Both CAV and CFW showing up as trojan in Virustotal and both get caught by MWB

I have on my laptop the .exe of versions 7062, 7098 and 8012.
I have submitted them to VT. None of the files were flagged.

Thanks, I already thought so.

Online or offline .exe or both?

7062 & 7098 : online
8012 : online & offline

offline 7036 (not available on the forum anymore)

“cispremium_only_installer.exe” VT score one : “ESET-NOD32” → “A Variant Of Generik.CDJTCZN Potentially Unwanted”

online 7036

“cispremium_installer.exe” VT score zero
“cav_installer.exe” VT score one : “Yandex” → “Trojan.Agent!gZ9QsxTMcLI”
“cmd_fw_installer.exe” VT score one : “Yandex” → “Trojan.Agent!gZ9QsxTMcLI”

Considering this 12.2.2.7036 version being an old version and thus obsolete and the very very low (only 1 out of 67) VT score I don’t see anything to worry about.

That is indeed the version in question. If you look at the “relations” and “behaviour” tab, it looks a little concerning with all the urls and http connections made, many of which are flagged as malicious on VT.

“I just redownloaded CFW, CAV and CIS from the official website and all three are now coming back as clean, which means that somebody must have done something since my initial post yesterday informing them of the matter on VT”

Did you save those files? Look at the check sums to see if anything was changed. If Comodo “fixed” the files, the checksum should be different.

online 7036

“cav_installer.exe” VT score one : “Yandex” → “Trojan.Agent!gZ9QsxTMcLI”
Extracted all files from installer package “cav_installer.exe” and checked all extracted *.exe and *.dll files on VT, all of them have VT zero score.

“cmd_fw_installer.exe” VT score one : “Yandex” → “Trojan.Agent!gZ9QsxTMcLI”
Extracted all files from installer package “cmd_fw_installer.exe” and checked all extracted *.exe and *.dll files on VT, all of them have VT zero score.

Since all *.exe and *.dll files contained in the installer packages are considered clean on VT there is nothing to worry about.
A storm in a teacup.

Thank you, kind sir. Unfortunately it seems like the latest build of CFW doesn’t want to install on W10. I don’t suppose you know of a fix for this?

Maybe it’s best to create another topic so that you get the right help for that problem.

I solved it :slight_smile: thank you for your help!

One question re: CFW that you may be familiar with, however. In HIPS, do you suggest turning on monitoring for the PC monitor and keyboard? Obviously knowing whether you’re being screen capped or keylogged is vital, but in selecting those options, are you not giving CFW permission to do the same thing in a round-about way?

blocking is better than monitoring so try CS’s settings

Thank you :slight_smile:

It pains me to dig this topic up again, but it seems like Virustotal is once more flagging CFW as malicious, though it’s only one vendor by the name of Zillya. This very same build I scanned a few weeks ago (as you can see earlier in this thread) and it was fine, but now that perfect rating has been changed. What’s the deal with files suddenly changing rating like this?

Maybe you should think about to stop torturing yourself and start digging in the garden which is much healthier. :smiley: :wink:

Probably a result of the vendor making changes to their Heuristics/AI scan algorithms.