Chingy Malware? Error:BOClean encountered a problem and needs to close.

Hi,

I’ve just installed BOClean two days ago.

I received three different BOClean messages:

FIRST:

Chingy Malware stopped by BOClean.
C:\Windows\System32\Final~1.scr
I said ‘YES’ to ‘Do you want the file removed?’
Microsoft Error Report Message popped up that BOClean has encountered a problem
and needs to close.
Also displayed was Error Message: Program Error BOC425.exe has generated errors and
will be closed by Windows. You will need to restart the program.

*I had a look at the file in question in System 32.
I think this is a false positive, since this file is present in my PC for years and was created by Softwaremaker Axialis.com.

SECOND: according to BOreport.txt

09/04/2007 13:46:09:
Trojan horse was found in memory.
C:\PROGRA~1\SYMANTEC\LIVEUP~1\LUCOMS~1.EXE contained the trojan.
Active trojan horse WAS shut down. System now safe.

*I’m running Norton Internet Security 2007 and Norton SystemWorks Basic Edition 2006

THIRD: according to BOreport.txt

09/04/2007 15:26:38: CHINGY MALWARE STOPPED by BOCLEAN!
Trojan horse was found in memory.
C:\PROGRAM FILES\FASTSTONE CAPTURE\FSCAPTURE.EXE contained the trojan.
Active trojan horse WAS shut down. System now safe.

*Surely a false positive.

Appreciate any tips and ideas on this one.
Thanks and Cheers

Hi kulaworld,
Welcome to the Comodo forums!
Please submit the files in question to support.
From the CBO forum FAQ:

[u][b]False Positives?[/b][/u]

Q: Where do we send the files that are being alerted on that we suspect are FPs?

A: You can email them to: malwaresubmit [ at ] avlab.comodo.com .
You may want to specify in the subject line “False Positive?” for clarity’s sake.
As usual, zip and password protect with “infected” including that information in the body.


If it is in fact an FP it will be fixed, usually in the next update.
We really appreciate your help.

Hi ~cat~,
Great to be here! (:WAV)

No worries, info is off to support already.

Thanks & Cheers

Good deal, thank you again.
I’m especially concerned with the “encountered a problem and needs to close” part.
This sounds suspicious…