Report trusted and whitelisted malwares here! [Don't attach Live Malware !!]

Hi!

I have already submitted this file but nothing happened.
Are you sure it’s safe?

-Comodo by VirusTotal: “UnclassifiedMalware”
-CIS 5.3: undetected

http://www.virustotal.com/file-scan/report.html?id=631ab7f16d588def9eb44bc0c8e823928f7c6c3f0be4c4d493ab657ebabcb28c-1294825862

Thanks and Regards,
vv5204

Hi vv5204,

We are looking into it!

Regards,
Ionel

Hi vv5204,

Associated vendor was removed from TVL.

Thanks and regards,
Ionel

Hi!

Some suspect files:

-VirusTotal result: 5/43
-CIS 5.3: vendor in TVL or whitelisted

http://www.virustotal.com/file-scan/report.html?id=f60aea11e524e90e362a35bceb0112474e9431267bb6222f08bf264c593e7203-1294964249

-VirusTotal result: 1/43
-CIS 5.3: vendor in TVL or whitelisted

http://www.virustotal.com/file-scan/report.html?id=bf4b6ca339c4ee3fda063b82f1145c2273fa3b502a1440b3c442fa0ab0b41a35-1294964272

-VirusTotal result: 8/43
-CIS 5.3: vendor in TVL or whitelisted

http://www.virustotal.com/file-scan/report.html?id=61b9b91465076b9d7eed6e6acfe489afbcd3fbd6ded62769a4eb3112a77d01e3-1294964339

-VirusTotal result: 11/43
-CIS 5.3: vendor in TVL or whitelisted

http://www.virustotal.com/file-scan/report.html?id=f5b30026b45b948855132458cfc7991f3f8e158ab485807a0fb6a3e2feaeef80-1294964477

-VirusTotal result: 19/43
-CIS 5.3: vendor in TVL or whitelisted

http://www.virustotal.com/file-scan/report.html?id=353dd1af55814a256adc5cd12e0aa411c225938c421fe2320dc7061c12656e40-1294964846

Thanks and Regards,
vv5204

Any idea from Comodo how to fix the dangerous vendors of TVL and entries of whitelist?

What do you mean “dangerous vendors”

Hi vv5204,
Thanks for malware submission. We are going to check this out and if found malware,detection will be added.
Thanks and Regards,
Lin mengze

!ot!

Files are infected by malware and trusted by Comodo. (TVL, whitelist)

http://www.virustotal.com/file-scan/report.html?id=15af4aa25b598fa5de3df9681681f0a1d41aeae48933362c0d7ea69c2fb67f57-1294955626

are you sure about that.?
they wouldnt be trusted if infected with malware.

Hi, guys!

Please check this…

http://www.virustotal.com/file-scan/report.html?id=b866232bd12229ba1fb0c7e139c680007c92a7e1d1bd78cd8e04c07ee904c6f1-1295022481

It is signed by DRPU Software Private Limited and trusted by Comodo.

http://www.virustotal.com/file-scan/report.html?id=89f776398451f81f9859384c4a65a1a82875c855faf9ac7b2e2fd4bbda7f3b30-1295020586

It is signed by Shanghai Emoney Software Technology Company Ltd and trusted by Comodo.

Hello,

Thank you for your submissions. We’ll check these.

Best regards,
FlorinG

!ot!

Ok, but why does exist this topic? :slight_smile:

Hi.
This is a video test performed by a uk webmaster on regcure.
The video is self explanatory and will show why regcure by paretologic is not a safe application.
the comments give some insight also.

Well with all due respect to you i must disagree in the highest forms.
The terminology malware should not be just confined to viruses trojans etc.
If a program can totally destroy a computer then how more malicious can you get.?
I mean even if software companies retail in PUPS then they should not be in the list.
Most people can handle a few trojans here and there but programs that have the potential to destroy your computer are far more malicious than any trojan.
Im sticking by my decision on paretologic.
They act like criminals in my opinion.And its criminal to have them in the whitelist.

regards.

here is another one. Fake registry cleaner that bugs you to buy it.

