Why does it take multiple fixes to the DB to resolve an FP?

https://forums.comodo.com/empty-t39534.0.html

https://forums.comodo.com/false_positivenegative_reporting_is_this_a_malware_that_cis_hasnot_detected/multiple_false_possitives-t43762.0.html

In the first link comodo staff confirm that the fp has been fixed, in the 2nd link it shows that later on it was found as malware, Again.

This is a great example on how many times it takes to fix this FP.
https://forums.comodo.com/false_positivenegative_reporting_is_this_a_malware_that_cis_hasnot_detected/spotifyexe_falsepositive_heursuspicious-t39848.0.html

What’s going on?

I’m having the same problem as well. I’ll get ten or fifteen notices about a known good program such as a W2K updater, or cleanmgr.exe. I add it to the list of okay programs and it will still be found and reported yet again in a day or so.

I’ve noticed the same thing. It’s a bit frustrating to see FP’s popping up on files you’ve already submitted. I could understand if the file or application may have been updated so CIS sees it as something new, but when there has been no change, what is the story there? ???

bump

Spotify uses Themida

Hi Kyle,

These situations appear due to version change/update of programs. If a file is added to our safe list, only that specific file is considered safe, any change like replacing, updating or modifying the file in any way or using any method will not be considered safe and therefore, if some conditions are met, heuristics might be triggered again.

Thanks,
Ionel

So what will be the solution? Excluding them each version?
What can COMODO do about this?

Thank you ionelp.

Something needs to be done about this though? Programs are always been updated… there must be an alternative method. ???