Author Topic: Win32:Dropper-LJP [Drp] during Comodo Firewall Setup - False Positive?  (Read 7919 times)

0 Members and 1 Guest are viewing this topic.

Offline cska133

  • Sr. Member
  • ****
  • Posts: 309
during the installation of Comodo firewall 5.10 (the same happens with version 5.12) Avast reported Win32:Dropper-LJP [Drp]. See screenshot
Comodo mods in the Comodo forum say this is false positive. The hashes of the installed setup are identical with these from Comodo official side.

does someone else have this alert or did one install CF 5.10 or 5.12 soonly?

how to proceed futher?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76039
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Win32:Dropper-LJP [Drp] during Comodo Firewall Setup - False Positive?
« Reply #1 on: January 25, 2013, 02:10:16 PM »
how to proceed futher?

Report it as a FP.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline cska133

  • Sr. Member
  • ****
  • Posts: 309
Re: Win32:Dropper-LJP [Drp] during Comodo Firewall Setup - False Positive?
« Reply #2 on: January 25, 2013, 03:06:39 PM »
where to report it?
and how can I (you) be sure that it is false positive?

iroc9555

  • Guest
Re: Win32:Dropper-LJP [Drp] during Comodo Firewall Setup - False Positive?
« Reply #3 on: January 25, 2013, 03:20:10 PM »
Report it here as a F/P: http://www.avast.com/contact-form.php?loadStyles

Must be if you are installing Comodo and both file open in temps while installing Comodo. However, all of this is true if you downloaded Comodo installer from its web site.

To tell you the truth I reinstalled Cfw 5.10 back at the end of december after trying out CIS 6, and I did not get any alert from Avast!; However, this could be a new detection added in Avast! VPS and that is why Asyn asked you to report it as a F/P and let avast! decides.

Offline cska133

  • Sr. Member
  • ****
  • Posts: 309
Re: Win32:Dropper-LJP [Drp] during Comodo Firewall Setup - False Positive?
« Reply #4 on: January 25, 2013, 05:54:06 PM »
   iroc9555

could you please upload somewhare your CF 5.10. PLEASE
I would like to compare the installers.
Send me the upload link in PM

iroc9555

  • Guest

Offline cska133

  • Sr. Member
  • ****
  • Posts: 309
Re: Win32:Dropper-LJP [Drp] during Comodo Firewall Setup - False Positive?
« Reply #6 on: January 25, 2013, 08:14:05 PM »
Quote
Report it here as a F/P: http://www.avast.com/contact-form.php?loadStyles
Well the tmp file is no longer avaiable so I can not send it to Avast by using the above link. Am I right? Or do I have to sent the Comodo installer?

iroc9555

  • Guest
Re: Win32:Dropper-LJP [Drp] during Comodo Firewall Setup - False Positive?
« Reply #7 on: January 25, 2013, 11:13:50 PM »
Quote
Report it here as a F/P: http://www.avast.com/contact-form.php?loadStyles
Well the tmp file is no longer avaiable so I can not send it to Avast by using the above link. Am I right? Or do I have to sent the Comodo installer?

Leave it like that. Try the link from FileHippo or the MediaFire link I gave you. If you still get the alert, click the part of the alert that says "Report the file as a false/positive" at the bottom of it then go to File System Shield and exclude the file to continue the installation.
« Last Edit: January 26, 2013, 12:00:10 AM by iroc9555 »

Offline securitest

  • Jr. Member
  • **
  • Posts: 33
Re: Win32:Dropper-LJP [Drp] during Comodo Firewall Setup - False Positive?
« Reply #8 on: January 27, 2013, 01:38:53 AM »
Avast :
program version : 7.0.1466
virus definition : 130126-1 (26 januray 2013, up-to-date)

I got the same virus alert
* virus found in CIS1.TMP
* virus type : WIN32:DROPPER-LJP [DRP]
* process : CMDINSTALL.EXE

when using the Comodo CIS installer : 5.10.228257.2253
MD5     : 8D25C043876A0FDBCED0443674D0E0E9
SHA-1   : 19A5936256E00F8470F6E173237C57F6818CFC9C
SHA-256 : 84FC4861DDBCB588601D993CFEF0338502FA6EA1DA6D0EFB74639B5678DADA5C
Size : 62 856 768 Bytes

In this post on the comodo forum :
http://forums.comodo.com/install-setup-configuration-help-cis/i-need-ciscf-510-or-512-t90635.0.html;msg653558#msg653558
you get a direct download link for this CIS 5.10 installer at :
http://www.cogneo.org/images/news/jan17/cispremium_installer_510.exe
(this is not a link on the comodo site since CIS 5.10 is not the latest CIS version)

I'll try to report it at
http://www.avast.com/contact-form.php?loadStyles

Offline securitest

  • Jr. Member
  • **
  • Posts: 33
Re: Win32:Dropper-LJP [Drp] during Comodo Firewall Setup - False Positive?
« Reply #9 on: January 27, 2013, 02:00:08 AM »
Unhappily when I try to report at http://www.avast.com/contact-form.php?loadStyles
each time I try, I get a 'The connection to the server was reset while the page was loading' from my browser.
So I can't report it for the moment.

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48334
  • 63 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Win32:Dropper-LJP [Drp] during Comodo Firewall Setup - False Positive?
« Reply #10 on: January 27, 2013, 02:27:15 AM »
Unhappily when I try to report at http://www.avast.com/contact-form.php?loadStyles
each time I try, I get a 'The connection to the server was reset while the page was loading' from my browser.
So I can't report it for the moment.
You didn't mention which browser you're using.

Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76039
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Win32:Dropper-LJP [Drp] during Comodo Firewall Setup - False Positive?
« Reply #11 on: January 27, 2013, 07:24:45 AM »
Unhappily when I try to report at http://www.avast.com/contact-form.php?loadStyles
each time I try, I get a 'The connection to the server was reset while the page was loading' from my browser.
So I can't report it for the moment.

You can also report it to: virus[at]avast.com
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

iroc9555

  • Guest
Re: Win32:Dropper-LJP [Drp] during Comodo Firewall Setup - False Positive?
« Reply #12 on: January 27, 2013, 03:14:54 PM »
Unhappily when I try to report at http://www.avast.com/contact-form.php?loadStyles
each time I try, I get a 'The connection to the server was reset while the page was loading' from my browser.
So I can't report it for the moment.

You can also report it to: virus[at]avast.com

...Or as I said above in reply # 7

...If you still get the alert, click the part of the alert that says "Report the file as a false/positive" at the bottom of it...

DrHaze

  • Guest
Re: Win32:Dropper-LJP [Drp] during Comodo Firewall Setup - False Positive?
« Reply #13 on: January 27, 2013, 08:47:15 PM »
Did anyone check to to see if this comodo installer was digitally signed? and have you or can you compared the file hashes?
I extracted the 5.12.2599 installer Digitally signed ‎Wednesday, ‎November ‎07, ‎2012 7:02:40 PM
and i found no alerts at all.
« Last Edit: January 27, 2013, 08:52:57 PM by DrHaze »

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48334
  • 63 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Win32:Dropper-LJP [Drp] during Comodo Firewall Setup - False Positive?
« Reply #14 on: January 27, 2013, 08:52:17 PM »
Did anyone check to to see if this comodo installer was digitally signed? and have you or can you compared the file hashes?
I extracted the 5.12.2599 installer Digitally signed ‎Wednesday, ‎November ‎07, ‎2012 7:02:40 PM
and i found no alerts at all.
And how does that relate to "connection to server reset"  ???
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet