False positive: Heur.Packed.Unknown - Thininstall

Found false positive for Thinstall VS.3.146.

File Info

Report generated: 5.3.2009 at 9.19.36 (GMT 1)
Filename: Thinstall.VS.3.146.Licensed.rar
File size: 5128 KB
MD5 Hash: 8ED34E7F2B9033842ED9A88BF608D5E2
SHA1 Hash: 1088ED94A97731BFD9C6483A1B722FE0AD9FDF41
Packer detected: Not a valid PE file
Self-Extract Archive: Nothing found
Binder Detector: Nothing found
Detection rate: 1 on 24

Detections

a-squared - Nothing found!
Avira AntiVir - Nothing found!
Avast - Nothing found!
AVG - Nothing found!
BitDefender - Nothing found!
ClamAV - Nothing found!
Comodo - Heur.Packed.Unknown
Dr.Web - Nothing found!
Ewido - Nothing found!
F-PROT 6 - Nothing found!
G DATA - Nothing found!
IkarusT3 - Nothing found!
Kaspersky - Nothing found!
McAfee - Nothing found!
MHR (Malware Hash Registry) - Nothing found!
NOD32 v3 - Nothing found!
Norman - Nothing found!
Panda - Nothing found!
Quick Heal - Nothing found!
Solo Antivirus - Nothing found!
Sophos - Nothing found!
TrendMicro - Nothing found!
VBA32 - Nothing found!
Virus Buster - Nothing found!

Reporting a False Positive

  1. Please zip up (using a archive tool like winzip,winrar etc) the file that you believe is wrongly detected and password it with password ‘infected’ without the quotes and email it to malwaresubmit[at]avlab.comodo.com (Look here if you don’t know how to rar files)

  2. Please make sure to mention “FALSE POSITIVE” on the subject line of the mail. Also include the the name and ID (for example, BACKDOOR.WIN32.XXXXX.XX (ID = XXXXXX) under which the file in question is getting detected. Attaching a screen shot would be very helpful.

Reporting a Suspicious File

  1. Please zip up (using a archive tool like winzip, winrar etc) the file that you believe is wrongly detected and password it with password ‘infected’ without the quotes and email it to malwaresubmit[at]avlab.comodo.com (Look here if you don’t know how to rar files)

  2. Please make sure to mention “SUSPICIOUS FILE SUBMISSION” on the subject line of the mail.

Hey kyle, do you like my new topic ? Here’s the one with colors

Reporting a False Positive

  1. Please zip up (using a archive tool like winzip,winrar etc) the file that you believe is wrongly detected and password it with password ‘infected’ without the quotes and email it to malwaresubmit[at]avlab.comodo.com (Look here if you don’t know how to rar files)

  2. Please make sure to mention “FALSE POSITIVE” on the subject line of the mail. Also include the the name and ID (for example, BACKDOOR.WIN32.XXXXX.XX (ID = XXXXXX) under which the file in question is getting detected. Attaching a screen shot would be very helpful.

Xan

Yeah it’s good. Hey btw Xan, Maybe it could be stickied in more boards? Questions in regards to false positives are always being asked.

There is a sticky about it in this board and in the Comodo BoClean board ? Where would it be helpfull also you think ?

Xan


All
the parent boards… lol (even if it doesn’t belong in the right board) l atleast while the hueristics are still new. Just my opinion.

I just installed CIS today and ran the AV. It showed a virus called Heur.packed.unknown. If this is a false positive is the correct thing to do is remove it or restore it? Thanks

If it’s a FP, I sujest you report it like said here :

in the meantime, I sujest you ignore it…

Xan

Hi eckstasy,

Could you please verify the FP with the latest base update?

Thanks,
Ramanan

I just ran CAV (CIS 3.8.65951.477) and got the red alert that it found heur.packed.unknown. I had it quarantined, but having just googled the file I found this forum result, so PLEASE ADVISE if I should not have this quarantined.

