Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
September 07, 2008, 12:51:20 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
189241
Posts
22043
Topics
52862
Members
Latest Member:
bmuth
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo BOClean Anti-Malware
Comodo BOClean Saved my day, even though I had an AV installed!!
« previous
next »
Pages:
[
1
]
2
3
Author
Topic: Comodo BOClean Saved my day, even though I had an AV installed!! (Read 20301 times)
Eric Cryptid
Global Moderator
Comodo's Hero
Offline
Posts: 1036
Security Saskquatch
Comodo BOClean Saved my day, even though I had an AV installed!!
«
on:
April 27, 2007, 07:11:35 AM »
BOClean saved my **** today!
I Downloaded a Program from
www.download.com
which is usually really reliable. It was a program called EasyCash which I wanted for keeping track of my finances. I downloaded it with no detection from anything not CPF Nor Antivir PE Preimium nor Spyware Terminator and then click to install the program still no detection from the above and and then the installer didn't fully install / stopped and closed in the middle of copying files. I looked at my BOClean log to find!!!
04/27/2007 12:55:45: IFSKEYLOG17 MALWARE STOPPED by BOCLEAN!
Trojan horse was found in memory.
C:\WINDOWS\IFINST27.EXE contained the trojan.
Active trojan horse WAS shut down. System now safe.
Logged in user: ******
OMG! Not even my Antivirus or anti-spyware caught that one! It stopped it and removed it before it had a chance to do anything!
I LOVE BOCLEAN!!!!!!!!!!!!!!!!!!!!
EDITED
******
topic splitted and Subject line modified to reflect the post..
«
Last Edit: June 30, 2007, 09:46:39 AM by Melih
»
Logged
Cryptid - Any animal or creature that has been reported to have existed, but has not been proven to.
Security Fanatic
Please Read Forum Policy Before Posting -
https://forums.comodo.com/new_member_information/forum_policy-t1516.0.html
FishStyx
Newbie
Offline
Posts: 9
Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #1 on:
April 27, 2007, 10:41:45 AM »
Quote from: EricEgan on April 27, 2007, 07:11:35 AM
BOClean saved my **** today!
I Downloaded a Program from
www.download.com
which is usually really reliable. It was a program called EasyCash which I wanted for keeping track of my finances. I downloaded it with no detection from anything not CPF Nor Antivir PE Preimium nor Spyware Terminator and then click to install the program still no detection from the above and and then the installer didn't fully install / stopped and closed in the middle of copying files. I looked at my BOClean log to find!!!
04/27/2007 12:55:45: IFSKEYLOG17 MALWARE STOPPED by BOCLEAN!
Trojan horse was found in memory.
C:\WINDOWS\IFINST27.EXE contained the trojan.
Active trojan horse WAS shut down. System now safe.
Logged in user: ******
OMG! Not even my Antivirus or anti-spyware caught that one! It stopped it and removed it before it had a chance to do anything!
I LOVE BOCLEAN!!!!!!!!!!!!!!!!!!!!
Very interesting. I'm curious as to what IFinst27.exe is and why BOClean identifies it as malware. I Google IFSKEYLOG17 and come up with nothing. I Google IFinst27.exe and find the same "virus removal" thread on several support web sites, but no explanation of what IFinst27.exe is, no proof that IFinst27.exe was the problem, or that it is in fact malware.
The other applications didn't flag it because there seems to be no record of it. Evidently no harm done in removing it, just wondering what it actually is...
«
Last Edit: April 27, 2007, 06:13:58 PM by Melih
»
Logged
Comodo Firewall Pro 2.4 || Avast! 4.7 || Comodo BOClean 4.23
Ad-Aware SE Personal 1.06r1 || Spybot S&D 1.4 || Windows Defender
N.T.T.W.
Global Moderator
Comodo's Hero
Offline
Posts: 1124
A minute of your time can help many.
Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #2 on:
April 27, 2007, 10:50:09 AM »
I only found one link that seemed useful:
http://www.castlecops.com/t171457-navil_toolbar.html
This seems to say that IFINST27.EXE is something to do with W32/Downloader.AOLK
«
Last Edit: April 27, 2007, 06:14:14 PM by Melih
»
Logged
Post proelia praemia.
Die dulci fruere.
FishStyx
Newbie
Offline
Posts: 9
Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #3 on:
April 27, 2007, 11:05:08 AM »
Quote from: Anderow on April 27, 2007, 10:50:09 AM
I only found one link that seemed useful:
http://www.castlecops.com/t171457-navil_toolbar.html
This seems to say that IFINST27.EXE is something to do with W32/Downloader.AOLK
Thanks Anderow, good catch. Looks like a browser hijack.
Good work BOClean!
