![]() |
|
|
#1 (permalink) |
|
Member
Join Date: Aug 2010
Posts: 2
|
When I began to install this my Comodo Internet Security popped up the following warning
"A malicious item has been detected! "Trojware.Win32.Buzus.vbf@101147784 "Location C:\Users\Appdata\.....\WS_AgentProcess.dll" The file could not be disinfected. I had Virustotal check out the installation file - 43 test sites (including Comodo) reported the file to be clean. I am uncertain what to make of the conflicting results. |
|
|
|
|
|
#2 (permalink) |
|
Member
Join Date: Aug 2010
Posts: 2
|
The file reported as a trojan is C:\Users\username\AppData\Local\Temp\is-BL8U6.tmp\WS_AgentProcess.dll.
A VirusTotal scan of this file resulted in Comodo reporting it as a trojan and 42 other scanners reporting it as safe. |
|
|
|
|
|
#3 (permalink) |
|
Foundation Editor/Forum Manager Intern
Join Date: Apr 2008
Location: Colorado, USA
Posts: 1,814
|
If VirusTotal claims it is safe and the only one that says it isn't is Comodo, then in my opinion, it is a false-positive on Comodo's part.
__________________
<-------Is looking for his brain.... |
|
|
|
|
|
#4 (permalink) | |
|
Foundation Editor
Join Date: Apr 2008
Location: Planet Earth
Posts: 1,391
|
Quote:
It could still be a real "zero day" virus and in that case the heuristics is doing what it is supposed to. The best line of action is to quarantine that file and see if the program will still run without it.
__________________
The smallest good deed is better than the greatest intention. |
|
|
|
|
|
|
#5 (permalink) |
|
Site Manager
Join Date: Aug 2008
Location: South American Banana Republic, third bunch from the left
Posts: 9,250
|
I think it is also important not to just sit on such an event and do nothing else with it. Most vendors offer a system whereby suspicious files can be submitted for analysis and for the benefit of the community as a whole it is important that this facility is used.
Vendors can then either issue a signature to detect it as true malware or ignore it during future scans in the case of a proven false positive.
__________________
Knows nothing and cares even less |
|
|
|
|
|
#6 (permalink) | |
|
Senior Member
Join Date: Nov 2009
Posts: 1,224
|
Quote:
it has happened before that when the file is executed, then it gets detected by your AV, even though your AV was quiet when the file was uploaded to Virus Total. If I was you and #1 Feel confident that the file is from a trusted company and # 2 Really wanted that program, then I would ignore the warning or exclude the file from being detected and install the program. MC s recommendation to send the file to your AV is a most so they change the detection or confirm it. If they change it, great. If they don't and you want the program, then keep the exclusion. Bo |
|
|
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|