Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 06, 2008, 06:51:03 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
197533
Posts
22748
Topics
54661
Members
Latest Member:
ahmadaakhan01
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo BOClean Anti-Malware
COMODO BOC thinks MIRC is a trojan?[Resolved]
« previous
next »
Pages:
[
1
]
Author
Topic: COMODO BOC thinks MIRC is a trojan?[Resolved] (Read 4512 times)
Toggie
Global Moderator
Comodo's Hero
Offline
Posts: 1256
"Oh, let me have just a little bit of peril"
COMODO BOC thinks MIRC is a trojan?[Resolved]
«
on:
April 22, 2007, 11:32:32 PM »
I just had a strange situation. When I launched MIRC, BOC popped up to state it was a Trojan. At that point Process Guard kicked in and terminated BOC, as it hasn't yet been given Terminate privileges.
Any thoughts?
Toggie
«
Last Edit: September 09, 2007, 11:58:50 AM by ~cat~
»
Logged
One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
Kevin McAleavey
Administrator
Comodo's Hero
Offline
Posts: 303
Snag a nasty? NO problem! =)
Re: COMODO BOC thinks MIRC is a trojan?
«
Reply #1 on:
April 22, 2007, 11:39:35 PM »
Yep ... that's correct. MIRC is *the* most frequently used core for what we call "pseudo-rootkits" to control bot networks because it's "legit" and therefore ignored by just about every anti-everything on the planet. Since you're deliberately using it, open BOClean's excluder and drag the icon for it to the excluder box (if you're not using Vista, you can drag a shortcut) and once it appears in there, close the excluder, close BOClean and restart it so it will pick up the fact that you want MIRC ignored and BOClean will leave you alone. Should *another* copy show up somewhere that you don't know about it, BOClean will let you know.
But that, and a few other "legit tools" were included because of their frequent use as the core of many exploits and malwares. Sorry, but absolutely necessary to do that ...
Logged
"I reject your reality and substitute my own." - (Adam Savage, "MYTHBUSTERS" TV show)
~cat~
Global Moderator
Comodo's Hero
Offline
Posts: 964
CBO "...there is nothing better."
Re: COMODO BOC thinks MIRC is a trojan?
«
Reply #2 on:
April 22, 2007, 11:42:11 PM »
This is the default action of BOC, if you use Mirc you must exclude it.
Edit: Found the reference (needs to be included in the FAQ/support documents).
MIRC DETECTION INFO, for users of BOClean
Whoops, link is out of date.
IMPORTANT CHANGE in BOClean engine as of this update. Many previous "pseudo-rootkits" have used a popular "chat program" called "MIRC" as the core of their "botnet" core. In almost every case, these rogue usages of the popular MIRC program have had unique factors which allowed us to detect those without interfering with legitimately-used MIRC chat software.
«
Last Edit: April 22, 2007, 11:46:30 PM by ~cat~
»
Logged
Parched dry and thirsty, knee deep in the river of life.
Toggie
Global Moderator
Comodo's Hero
Offline
Posts: 1256
"Oh, let me have just a little bit of peril"
Re: COMODO BOC thinks MIRC is a trojan?
«
Reply #3 on:
April 23, 2007, 12:52:21 AM »
Thanks for the replies, I hadn't come across that before.
Toggie
Logged
One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
Toggie
Global Moderator
Comodo's Hero
Offline
Posts: 1256
"Oh, let me have just a little bit of peril"
Re: COMODO BOC thinks MIRC is a trojan?
«
Reply #4 on:
April 26, 2007, 10:31:47 PM »
Unfortunately, adding MIRC to the 'exclude' list doesn't seem to be working.
I have the app listed in 'exclude' but BOC still wants to close the app when I launch it.
Toggie
Logged
One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
Bluesman
Comodo's Hero
Offline
Posts: 550
Only Amiga Makes It Possible
Re: COMODO BOC thinks MIRC is a trojan?