Thanks,

dorothy

I am receiving the same error in a very strange kind of situation.
the wearied thing is that these are comodo products!
When ever i download the comodo antispan or boclean from comodo website through firefoxe or some times with IE8 the comodo internet security says

Virus found if you want to delete it you must restart the computer

  1. yes
  2. NO

And it also reports it in the antivirus log.

every time the file is in the “temp” folder or firefox folder

  1. “C:\windows\temp_avast\up105969567”

OR

C:\Documents and settings%%%\Local settings\temp\nw6pvgDJ.exe.part

OR

C:\Documents and settings%%%\Local settings\Applitcation Data\Mozzilla\Firefox\Profiles\nw6pvgDJ.exe.part

then what i did is i downloaded the Free downloaded manager and the files were successfully downloaded.

BTW does any one know why this happens or what is the solution to it.

Thanks in advance

Hi! I found this while searching for Heur.Packed.Unknown because I’ve had to quarantine files from at least four programs. Okay, so I’ve quarantined them, and I figured out how to restore them so I can rar them up, but there’s one problem: one of the programs it triggers on is winrar! I tried restoring the “offending” file from Winrar, but as soon as I fire up Winrar, it triggers the darned Heur.Packed.Unknown again.

I’m recovering my computer from what apparently was virut. I started fresh with a hard format (fully zeroed my boot drive), then deleted all .exe, .htm, and .html files (the virus will inject code into htm* files) on my accessory drives, along with programs that used them.

Okay, so I’m redoing my setup and even with Comodo set to all but paranoia mode for downloads, and when I am ready to install a file, I scan with Comodo again, followed by Malwarebytes. Up to that point, nothing was detected. However, as soon as I run Malwarebytes, when it runs across the aforementioned “offending” files in Winrar, Splitfile, and Calendar, (all of which were downloaded from CNet), boom, there goes the red pop-up from Comodo, saying that I have Heur.Packed.Uknown in certain files.

So, I tried to restore one .dll and two .exe files from Comodo’s quarantine, so that I may put each file into a rar file (with the password “infected”) and send off to Comodo. That’s when more problems occur. The .dll file from one of the programs, after restoring, becomes stubborn. Not only am I unable to add it to a .rar or .zip file, it won’t let me delete it again, and Comodo doesn’t do the “hey, you’ve got Heur.Packed.Uknown” thing on the file. At that point, I’m WTF? It won’t tell me that the file is infected, AND now I can’t delete it? Thankfully, the File Assassin that is built into Malwarebytes will delete it. With that many problems on a freeware program, I give up.

Back to the Winrar thing. I don’t understand why Comodo will allow me to use Winrar, but while I’m doing something else, suddenly tell me that my Winrar is infected. This is getting really annoying. Up to this point, I have really grown to love Comodo and the killer firewall that comes with it, but now I’m ready to dump it and switch back to AVG. Yeah, I know that probably is a dirty word around here, but come on, during the six years I used AVG, not once did I receive a false positive.

So, to you gurus who work for Comodo, please tell me what I should do here. I nuked the Winrar I had, downloaded the free (evaluation) copy and installed it and as soon as I went to use it, Comodo tells me it’s infected with - you guessed it - Heur.Packed.Unknown. Not only that, if I tell it to ignore, it keeps popping back up, not obeying my ignore command. How in the heck am I supposed to send a rar file of the “offending” file to you guys if Comodo won’t let me use the ■■■■■■ program?

kat, going from O0 to :frowning: (about to pull my hair out)

Hi katillac,

You can lower the Heuristics levels to a point where you will be able to handle the files:

CIS > Antivirus > Scanner Settings > Real Time Scanning > Heuristics

After this, please submit the files to us at Comodo Firewall | Get Best Personal Firewall Software for $29.99 A Year so we can verify and provide a fix if it confirms to be false positive.

Regards,
Ionel

Thank you for the quick response, Ionel! After reading your post, I remembered that I had changed the heuristics setting to Medium. I just reset it back to Low, which was what it was at after installation. Thank you also for the link for reporting false positives and suspicious files. I hope I won’t need to use it any time soon. I do like the Proactive Defense feature; though it can be a bit annoying, I like the way it double checks files. After suffering through a bout with Virut (opened a file from a trusted friend and AVG didn’t catch it), I’m still a bit paranoid. I lost about six years worth of files and I’m having to rebuild from scratch.

I’ll try to give an update within another day or two. Thank youa gain, Ionel =)

Sorry for not reporting back in sooner. Death in the family.

No new false reports since adjusting the heuristics level from pit bull mode to more like Lassie mode. Or something along those lines. :comodosavedmylife: