I got the Heur.Suspicious virus alert while using my Nokia PC Suit Updater

So I didn’t know it was a false alert, I pressed disinfect! So now my nokia updater will not work anymore no matter what!! I have tried installing and uninstalling nokia pc suit using uninstaller or revo unistaller, I have tried turning antivirus on and off, and no matter what whenever I launch nokia uninstaller it says windows cannot access the specified device, path, or file! Then it says failed to start the process: "c:\program files\nokia\nokia software updater\nsu_ui_client.exe
NO matter what I try, I have went through all of comodo and I cannot find how to undo the disinfect that I did!!! Please someone help!

Hi Vadimk,

Please submit the detected file at Comodo Antivirus Database | Submit Files for Malware Analysis.

Regards,
Haja

exactly. this is the worst antivrus alert. cleanup deletes the file, disinfect deletes the file. many time users have mentioned this and asked to rename cleanup to delete and make the quarantine button visible and place the delete button in the drop down menu, but the devs simply ignore this prob and have never answered to this prob. i dont understand why disinfect is there when it simply does what the delete button does.

for your prob i guess system restore may work. the current antivirus alert is really a serious prob for novices and average users, even expert users deleted things thinking cleanup will try to clean the file and disinfect will try to disinfect the file.

i think they should change this to as i have mentioned here and many users have mentioned in other threads and wishlist thread.

thanxx
naren

Updated: i too have nokia software updater. so i tried the update. strange thing happened here. downloaded fine and i got an error regarding nokia software updater which said it will start the updater gain and the updater started fine and started installing. when installing at 35%i received the alert heur.suspicious malicious malware found (i have set to automatically quarantine the threats coz of the worst antivirus alert) but the installation was successful and asked to restart. i said restart later. tried to open the updater but it gave error. checked the quarantine but there was nothing. checked the antivirus events there is an entry regarding the detection but nothing about the quarantine. i dont know why there is nothing in quarantine when i have selected to automatically quarantine and it gave me the alert also. i restarted the system and nokia updater started automatically but when i closed it and tried to start it again it gives error. checked the quarantine again nothing found.

can the devs explain me this strange behaviour of comodo antivirus. why the detected threat is not in quarantine when i have selected to automatically quarantine in the real time scan. i have only comodo firewall and antivirus enabled. D+ and sandbox disabled.

attached is the screenshot of antivirus events.

thanxx
naren

[attachment deleted by admin]

Hi naren,

We will investigate the reported false-positive and if it will confirm, detection will be removed.

Regards,
Ionel

strange?? downloaded the same latest version form nokia site and installed. comodo didn’t detected anything this time. and yes the database is same no change i.e 5765.

yes i know the detection will be removed but you didn’t explained why the threat was not quarantined. hope you read the post fully and carefully. comodo needs may be a year or 2 to become a good antivirus and internet security software.

back to the proven and best avast free and zonealarm free.

thanxx
naren

p.s. previously it detected a threat, lil later it didn’t detected anything. why this strange detection?? and not quarantining even if set to automatic quarantine?? cav is not trustable.

I CAN’T BELIEVE THEY ARE JUST IGNORING MY QUESTIONS ABOUT UNDOING!! THEY JUST KEEP ON GIVING THE SAME RESPONSE ON ALL POSTS WHICH SAYS PLEASE SUBMIT YOUR FILE FOR TESTING!" THIS IS COMPLETE BS! I CAN’T USE MY PROGRAM NOW BECAUSE OF COMODO! YOU SHOULD TELL ME HOW TO UNDO AND FIX THE PROBLEM I HAVE WITH THE PROGRAM BECAUSE OF YOU!

Hi Vadimk,
This FP has been fixed.Please check in virus signature database 5778.

Thanks and Regards,

Guoqiang.

So what it has been fixed!? It doesn’t mean anything for me at all! My program is still not working, how do I undo the damage that comodo did to the program? How do I make my program work!?

just reinstall the program. When pressing disinfect you deleted the file. If you are not sure next time select quarantine the file until you are sure. Also comodo did not do any damage, you selected disinfect. Next time select quarantine until you are sure about the file.

he selected to disinfect the file and not delete the file. so the damage is done by comodo. in any antivirus app disinfect means the antivirus app will try to heal the file and not delete the file. so definitely damage done by comodo.

thanxx
naren

I HAVE TRIED REINSTALLING THE PROGRAM, REINSTALLING COMODO, DOING EVERYTHING AND NO MATTER WHAT MY NOKIA SOFTWARE WILL NOT WORK, SO I’M ASSUMING IT MESSED UP THE REGISTRY

you have to unistall the nokia software updater and download a fresh copy from the nokia site and install. hope this will work coz in my case it worked. and if you have comodo antivirus installed and if the heur.suspicious alert pop ups while downloading or installing, click on ignore and add it to exclusions. in my case updating the nokia software updater gave the heur alert but download and install of the fresh copy from nokia site didn’t gave me any alert. comodo heuristic gives a lot of FP’s but it also catches lot of new malware. if you are an average user, i suggest you disable the heuristics, coz sandbox is there to protect you from anything unknown (if you use comodo sandbox).

thanxx
naren