«
Reply #5 on:
April 27, 2007, 04:45:21 AM »
Quote from: Toggie on April 26, 2007, 10:31:47 PM
Unfortunately, adding MIRC to the 'exclude' list doesn't seem to be working.
I have the app listed in 'exclude' but BOC still wants to close the app when I launch it.
Toggie
I had the same problem, but I just closed BOC and restarted it, and now everything works just fine.
Logged
"The blues are the roots, everything else is the fruits" -Willie Dixon
malva00
Newbie
Offline
Posts: 12
Re: COMODO BOC thinks MIRC is a trojan?
«
Reply #6 on:
April 27, 2007, 12:22:04 PM »
When I opened up my mirc v6.21 for the first time after installing BOC, it worked fine and it's not in my excludes.
Is this normal?
Logged
malva00
Newbie
Offline
Posts: 12
Re: COMODO BOC thinks MIRC is a trojan?
«
Reply #7 on:
April 30, 2007, 06:57:46 PM »
is this the answer to my question?
"IMPORTANT CHANGE in BOClean engine as of this update. Many previous "pseudo-rootkits" have used a popular "chat program" called "MIRC" as the core of their "botnet" core. In almost every case, these rogue usages of the popular MIRC program have had unique factors which allowed us to detect those without interfering with legitimately-used MIRC chat software."
«
Last Edit: April 30, 2007, 07:01:50 PM by malva00
»
Logged
Toggie
Global Moderator
Comodo's Hero
Offline
Posts: 1256
"Oh, let me have just a little bit of peril"
Re: COMODO BOC thinks MIRC is a trojan?
«
Reply #8 on:
April 30, 2007, 10:49:44 PM »
I have to add MIRC to excludes, otherwise it's terminated...
Logged
One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
Scott B.
Comodo Family Member
Offline
Posts: 66
Re: COMODO BOC thinks MIRC is a trojan?
«
Reply #9 on:
May 04, 2007, 09:09:27 PM »
Then you probably really do have a Trojan. Because MiRC works fine with BOClean here... I do not have to exclude it or anything.
Uninstall MiRC, delete the entire directory, and use CCleaner or so to securely delete all traces of that directory. Reboot, Reinstall MiRC and see if that helps.
Logged
sojo
Newbie
Offline
Posts: 4
Re: COMODO BOC thinks MIRC is a trojan?
«
Reply #10 on:
August 08, 2007, 02:36:19 PM »
Quote from: Scott B. on May 04, 2007, 09:09:27 PM
Then you probably really do have a Trojan. Because MiRC works fine with BOClean here... I do not have to exclude it or anything.
Uninstall MiRC, delete the entire directory, and use CCleaner or so to securely delete all traces of that directory. Reboot, Reinstall MiRC and see if that helps.
I tried all that as I was having the same problem as Toggle and mIRC still doesn't work unless I exclude it. So I excluded it and now when I turn on my computer instead of going to the desktop it goes to the mIRC file. Anyway to fix that?
Logged
stradivariuus
Newbie
Offline
Posts: 4
Re: COMODO BOC thinks MIRC is a trojan?
«
Reply #11 on:
September 08, 2007, 05:40:07 PM »
It happened to me too. The Bo ate my Mirc. 1st time i thought something was there like a trojan and i reinstalled mirc. It's the official Mirc form
http://www.mirc.com/
So I installed it . I reopende it and imediately Bo ate it again. LOL
Then I went to Bo and red all the program . I found out the Exclude Area. Just took the mirc into it and now the 2 programs work wonderfully
Logged
~cat~
Global Moderator
Comodo's Hero
Offline
Posts: 964
CBO "...there is nothing better."
Re: COMODO BOC thinks MIRC is a trojan?
«
Reply #12 on:
September 09, 2007, 11:58:12 AM »
I'm going to lock the gate on this dead horse.
OP knows the drill.
Logged
Parched dry and thirsty, knee deep in the river of life.
Tags:
mirc
excluder
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.101 seconds with 18 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com