trojware.win32.trojan.agent.gen

Comodo continues to identify that I have a ton of trojware.win32.trojan.agent.gen activity (as well as a few Huer.Packed.Unknown@1 & ApplicUnsaf.Win32.Hide~AB@5325787) throughout my drives but yet when I run Malwarebytes and SAS, I see no activity and all are clean free. Are these possibly all FP’s? Please see atatched screen shot. Please advise, thank you.

[attachment deleted by admin]

I would upload them to virustotal.com to see whether others detect this as well. If not, upload to Comodo as false positives.

Hello vfr750mmm,

The detected files having the malware name “TrojWare.Win32.Trojan.Agent.Gen@104571357” are not False-Positives so please make sure you remove them from your system.
The files detected as “ApplicUnsaf.Win32.Hide.~AB@5325787” are applications that can be used as malware in certain conditions, you will find more informations about them in this link: https://forums.comodo.com/av-false-positivenegative-detection-reporting/cis-malware-naming-rules-for-potentially-dangerous-applicationsriskware-t38506.0.html , if you want to further use them just add them to your “Exclusions” list.
In order to check to files detected as “Heur.Packed.Unknown” please submitt them on : Comodo Antivirus Database | Submit Files for Malware Analysis and we’ll get back to you soon with the result.

Best regards,
FlorinG

Thank you for the kind reply. My concern is I am deleting these files after they are quarantined yet more pop up as I proceed activity on the PC. I will soon check out the forum you advised me to with regards to the
other potential malware, but obviously my immediate concern is about not being able to rid my system of the TrojWare.Win32.Trojan.Agent.Gen despite repeatedly deleting them and Malwarebyte an SAS not detecting any of them. Any suggestions? Here is a sample of the latest two popping up.

[attachment deleted by admin]

My concern is I am deleting these files after they are quarantined yet more pop up as I proceed activity on the PC
Do this
  1. Restart computer

  2. The second the computer restarts, quickly and keep htting the “F8” key until a new screen comes up

  3. Go to windows safe mode

  4. Open comodo

  5. Run anti-virus and clean what it finds

  6. Then run the anti-virus again to make sure nothing comes back

  7. Restart the computer

  8. Done :slight_smile:

Jay, thanks for the suggestion. I scanned the drives in safe mode. At first I could not do it, I kept getting a “no interface available” then I just right clicked on each drive individually and was able to scan. The problem I now am faced with is I am unable to delete the files in the Quarantine Items list. When i try to delete them I get a "Remove failure. Error code 0x80004002. No such interface supported. My window is still open with being undecided on what to do (I am presently on my notebook writing this). If i move forward and reboot in normal mode with my internet disabled and then go and delete them, will this maybe have worked with no connection to ping back to regenerate?

If i move forward and reboot in normal mode with my internet disabled
After everythings clean, just reboot in normal mode (DON'T DISABLE INTERNET)
The problem I now am faced with is I am unable to delete the files in the Quarantine Items list.
did you do this??? (Assuming your your in normal computer mode) (I don't know anything about deleting stuff in comodo quarantine in "SAFE MODE"

1)open comodo icon
2) click on “anti-virus”
3) click on “quarantine items”
4) highlight an item
5) click on “delete”
6) repeat steps 4 and 5 until all the items you want removed
7) Then click “close”

no, i am at a standstill with my pc still in safe mode. I cannot delete them in safe mode. I guess my only option is to reboot offline and delete them and pray they dont regenerate?

Please see this guide:
What You Need To Know About Removing Infections and Securing Your Computer
You might find it useful. :wink:

Also, as it now appears that these are not FP’s I believe that this topic now belongs here:

Could you please start a new topic on that board.