Post here your unfixed FP's (only after 2 days)

Please post here all unfixed FP’s . Please only post them when they’re not detected after 2 days.

Please include,

  • your original FP post
  • when you last tested CIS against it + what database

When the FP is fixed, please delete your post in this topic again !

Thanks,

Xan

Thanks eXPerience,
This will help us to clean up whatever is left.

Thanks
-umesh

https://forums.comodo.com/false_positivenegative_reporting_is_this_a_malware_that_cis_hasnot_detected/again_heurpebomb_in_browser_cache-t35714.0.html
First post.
Last tested with DB 1046.

https://forums.comodo.com/false_positivenegative_reporting_is_this_a_malware_that_cis_hasnot_detected/again_heurpebomb_in_browser_cache-t35714.0.html First post. Last tested with DB 1046.
Hi, I have responded here: https://forums.comodo.com/false_positivenegative_reporting_is_this_a_malware_that_cis_hasnot_detected/again_heurpebomb_in_browser_cache-t35714.0.html;msg258622#msg258622

Thanks
-umesh

yo!
what about the b2e.exe
i’ve posted it several times, but i can’t remember where my posts are 88)

but i remember it’s been removed from BOClean database :-La

RAR Slayer v1.1.exe
Sent it via mail.

Virus total results

http://www.virustotal.com/analisis/e28c42883cc2ab0c8a1f6f60f1f1f626

  1. CPU Athlon 64 X2 4600+
  2. Windows XP pro, service pack 3, 32 bit
  3. CIS 3.8.65951.477
  4. Antivirus - default settings
  5. Firewall - custom policy mode
  6. Defense+ - clean PC mode
  7. Administrator account

Last scan today. Virus database 1049

Hi,
We will have a look at this today.

Thanks
-umesh

Hi Lt.ganda,

CIS is not detecting the file b2e.exe with/without heuristics. Please verify it with the latest base update. If you still find the detection in CIS, please submit the sample to AVLab.

Thanks,
Ramanan

nope, still there with database #1049 :stuck_out_tongue:

[attachment deleted by admin]

This is what I got over pm


Original post: https://forums.comodo.com/false_positivenegative_reporting_is_this_a_malware_that_cis_hasnot_detected/qfecheck_fp-t36252.0.html

Last test: today with DB 1049

Thanks
Hakan


Xan

Hi Lt.ganda,

Please check with the latest base update.

Thanks,
Ramanan

Hi MJ.nfl,

The file in question is detected by heuristics and is a cracking application. Although it is not a “maliclious software”, the purpose of the detection is to warn the user about potentially unwanted/dangerous applications. Moreover, such cracking applications are packed/protected by some non standard programs which are used almost only by malicious files. This detection is one such generic detection. If someone still wants to use the ■■■■■ application, the user can just add the file to exclusion list.

Thanks,
Ramanan

False Positive in relation to BOClean files (evidence.boc) has reappeared although different threat this time.

See attached image file.

Should I upload to avlab again?

Edit: reappeared with Database version 1049 and still present with Database version 1056

[attachment deleted by admin]

Hi monkeytails,

Thanks for reporting,
FYI : evidence.boc is a backup file ,which BOClean takes before removing the file on detection.

That might not be a FP.

Thanks and Regards,
Suresh.

Checked BOClean logs and shows a detection of leaktest.exe.

If this a backup that BOClean creates (Am I understanding you correctly?), then the AV of CIS will always detect the backup file. Again correct me if im wrong.

So should I delete this file or permanently exclude it or the folder from scaning…???

regards

monkeytails

Edit: have answered my question by looking at the BOClean on line help…will delete from computer.

Thanks for your help.

HI,

I am posting this at the request of Experience. My initial False Positive report is below, along with the message from Suresh that the problem was fixed.

On the morning of 03/17/09 I had to restore a backup to my laptop, and took the opportunity to install the latest CIS (3.8.65951.477, data base 1062) and BOClean 4.27. Almost immediately, CIS showed 1 threat found, and it was the same ALCXSENS.SYS driver mentioned in my initial post, again as a Heur.Pck.tElock . What was very strange was that after an hour or so, the summary screen shows no threats found, (down from 1 earlier) yet the Antivirus events log still shows the detection.

I don’t know that it matters, but I am running XP Home SP3 on a Gateway laptop with an AMD Athlon 64 3400+ with 1 GB memory, and the CIS settings are all default.

Wrapper

Topic Summary
Posted on: March 10, 2009, 08:56:24 AMPosted by: sureshk
Insert Quote
Hi wrapper,

FP has fixed.Please confirm with our latest Updated base.

Thanks for Reporting.

Thanks and Regards,
Suresh.

Hi oldCoCo3user,
Can you please send the suspected file to us. Please visit this link on https://forums.comodo.com/false_positivenegative_reporting_is_this_a_malware_that_cis_hasnot_detected/how_to_report_false_positivessuspicious_files_how_to_submit_them-t36051.0.html
to know more on submission of files.

Regards,
Sriram.P

Hi oldCoCo3user,

Thank you for submitting the file. The reported False Positive has been fixed.

Regards,
Sriram.P

I reported archlp.dll as an FP during the weekend. It is part of Arcsoft’s Total Media Theater installation. Copy of the file was submitted through CIS RC 2. Not yet fixed in ver 1154. Identified as unclassified malware@14955904.

Richard