PDA

View Full Version : Freaking Comodo flagging suspicious .exe >_<



Winter_Wolf
2011-12-13, 07:44 PM
Edited in: Let the following be a lesson about blindly just doing things without considering the repercussions. Or just skip to the "Edit" at the bottom.

About 18:00 Comodo flagged this thing called "xle.exe" as potentially malicious and sandboxed it. I killed the process in task manager and deleted the file through Comodo. Now I'm paranoid, since I didn't find it otherwise and I'm not 100% sure that it's actually gone-gone.

Popped up when I went to memebase.com (Rage comics), and my web search has turned up all of one or two sites, both of which are unknown quantities as far as being legit or no. There were a couple other really suspicious things hanging out there with it. They had panda faces next to them and were nestled (according to Comodo) in the C: User (name) AppData folder. Which does not apparently exist when I go looking for it.

Has anyone else been there lately and if so has any warning popped up letting you know you caught something?

Edit: Now know this: I (probably) killed Windows Defender when I deleted those files, because I trusted Comodo to correctly tell me when something dangerous was trying to get into my system. While I'm not 100% sure that deleting xle.exe and the other "scanned online and flagged as malicious" files was definitely what did it, blaming it on coincidence is a bit convenient. I had to go back and do a previous restore point, which I very luckily did not disable/delete them all as I habitually do. Really, Comodo? Really? And I trusted you! :smallannoyed:

Destro_Yersul
2011-12-13, 11:35 PM
The AppData folder on PCs contains important files. It's 'hidden' by default, meaning you can't just go looking for it. So it actually does exist, but your computer doesn't want you to see it.

Winter_Wolf
2011-12-13, 11:45 PM
Yeah, I went and unhid it after the fact. Deleted the "dangerous suspicious ohNoez" .exe files through a panel in Comodo. Mainly because I couldn't find any info on the flagged .exe except on two sites claiming to be spyware removal application websites.

Figured it was more likely that they were planting the files in an attempt to solicit people to pay for their product which would conveniently remove them.

All is back as it was though, functionality wise. I haven't bothered to go back and look for it since restoring the system, and the .exe hasn't tried to fire since either, so I'm going to leave well enough alone and hope I didn't end up really borking something.

One thing I DO wonder though, why is there still stuff from Google (GoogleEarth and SketchUp) in there, among several other programs which I uninstalled many moons ago. I don't plan to touch them for fear of breaking something, but they seem to be just lurking there in an untrustworthy manner.