SafeApp Software LLC signed by VeriSign

http://camas.comodo.com/cgi-bin/submit?file=0563ef859b63ca0891983993d8a4c5f0e04ec5d321cfa1d56f9f0e5c8c788957

http://www.virustotal.com/file-scan/report.html?id=0563ef859b63ca0891983993d8a4c5f0e04ec5d321cfa1d56f9f0e5c8c788957-1295132056

http://www.virustotal.com/file-scan/report.html?id=b21526716068d2a8550780038e2b5ddb843d77890a07ec82ed9ce9dd0be52c64-1295174308

http://www.virustotal.com/file-scan/report.html?id=159797ef8760f327cd64db646f0fa03e0ae4d504b6d4fcfe12da30a70a3c8ddf-1295174343

Zhuhai Kingsoft Software Co.,Ltd

“Not fake but this is an old version of the legit Kingsoft Antivirus file which gets exploited by malware.” - as you can see below VT report.

I’ve submitted all of this “rouge(or not rouge)” here: https://forums.comodo.com/malware-research-group/submit-malware-here-to-be-blacklisted-2011-t66774.0.html;msg481449#msg481449

These are whitelisted by CIS

http://www.virustotal.com/file-scan/report.html?id=e3a3cd7e13c294d45098967b4b5a4fd774d462a2c19ef1f9cbc78a9d0221bc60-1295288492

http://www.virustotal.com/file-scan/report.html?id=f5b30026b45b948855132458cfc7991f3f8e158ab485807a0fb6a3e2feaeef80-1295289042

http://www.virustotal.com/file-scan/report.html?id=e670b47d9bf442f1aff5f1f45d5ced02916c96c55630235566c8e0f567ebdfc4-1295288989

http://www.virustotal.com/file-scan/report.html?id=f60aea11e524e90e362a35bceb0112474e9431267bb6222f08bf264c593e7203-1295288949

http://www.virustotal.com/file-scan/report.html?id=bf4b6ca339c4ee3fda063b82f1145c2273fa3b502a1440b3c442fa0ab0b41a35-1295289261

http://www.virustotal.com/file-scan/report.html?id=61b9b91465076b9d7eed6e6acfe489afbcd3fbd6ded62769a4eb3112a77d01e3-1295289311

http://www.virustotal.com/file-scan/report.html?id=353dd1af55814a256adc5cd12e0aa411c225938c421fe2320dc7061c12656e40-1295103819

http://www.virustotal.com/file-scan/report.html?id=7457828319e2282f0ded4b924a89f18b53e3a7a3c3da9d0ce892c0af49cf70d3-1295289336

edit: some more:

http://www.virustotal.com/file-scan/report.html?id=fc3b5e2c9e3338e6b722dacf49bdc819a0f3504ffca43882300e2c356fb2b38c-1295291189

http://www.virustotal.com/file-scan/report.html?id=89f776398451f81f9859384c4a65a1a82875c855faf9ac7b2e2fd4bbda7f3b30-1295291272

http://www.virustotal.com/file-scan/report.html?id=9fb9604b8bbbc6d029c8c793c0a926b227ced579db867f6ce6bb1a1aab3440c3-1295291253

http://www.virustotal.com/file-scan/report.html?id=efc79aa75d2faa8e340a787f5f900b2fdd3051b517f6319ec4146c2aab317b28-1295291213

Hi nime,

We are going to verify and get back to you.

Regards,
Ionel

Guys,

can you check this one…

http://www.virustotal.com/file-scan/report.html?id=4dda42df9fe0ae768b89e119656e98553341f5f8307ad23614b91f3403080318-1295337928

http://camas.comodo.com/cgi-bin/submit?file=4dda42df9fe0ae768b89e119656e98553341f5f8307ad23614b91f3403080318

http://www.urlvoid.com/scan/zugo.com

whitesmoke-silent.exe has Zugo Ltd digital signature signed by Comodo Time Stamping Signer.