Hello. Today i had reformatted my pc and did a full scan in db 2116 and it came up with i believe an fp in C:\WINDOWS\SMINST\RMC_AR32.EXE. i scanned with Prevx and it came up clean. I have seen this before i think. It is quarantined and submitted via same. Please Advise.



Please submit the sample at Comodo Firewall | Get Best Personal Firewall Software for $29.99 A Year.
Before doing that, please restore the file from quarantine and then temporarily disable the Antivirus until submission completed.

Thank you,
Sonia Botezatu.

Hello. I submitted this via quarantine and the address Comodo gave me to have it analysed. That was on the 27/08/09 and today i performed a scan and its still in data base 2179. I am fairly sure its an fp as i think i have seen this previously in a reformatted machine. It appeared as soon as it was reformatted and a scheduled scan was conducted. Please advise as to whats happenning with this case.


Hi dave1234,

We have performed investigation on your FP reporting and the file “C:\WINDOWS\SMINST\RMC_AR32.EXE” which is being detected as " HeurSuspicious[at]19395081" is definitely a false positive. Please ignore this detection by adding it to your exclusion-list.

Thanks and Regards,
-Chandra Mohan