Hi, I have an old machine, a pentium 4 2.8 with
windows xpsp2
avast 2014
comodo firewall 2.4
and many other old software and drivers as you understand.
I haven’t changed any software on my pc the last month and in general since I installed avast 2014, about a year ago, I only do updates on avast/spywareblaster/mozilla/flash, nothing else.
This is the report of a memory scan:
Process 612 [csrss.exe], memory block 0x0000000000000000, block size 655360 [E] The system cannot find the file specified (2)
Process 1444 [cpf.exe], memory block 0x0000000000400000, block size 7610368 (cpf.exe) [L] Win32:Evo-gen [Susp] (0)
Infected files: 1
Total files: 36807
Total folders: 1
Total size: 14.0 GB
- Scan stopped: Monday, November 09, 2015 7:01:15 AM
- Run-time was 6 minute(s), 6 second(s)
I discovered it by luck, I have no problems, it was a routine check, the previous ful scan was about a month ago, so I can’t tell if it is because of a certain update of the last days.
The only cpf.exe in my pc is this: C:\Program Files\Comodo\Firewall\cpf.exe
It’s the main exe of comodo firewall.
I did a full system scan with settings to check all files recognized by content, high heuristics and all packers selected. There is nothing else found, not even the actual cpf.exe which is obviously the file loaded on memory and found as virus. I also did a boot time scan and there is no infection, obviously because on boot time comodo firewall is not running.
I’m no expert but it must be a false positive. It has happened to me before with old software or drivers, but in those cases the supposed infected file was not a file loaded in memory. I was simply adding it to the exclusions till you fix the situation. I can’t exclude this.
I hope you will fix it soon.