Heur.Packed.Unknown[at]4294967295

This is a continuation of my first reporting. I sent the sample files to the online submission, but got an email back saying the packed sample files weren’t detected (I don’t think they unpacked them).

Hi,

( (SHA1: <50776daa6d1536dd83c891fc47c1f0edb4907224>))
(<Quarantine.zip> (SHA1: ))

The samples u submitted as false-positive is not detected by Comodo Internet Security version <6.2.285401.2860> with database version <16841>. Please make sure the Antivirus database is updated and check again.
If detection is still present, please submit the file on Comodo forums at https://forums.comodo.com/false_positivenegative_reporting_is_this_a_malware_that_cis_hasnot_detecte-b154.0/ along with details about the environment on which this event occurred.

Regards,
Qiuhui.■■■■
Comodo Antivirus lab
2013-8-29

I did manage to get CIS to quarantine one of the pesky temp files. I’ve attached a copy of my Quarantine directory and my log file (please unpack).

Reference: https://forums.comodo.com/av-false-positivenegative-detection-reporting/fp-utorrent-33130017-temp-files-t97784.0.html

With heuristics set on high, right click Quarantine.zip and choose Scan with Comodo AntiVirus, produces an alert. It detects the FP file inside the .zip file.

[attachment deleted by admin]

Hi L.A.R. Grizzly ,

Thank you for reporting this.
We’ll check it and get back to you soon.

Best regards
Qiuhui.■■■■

Hello L.A.R. Grizzly,

This False Positive had been fixed. You can update to AV database Version 16846 of Comodo Internet Security Version 6.2.285401.2860 and confirm it.

Best regards,
FlorinG

Thanks FlorinG! Confirmed fixed! :BNC (:CLP) :■■■■