JimmyD
May 16, 2007, 10:34pm
#1
Using BOClean 4.23. After today’s update: 2007-05-16 16:08:46, it started giving me a trojan alert for:
RSK-REMOTELYANYWHERE MALWARE
See screenshot.
Now, I don’t use remotelyanywhere but I do use LogMeIn. Could this be a false positive after today’s update?
Here’s a screenshot:
http://i34.photobucket.com/albums/d134/venusbase/boclean_pic.jpg
Edit: I believe it is a false positive. LMIINIT.DLL is used for LogMeIn:
http://www.fbmsoftware.com/spyware-net/Process/LMIinit_dll/3208/
_cat
May 16, 2007, 11:44pm
#2
It’s possible.
Are you sure about the source where you acquired the app?
Have you scanned the file with any other application or site?
http://www.virustotal.com/en/indexf.html
From our work in progress FAQ.
False Positives…where to send?
https://forums.comodo.com/index.php/topic,8630.msg62481.html#msg62481
You can email suspect files to: bocleansubmissions at comodo.com .
You may want to specify in the subject line "False Positive?" for clarity's sake.
As usual, zip and password protect with "infected" including that information in the body.
JimmyD
May 17, 2007, 12:07am
#3
I got it directly from the LogMeIn site. I’ve been using it for over a month now. BOClean just alerted me after today’s update. NOD32 says it’s clean.
JimmyD
May 17, 2007, 12:39am
#5
That’s what I thought. Hope it’s fixed soon.
_cat
May 17, 2007, 1:06am
#8
Excellent, thank you!
That’s the fastest way to get a fix, let Kevin and the team know.
When did you turn it in?
JimmyD
May 17, 2007, 1:17am
#9
I emailed bocleansubmissions at comodo.com a little over 2 hours ago, shortly after I made the first post. I gave them the same info in the post and also provided a link to it.
_cat
May 17, 2007, 1:55am
#10
Hopefully you’ll see it fixed in the next update early tomorrow morning.
Thank you for your help!