| View previous topic :: View next topic |
| Author |
Message |
biggestal
Trooper

 Joined: Mar 27, 2008 Posts: 17 Location: UK
|
Posted: Mon Apr 14, 2008 7:22 pm Post subject: Complainterator download infected? |
|
|
Downloaded complainterator zip-file complainterator21_156.zip from www.castlecops.com/modules/Forums/attachments/ today.
After unzipping and trying to run the .exe file I was warned of virus IM-Worm.Win32.Sohanad.gy which was immediately quarantined by Comodo antivirus!!!
Obviously surprised - is there a real problem?
|
|
| Back to top |
|
 |
tembow
Blue Angel Premium Member
 Joined: Oct 10, 2005 Posts: 2942
|
|
| Back to top |
|
 |
biggestal
Trooper

 Joined: Mar 27, 2008 Posts: 17 Location: UK
|
|
| Back to top |
|
 |
biggestal
Trooper

 Joined: Mar 27, 2008 Posts: 17 Location: UK
|
Posted: Mon Apr 14, 2008 8:33 pm Post subject: |
|
|
Screenshot of freedownloadmanager related to complainerator download attached, if that helps
| Description: |
|
| Filesize: |
110.62 KB |
| Viewed: |
52 Time(s) |

|
|
|
| Back to top |
|
 |
tembow
Blue Angel Premium Member
 Joined: Oct 10, 2005 Posts: 2942
|
Posted: Mon Apr 14, 2008 8:49 pm Post subject: |
|
|
OK, I have submitted current and previous releases of complainterator.exe to virustotal.com
The program is written in an interpretive language and then compiled. The compiler creates the exe in a packed format. This format sometimes triggers false positives. Furthermore, Complainterator generates keystrokes and places them into your browser, then examines the results posted back by the web sites, such as dnsstuff.com. Because it is sending keystrokes, it can be wrongly interpreted by the lesser virus scanners as performing functions similar to keyloggers and malware.
I have compiled some other harmless programs and submitted them to virustotal.com
False positives are reported for Complainterator V19 by
http://www.virustotal.com/analisis/3089b7f4cebb2a439e699aa2d2595c0c
eSafe 7.0.15.0 2008.04.09 suspicious Trojan/Worm
Rising 20.40.02.00 2008.04.14 Trojan.Win32.BrandStep.a
Another harmless compiled program, AutoBlog.exe, has false positives
CAT-QuickHeal 9.50 2008.04.14 I-Worm.Sohanad.fg
eSafe 7.0.15.0 2008.04.09 suspicious Trojan/Worm
NOD32v2 3026 2008.04.14 archive damaged
TheHacker 6.2.92.277 2008.04.14 W32/Sohanad.gh
Finally, I sent a compiled program that says "Hello World" (hw.exe)
http://www.virustotal.com/analisis/2580364a8100c0ec28df66dd342809c4
False positives for "Hello World" (hw.exe)
CAT-QuickHeal 9.50 2008.04.14 I-Worm.Sohanad.fg
eSafe 7.0.15.0 2008.04.09 suspicious Trojan/Worm
NOD32v2 3026 2008.04.14 archive damaged
TheHacker 6.2.92.277 2008.04.14 W32/Sohanad.gh
These are all given a clean report by the big players - AVG, Avast, McAfee, Microsoft, Kaspersky, Symantec
Conclusion
The programs are clean, the less credible scanners are defective.
Please report your Comodo problem to them so they can fix their product.
|
|
| Back to top |
|
 |
biggestal
Trooper

 Joined: Mar 27, 2008 Posts: 17 Location: UK
|
Posted: Mon Apr 14, 2008 9:10 pm Post subject: |
|
|
tembow, many thanks for quick response and reassurance.
My objective was to flag possible issue, not to alarm.
Virus checker I used was Comodo Antivirus beta2, www.comodo.com fyi.
|
|
| Back to top |
|
 |
tembow
Blue Angel Premium Member
 Joined: Oct 10, 2005 Posts: 2942
|
Posted: Mon Apr 14, 2008 10:23 pm Post subject: |
|
|
No problem, it is good to reassure you and anyone else who detects faults in scanners and who may come to the wrong conclusion.
As their user, I leave it to you to alert them to their problem.
|
|
| Back to top |
|
 |
biggestal
Trooper

 Joined: Mar 27, 2008 Posts: 17 Location: UK
|
Posted: Mon Apr 14, 2008 10:55 pm Post subject: |
|
|
Have started posting with comodo av (https://forums.comodo.com/feedbackcommentsannouncementsnews_about_cavs/false_positive_complainterator_v210-t21857.0.html ) and will advise response.
|
|
| Back to top |
|
 |
tembow
Blue Angel Premium Member
 Joined: Oct 10, 2005 Posts: 2942
|
Posted: Fri Apr 18, 2008 7:57 am Post subject: |
|
|
Comodo has fixed the false positive | Quote: | Thanks for your information. False positive is fixed for
"Complainterator " files.
Regards
Malcolm
Technical Support |
|
|
| Back to top |
|
 |
biggestal
Trooper

 Joined: Mar 27, 2008 Posts: 17 Location: UK
|
Posted: Fri Apr 18, 2008 7:16 pm Post subject: |
|
|
Confirming Comodo AV now happy on my PC, will try complainterator over weekend.
Ran file this evening through virustotal.com and pleased to confirm that majority of well known/trusted checkers agree no problem.
Several hours on castlecops confirmed to me that you are major, major battler against spam, tenbow. Thanks for all your efforts.
As newcomer to stopping, rather than blocking spam, I salute you.
|
|
| Back to top |
|
 |
|
|