DLDR-Games.D False Positive ? [Resolved]

On Boot this AM, found in:

C:\WINDOWS\SYSTEM32\DRIVERS\AEC.SYS

Clean Jotti scan

yep… i am seeing the same thing… i submitted the file to comodo as a false-positive… hopefully it will be addressed soon…

On my PC it found:

C:\WINDOWS\SYSTEM32\DRIVERS\DMIO.SYS

:SMLR

Found this one in C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.0\WINDOWS COMMUNICATION FOUNDATION\INFOCARD.EXE for me.

Definitely a FP as I’m getting the same thing here too.

… and again the same here… what’s worse, you can’t drag the application into the Program Excluder, as it will not accept sysfiles…

Could it possibly be that now that Kevin is no longer doing detections those who ARE are no longer taking the same care as used to be the case?

Probably the best thing right now is to just select no and wait until it is fixed.

got the 05/21/2007 10:13:52: C:\PROGRA~1\GRISOFT\AVG7\AVGCC.EXE
Trojan horse was found in above file
DLDR-GAMES.D MALWARE STOPPED by BOCLEAN!
Logged in user: USER
Active trojan horse was shut down. System now safe.
Trojan horse was removed, registry cleaned.


05/21/2007 10:23:16: C:\WINDOWS\SYSTEM32\DRIVERS\AEC.SYS
Trojan horse was found in above file
DLDR-GAMES.D MALWARE STOPPED by BOCLEAN!
Logged in user: USER
Active trojan horse was shut down. System now safe.
Trojan horse was removed, registry cleaned.


05/21/2007 11:07:20: C:\WINDOWS\SYSTEM32\DRIVERS\AEC.SYS
Trojan horse was found in above file
DLDR-GAMES.D MALWARE STOPPED by BOCLEAN!
Logged in user: USER
Active trojan horse was shut down. System now safe.
Trojan horse was removed, registry cleaned.


05/21/2007 11:09:50: C:\WINDOWS\SYSTEM32\DRIVERS\AEC.SYS
Trojan horse was found in above file
DLDR-GAMES.D MALWARE STOPPED by BOCLEAN!
Logged in user: USERsame things. said yes to deleting files though. frank.

Idem today:

http://www.hostingfiles.net/files/20070521065720_boclean.jpg

In case you lost it, aec.sys v.5.1.2601.2180 attached here.

Typical location to extract to:

Win XP Pro: C:\Windows\System32\Drivers
Win XP Home: C:\Winnt\System32\Drivers

[attachment deleted by admin]

Yep got the same and BOClean says its been removed but it keeps coming back??

The log:

05/21/2007 17:37:50: C:\WINDOWS\SYSTEM32\DRIVERS\AEC.SYS
Trojan horse was found in above file
DLDR-GAMES.D MALWARE STOPPED by BOCLEAN!
Logged in user: Tr@gic
Active trojan horse was shut down. System now safe.
Trojan horse was removed, registry cleaned.


05/21/2007 18:56:18: C:\WINDOWS\SYSTEM32\DRIVERS\AEC.SYS
Trojan horse was found in above file
DLDR-GAMES.D MALWARE STOPPED by BOCLEAN!
Logged in user: Tr@gic
Active trojan horse was shut down. System now safe.
Trojan horse was removed, registry cleaned.


05/21/2007 18:57:03: C:\WINDOWS\SYSTEM32\DRIVERS\AEC.SYS
Trojan horse was found in above file
DLDR-GAMES.D MALWARE STOPPED by BOCLEAN!
Logged in user: Tr@gic
Active trojan horse was shut down. System now safe.
Trojan horse was removed, registry cleaned.

got the 05/21/2007 10:13:52: C:\PROGRA~1\GRISOFT\AVG7\AVGCC.EXE Trojan horse was found in above file DLDR-GAMES.D MALWARE STOPPED by BOCLEAN! Logged in user: USER Active trojan horse was shut down. System now safe. Trojan horse was removed, registry cleaned.

I also received the above this morning. ??? Hope the FP get fixed soon.

What we’d like to see in a future build is

  1. a ‘rollback’ feature allowing the user to revert to the previous database update

  2. the possibility to add sysfiles to BOClean’s Program Excluder (as well as any other filetypes presently targeted but not allowed)

Here’s the place for requests: Comodo BOClean Wishlist 1

Same here…C:\WINDOWS\SYSTEM32\DRIVERS\AEC.SYS

Well, strictly speaking Soya is of course right :slight_smile:

I just thought that my remarks were pretty relevant to the topic at hand.

(I seem to be posting in the wrong place rather a lot today…

)

I agree :slight_smile:

Greetz, Red.

boclean found the same FP at programfiles\a-squared free\a2service.exe on my pc :frowning:

Ctrlaltdelete send me a pm that he has that FP too :frowning:

Greetz, Red.

OK, I’ll do that. :slight_smile: