts: 331



« Reply #11 on: October 31, 2007, 01:26:31 PM »

I have scanned all of these files on virustotal and all came back negative.
within da same area w same scanners, NTTW scan for nothing but andy found nasty then surely andy's comp is infected: not a false positiv.

But
I don't have any of those files on my system but that's probably due to the fact that I use Returnil.
u use returnil so everytime u reboot da file is reinfected by dat nasty (unless u disabled returnil wen BD quarantined it) but no suspicious activity is reported. so i guess dat botnet is not so activ.

i suggest u disconnect internet, disable returnil,quarantine da botnet and activate returnil again.
Logged

small minds discuss people, normal minds discuss events, great minds discuss ideas
andyman35
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 734


« Reply #12 on: October 31, 2007, 01:45:15 PM »

within da same area w same scanners, NTTW scan for nothing but andy found nasty then surely andy's comp is infected: not a false positiv.

Butu use returnil so everytime u reboot da file is reinfected by dat nasty (unless u disabled returnil wen BD quarantined it) but no suspicious activity is reported. so i guess dat botnet is not so activ.

i suggest u disconnect internet, disable returnil,quarantine da botnet and activate returnil again.


Sorry there has been some confusion it isn't my system that's infected with that file,it is Soulman,thanks anyway  Cheers

Good point on Returnil though,it should only ever be run on a clean system since any 'real' malware 'removed' from within the cloned system would reappear on reboot if protection was enabled.
Logged
soulman
Comodo Member
**
Offline Offline

Posts: 25



« Reply #13 on: November 06, 2007, 01:20:15 AM »

Sorry i have not replied, i have had no email to say someone has got back to me?

When i try to send the file to virus total all i get is this :-
0 bytes size received / Se ha recibido un archivo vacio

Am i doing something wrong? This is the path to the file that i am trying to send :-
C:\Documents and Settings\shaun wade\Local Settings\Application Data\Comodo\Comodo Firewall\Temp\CPF5.tmp=>(gzip)=>(Embedded EXE g)

I have just scanned again using the bitdefender online scan and here are the results:-

BitDefender Online Scanner
   

 
   

 

Scan report generated at: Tue, Nov 06, 2007 - 02:58:30

 
   

 
   

 

Scan path: C:\Grin:\;F:\;G:\;H:\;
   

 
   

 

 
   

 
   

 

Statistics

Time
   

01:22:03

Files
   

343405

Folders
   

8331

Boot Sectors
   

3

Archives
   

9236

Packed Files
   

18382
   

 
   

 

Results

Identified Viruses
   

1

Infected Files
   

1

Suspect Files
   

0

Warnings
   

0

Disinfected
   

0

Deleted Files
   

1
   

 
   

 

Engines Info

Virus Definitions
   

860306

Engine build
   

AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

Scan plugins
   

14

Archive plugins
   

38

Unpack plugins
   

7

E-mail plugins
   

6

System plugins
   

1
   

 
   

 

Scan Settings

First Action
   

Disinfect

Second Action
   

Delete

Heuristics
   

Yes

Enable Warnings
   

Yes

Scanned Extensions
   

*;

Exclude Extensions
   

 

Scan Emails
   

Yes

Scan Archives
   

Yes

Scan Packed
   

Yes

Scan Files
   

Yes

Scan Boot
   

Yes
   

 
   

 
 

Scanned File
   

 Status

C:\Documents and Settings\shaun wade\Local Settings\Application Data\Comodo\Comodo Firewall\Temp\CPF5.tmp=>(gzip)=>(Embedded EXE g)
   

Infected with: Trojan.Peed.Gen

C:\Documents and Settings\shaun wade\Local Settings\Application Data\Comodo\Comodo Firewall\Temp\CPF5.tmp=>(gzip)=>(Embedded EXE g)
   

Disinfection failed

C:\Documents and Settings\shaun wade\Local Settings\Application Data\Comodo\Comodo Firewall\Temp\CPF5.tmp=>(gzip)=>(Embedded EXE g)
   

Deleted

C:\Documents and Settings\shaun wade\Local Settings\Application Data\Comodo\Comodo Firewall\Temp\CPF5.tmp=>(gzip)
   

Update failed



Thanks for all the help here, and i will check in after work and not rely on email notification.

Ps... i have scanned this file with my AVG free, and it found nothing

Cheers, Soulman.
« Last Edit: November 06, 2007, 01:29:31 AM by soulman » Logged
andyman35
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 734


« Reply #14 on: November 06, 2007, 04:04:56 AM »

According to the results you posted there the file has been deleted by the Bitdefender online scanner.Since I don't speak Spanish I'm only guessing that "0 bytes size received / Se ha recibido un archivo vacio" refers to an empty archive? Perhaps you should just manually delete anything left in that particular folder.
Logged
Tags:
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.186 seconds with 20 queries.
Powered by SMF 1.1.7 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com