CIS 3.8 is picking up false positives. It is also scanning the Comodo quarintined files during a AV scan even though the Comodo dir and files are in the exclusion list. If you need any more info please let me know.
Here is my AV log:
COMODO Internet Security Logs
Table : Antivirus Logs
Date Created : 2/13/2009 10:24:43 AM
Log Scope : Last 7 Days
Records count : 58
Date/Time Action Location Malware Name Status
2/12/2009 4:43:49 PM Detect C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP151\A0018919.exe Unclassified Malware@4237958 Success
2/12/2009 4:44:49 PM Ignore C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP151\A0018919.exe Unclassified Malware@4237958 Success
2/12/2009 4:44:49 PM Detect C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP151\A0018919.exe Unclassified Malware@4237958 Success
2/12/2009 4:45:08 PM Ignore C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP151\A0018919.exe Unclassified Malware@4237958 Success
2/12/2009 4:45:08 PM Detect C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP151\A0018919.exe Unclassified Malware@4237958 Success
2/12/2009 4:45:29 PM Quarantine C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP151\A0018919.exe Unclassified Malware@4237958 Success
2/12/2009 4:56:23 PM Detect C:\Program Files\Auslogics\AusLogics Registry Defrag\axforms10.bpl Heur.Pck.MEW Success
2/12/2009 5:43:22 PM Detect C:\My Downloads\My Downloads\copytodvd4se.exe Application.Win32.FraudTool.MacroVirus.~A@2937430 Success
2/12/2009 5:44:02 PM Detect C:\Program Files\Auslogics\AusLogics Registry Defrag\axforms10.bpl Heur.Pck.MEW Success
2/12/2009 5:44:03 PM Detect C:\Program Files\CachemanXP\CachemanXPLauncher.exe Heur.Packed.Unknown Success
2/12/2009 5:44:44 PM Detect C:\Program Files\Comodo\COMODO Internet Security\Quarantine\A0018919.exe Unclassified Malware@4237958 Success
2/12/2009 5:47:12 PM Detect C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP103\A0014036.exe Heur.Packed.Unknown Success
2/12/2009 5:47:25 PM Detect C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP114\A0014488.exe Heur.Packed.Unknown Success
2/12/2009 5:47:25 PM Detect C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP114\A0014495.dll Heur.Packed.Unknown Success
2/12/2009 5:50:11 PM Detect C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP75\A0008025.dll Heur.Packed.Unknown Success
2/12/2009 5:50:11 PM Detect C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP75\A0008035.exe Heur.Packed.Unknown Success
2/12/2009 5:51:07 PM Detect C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP82\A0012050.dll Heur.Packed.Unknown Success
2/12/2009 5:51:34 PM Detect C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP99\A0013767.dll Heur.Packed.Unknown Success
2/12/2009 5:51:34 PM Detect C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP99\A0013776.exe Heur.Packed.Unknown Success
2/12/2009 5:59:50 PM Detect C:\WINDOWS\system32\mfc45.dll Heur.PEBomb Success
2/12/2009 6:07:30 PM Ignore C:\My Downloads\My Downloads\copytodvd4se.exe Application.Win32.FraudTool.MacroVirus.~A@2937430 Success
2/12/2009 6:07:30 PM Ignore C:\Program Files\Auslogics\AusLogics Registry Defrag\axforms10.bpl Heur.Pck.MEW Success
2/12/2009 6:07:31 PM Ignore C:\Program Files\CachemanXP\CachemanXPLauncher.exe Heur.Packed.Unknown Success
2/12/2009 6:07:31 PM Ignore C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP103\A0014036.exe Heur.Packed.Unknown Success
2/12/2009 6:07:32 PM Ignore C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP114\A0014488.exe Heur.Packed.Unknown Success
2/12/2009 6:07:32 PM Ignore C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP114\A0014495.dll Heur.Packed.Unknown Success
