CIS "found" TrojWare.MSIL.TrojanSpy.Agent

Hello,

I’m Software Developer and used CIS at home.
For about 1 week i get about 20 messages that all my exuteable project output are infected with the following “virus” :
TrojWare.MSIL.TrojanSpy.Agent

At first i take this message serious and deleted all the infected Files.
The next day the same game. Each time I want to debug my project, comodo said that the output file is a virus.

At the same day I formatted all my partitions and installed Windows Vista again.
At first it seems like CIS don’t have any problems.
It takes about 24 hours until the next message.

Now it ■■■■■■ me really off.

I upload one of the hundred “infected” files to VirusTotal .

The result 1 of 32 scanner engines found the “virus”.

And yeah you guess riight. the only one is CIS.

Now my questions?

Should I take this messages really serious? Even after I delete my hole files and reinstall Windows on a clean partition CIS found the virus again.
And only Comdo!

For the moment I replaced CIS with Panda Internet Security 2010 and it doesn’t find anything.

Did somebody ever had problems like me.

If I used CIS anymore I couldn’t work at the computer because each time I debug my project it shows about two or more messages that the current file is infected.

Please excuse me for my worse english.

I’m from Germany.

Best regards,

rhymin

Could you please submit one of the files that Comodo says is infected to:

Please call it a false positive. It sounds as if this might be a signature that needs to be fixed. If you send the file they will send you an email with the results.

All AV’s have false positives from time to time. Please see here:
https://forums.comodo.com/other-security-products/another-bad-av-update-comodo-avast-arent-the-first-t53998.0.html

hi,

after I wrote this topic, I have sent one of the files to the uri you gave me.
For now I have to wait.

Tanks for your response.

Moving to FP board…

And yeah you guess riight. the only one is CIS.
The simplest way 1)open comodo icon 2)under "misc" or "antivirus" icon (depending on the version 3) click "submit file, find the the files in question and slide it over, then click on false positive, then send
Did somebody ever had problems like me.
Sadly enough on Sat Mar 20, 2010 I was a big problem for bitdefender

http://news.yahoo.com/s/pcworld/20100320/tc_pcworld/badbitdefenderupdateclobberswindowspcs

a quote from the news page

Users of the BitDefender antivirus software started flooding the company's support forums Saturday, apparently after a faulty antivirus update caused 64-bit Windows machines to stop working.

The company acknowledged the issue in a note explaining the problem, posted Saturday. “Due to a recent update it is possible that BitDefender detects several Windows and BitDefender files as infected with Trojan.FakeAlert.5,” the company said.

The acknowledgement came after BitDefender users had logged hundreds of posts on the topic. Some complained of being unable to reboot their systems.

“EVERY file that is trying to run is getting quarantined,” one user, identified as lhmathys, reported. “Windows Explorer and even Bitdefender update itself is being quarantined. Someone really ■■■■■■■ this one up.”

“We are in a really terrible position now,” wrote another user, identified as ufitec. “We have 150 business clients and most of the pcs [on] which BitDefender thinks everything is virus does not boot any more!!!”


AVG had one like this awhile ago

Please excuse me for my worse english.
Whether "German or American, Your english seems pretty good to me :)

You could just keep Comodo “firewall” and maybe “Defence +” and (use a different anti-virus) <–just an idea

Hi rhymin,

We will verify this issue and get back to you after reaching a conclusion.

Regards,
Ionel

Yeah that would be an idea.
Excuse me for my horrible diction in my first post, but at that moment I was nervously quite down.
On the following day I had a deadline for a project…
However thanks a lot for the fast response. :wink: :wink:

hi rhymin,

This is to inform you that false-positive with
<testware.exe> (SHA1: )
has been fixed.
You can update to AV database Version <4362> of Comodo Internet Security Version<4.0.135239.742> and confirm it.

Regards,
liufuxin
Comodo AntiVirus Lab
2010-3-24

Thanks a lot, now its better :smiley: .

I had a deadline for a project....
I hate those, they always want everything done like yesterday. Energy drinks don't help much either