Endejan's Question: Recovering a file deleted by Comodo

Status
Not open for further replies.

bogdan

Level 1
Thread author
Jan 7, 2011
1,362
Sorry, I had to copy/paste this thread from the old server.

endejan asked:

Hi, I'm having a problem here.
I installed some software that asked me to reboot my computer, after it was booted, I got a lot of pop-ups from Comodo (Defense+, thought I run Comodo Firewall, without the antivirus module) and I allowed all of the requests with the option to submit the files for analysis enabled. After the results came back, one file was detected as malware. I didn't recognize it so I cleaned it, only to find that it was related to the software I installed, and needed for it to uninstall. I considered a system restore, but I wanted to consider other options, so if anyone has an idea on how I can recover the file, I'd appreciate the help.

Thanks :glasses:
It was a COMODO cloud scanner alert?
image001iw.png

In the center of your screen?

And what software did you install? You think it was a false positive (the file was not actually malicious)?
Yeah, it was the cloud scanner that told me that, and I'm pretty sure it is a false positive. I installed the Snow Leopard Transformation pack from here
WOT says the site is safe, as you can see. Also, I think the reason Comodo detects it is the fact it changes so many of the settings and tries to modify System32.
Well, I don't have a Win7 virtual Machine to see if there is something malicious inside that archive. I generally do not like transformation packs myself. They change allot of system files and often cause stability issues.

If you are sure it is not malicious you could try re-installing it but this time go to Defense+ -> Defense+ Settings -> Execution Control Settings and disable "Perform cloud based behavior analysis" and "Automatically scan unrecognized files in the cloud" before you install it. You will still get Defense+ Pop-ups...make sure you answer them correctly but you won't get virus warnings.
to be honest I don't know if FP that is "cleaned" can be recovered. I am made some research and it seems to be okey but I will download it and report it as FP and see what I get for answer.

Regards
'Clean' as Comodo calls it, is actually delete. You could try Avira UnErase and see if that gets the file back, but it might not be able to, I have not studied the methods in which Comodo deletes files.
I have sent it to comodo labs and I will let you know if it's malware
Thanks guys, I'll try Avira's software, hopefully it works, because I can't uninstall the transformation pack with ease without it.
 

Dejan

New Member
Mar 3, 2011
559
Sorry for taking so long, I've been busy all day...
No, Avira can't find the file (or maybe it can, I didn't check the WHOLE list), same goes for Recuva. I might do a system restore, but then again, this transformation pack is pretty good. Anyway, mods can lock this if needed, for now I'm at a loss.
 

bogdan

Level 1
Thread author
Jan 7, 2011
1,362
Why don't you try re-installing it? (but disable the 2 options I've mentioned above so that CIS doesn't scan that file)
 

Valentin N

Level 2
Feb 25, 2011
1,314
if I am not mistaken it was the Mac transformation application or? if it the I can tell you that it's safe and okey.

Regards
 

Dejan

New Member
Mar 3, 2011
559
It's not about how safe it is, it's the fact that I can't uninstall the tranformation pack unless I have the file Comodo deleted. That was the main problem.
 

Chiron

Level 1
Feb 24, 2011
250
endejan said:
It's not about how safe it is, it's the fact that I can't uninstall the tranformation pack unless I have the file Comodo deleted. That was the main problem.

Can you repair the program?

Sometimes when you re-download the installer and go to install it it will give you the option to repair the version on your computer.
 

Dejan

New Member
Mar 3, 2011
559
Chiron said:
endejan said:
It's not about how safe it is, it's the fact that I can't uninstall the tranformation pack unless I have the file Comodo deleted. That was the main problem.

Can you repair the program?

Sometimes when you re-download the installer and go to install it it will give you the option to repair the version on your computer.

Sorry, no. I'll try and contact the guy who made it, or just do a system restore.
 

malbky

Level 1
Jun 23, 2011
1,011
Just do a system restore. The Snow Transformation pack is safe. Even Norton's download insight wrongly files it as malicious. So dont worry Endejan.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
I assume majority of security products have set on "a restore points" in case of problem for removing.
 

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
You do realise this topic is over a year old, 2011.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top