2/12/2009 6:07:32 PM Ignore C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP75\A0008025.dll Heur.Packed.Unknown Success
2/12/2009 6:07:33 PM Ignore C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP75\A0008035.exe Heur.Packed.Unknown Success
2/12/2009 6:07:33 PM Ignore C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP82\A0012050.dll Heur.Packed.Unknown Success
2/12/2009 6:07:34 PM Ignore C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP99\A0013767.dll Heur.Packed.Unknown Success
2/12/2009 6:07:34 PM Ignore C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP99\A0013776.exe Heur.Packed.Unknown Success
2/12/2009 6:22:04 PM Detect C:\WINDOWS\system32\mfc45.dll Heur.PEBomb Success
2/12/2009 6:23:06 PM Ignore C:\WINDOWS\system32\mfc45.dll Heur.PEBomb Success
2/12/2009 6:23:06 PM Detect C:\WINDOWS\system32\mfc45.dll Heur.PEBomb Success
2/12/2009 6:23:15 PM Ignore C:\WINDOWS\system32\mfc45.dll Heur.PEBomb Success
2/12/2009 6:23:15 PM Detect C:\WINDOWS\system32\mfc45.dll Heur.PEBomb Success
2/12/2009 6:23:20 PM Quarantine C:\WINDOWS\system32\mfc45.dll Heur.PEBomb Success
2/12/2009 6:24:28 PM Quarantine C:\Program Files\Comodo\COMODO Internet Security\Quarantine\A0018919.exe Unclassified Malware@4237958 Success
2/12/2009 6:24:28 PM Quarantine C:\WINDOWS\system32\mfc45.dll Heur.PEBomb Success
2/12/2009 6:39:41 PM Detect C:\Program Files\Auslogics\AusLogics Registry Defrag\axforms10.bpl Heur.Pck.MEW Success
2/12/2009 6:39:42 PM Detect C:\Program Files\CachemanXP\CachemanXPLauncher.exe Heur.Packed.Unknown Success
2/12/2009 6:40:34 PM Detect C:\Program Files\Comodo\COMODO Internet Security\Quarantine\A0018919.exe1 Unclassified Malware@4237958 Success
2/12/2009 6:40:34 PM Detect C:\Program Files\Comodo\COMODO Internet Security\Quarantine\mfc45.dll Heur.PEBomb Success
2/12/2009 6:47:41 PM Quarantine C:\Program Files\Comodo\COMODO Internet Security\Quarantine\A0018919.exe1 Unclassified Malware@4237958 Success
2/12/2009 6:47:41 PM Quarantine C:\Program Files\Comodo\COMODO Internet Security\Quarantine\mfc45.dll Heur.PEBomb Success
2/12/2009 11:40:13 PM Detect C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP151\A0019151.dll Heur.PEBomb Success
2/13/2009 2:39:51 AM Detect C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP151\A0019151.dll Heur.PEBomb Success
2/13/2009 6:39:51 AM Detect C:\System Volume Information_restore{6D3FBDEF-8C21-4647-9BF3-72176E328E86}\RP151\A0019151.dll Heur.PEBomb Success
2/13/2009 9:18:52 AM Detect C:\Program Files\Auslogics\AusLogics Disk Defrag\is-UMABG.tmp Heur.Pck.MEW Success
2/13/2009 9:19:05 AM Ignore C:\Program Files\Auslogics\AusLogics Disk Defrag\is-UMABG.tmp Heur.Pck.MEW Success
2/13/2009 9:19:35 AM Detect C:\Program Files\Auslogics\AusLogics Disk Defrag\AxPackage10.bpl Heur.Pck.MEW Success
2/13/2009 9:19:42 AM Ignore C:\Program Files\Auslogics\AusLogics Disk Defrag\AxPackage10.bpl Heur.Pck.MEW Success
2/13/2009 9:25:15 AM Detect C:\Program Files\Auslogics\AusLogics Registry Defrag\is-TV8VC.tmp Heur.Pck.MEW Success
2/13/2009 9:25:19 AM Ignore C:\Program Files\Auslogics\AusLogics Registry Defrag\is-TV8VC.tmp Heur.Pck.MEW Success
2/13/2009 9:25:22 AM Detect C:\Program Files\Auslogics\AusLogics Registry Defrag\axpackage10.bpl Heur.Pck.MEW Success
2/13/2009 9:25:27 AM Ignore C:\Program Files\Auslogics\AusLogics Registry Defrag\axpackage10.bpl Heur.Pck.MEW Success
2/13/2009 9:28:52 AM Detect C:\Program Files\Auslogics\AusLogics Disk Defrag\is-V7N3F.tmp Heur.Pck.MEW Success
2/13/2009 9:28:56 AM Ignore C:\Program Files\Auslogics\AusLogics Disk Defrag\is-V7N3F.tmp Heur.Pck.MEW Success
End of The Report
Hi,
Could you please verify these FP’s with latest base updates? If you still find any FP’s please submit those files to AVLab.
Thanks,
Ramanan