«
Last Edit: April 27, 2007, 06:14:31 PM by Melih
»
Logged
Comodo Firewall Pro 2.4 || Avast! 4.7 || Comodo BOClean 4.23
Ad-Aware SE Personal 1.06r1 || Spybot S&D 1.4 || Windows Defender
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 5367
Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #4 on:
April 27, 2007, 05:41:40 PM »
Quote from: FishStyx on April 27, 2007, 11:05:08 AM
Thanks Anderow, good catch. Looks like a browser hijack.
Good work BOClean!
Now you know what we mean by saying:
You should have Comodo BOClean in addition to your AV products
Its a tool that every PC should have no matter what AV they use!!!
Melih
«
Last Edit: April 27, 2007, 06:14:48 PM by Melih
»
Logged
Visit Melih's Blog
oOeagleOo
Comodo Loves me
Offline
Posts: 104
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #5 on:
April 27, 2007, 07:11:38 PM »
uhm when BOClean detects something, should it not then come with an alert.?
because it sounds like you didnt get an alrt and that the only way you did find out BOClean did find the trojan was because you looked in the BOClean log.
Or do you have "permanently hide traybar icon and alerts" on
Logged
Firewall : Comodo Firewall Pro V3. (With hips)
Anti Virus : Avira Antivir.
Anti Spyware: SUPERAntiSpyware Pro V4.0
mike6688
Global Moderator
Comodo's Hero
Offline
Posts: 2013
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #6 on:
April 27, 2007, 07:13:49 PM »
Quote from: oOeagleOo on April 27, 2007, 07:11:38 PM
uhm when BOClean detects something, should it not then come with an alert.?
because it sounds like you didnt get an alrt and that the only way you did find out BOClean did find the trojan was because you looked in the BOClean log.
Or do you have "permanently hide traybar icon and alerts" on
Hi,
There is an option in Boclean for 'unattended cleanup and removal'. With this enabled BOClean will noy display alerts. If this is not enabled, you will be given an alert and an option for what you want to do.
Mike
Logged
C.O.M.O.D.O: CFP3 & Defence+ | CMF | VEngine | TrustConnect | CAVS 3 (soon)
XP SP3 32bit | 2.16GHz | 2GB Ram
oOeagleOo
Comodo Loves me
Offline
Posts: 104
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #7 on:
April 27, 2007, 07:29:06 PM »
Quote from: mike6688 on April 27, 2007, 07:13:49 PM
Hi,
There is an option in Boclean for 'unattended cleanup and removal'. With this enabled BOClean will noy display alerts. If this is not enabled, you will be given an alert and an option for what you want to do.
Mike
ok
Logged
Firewall : Comodo Firewall Pro V3. (With hips)
Anti Virus : Avira Antivir.
Anti Spyware: SUPERAntiSpyware Pro V4.0
Rednose
Comodo's Hero
Offline
Posts: 1278
Ganda's sleepy ( in his wildest dreams )
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #8 on:
April 27, 2007, 07:52:43 PM »
Now I am confused
When you guys talk about the BOClean log, do you talk about the report you get when clicking " Examine report ", or about something else
Greetz, Red.
Logged
XP 32x SP3 CFP 2.4 SSM 2.0 Free Avast! 4.8 Home CBOClean 4.27 CMF 2.0 SAS 4.15 Free MBAM 1.24
oOeagleOo
Comodo Loves me
Offline
Posts: 104
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #9 on:
April 27, 2007, 07:55:07 PM »
Quote from: Rednose on April 27, 2007, 07:52:43 PM
Now I am confused
When you guys talk about the BOClean log, do you talk about the report you get when clicking " Examine report ", or about something else
Greetz, Red.
I am talking about the "Examine report" because i think thats the one he is talking about
Logged
Firewall : Comodo Firewall Pro V3. (With hips)
Anti Virus : Avira Antivir.
Anti Spyware: SUPERAntiSpyware Pro V4.0
Rednose
Comodo's Hero
Offline
Posts: 1278
Ganda's sleepy ( in his wildest dreams )
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #10 on:
April 27, 2007, 08:07:54 PM »
Yeah, that is what I thought too
Greetz, Red.
Logged
XP 32x SP3 CFP 2.4 SSM 2.0 Free Avast! 4.8 Home CBOClean 4.27 CMF 2.0 SAS 4.15 Free MBAM 1.24
mike6688
Global Moderator
Comodo's Hero
Offline
Posts: 2013
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #11 on:
April 28, 2007, 12:02:22 PM »
Quote from: oOeagleOo on April 27, 2007, 07:29:06 PM
ok
No problem.
Logged
C.O.M.O.D.O: CFP3 & Defence+ | CMF | VEngine | TrustConnect | CAVS 3 (soon)
XP SP3 32bit | 2.16GHz | 2GB Ram
weaselthatbites
Newbie
Offline
Posts: 14
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #12 on:
April 28, 2007, 02:44:24 PM »
Just downloaded the easy cash program from download.com...and it came out totally clean. Not only that...but there is no such file on my hard drive as described on my hard drive after installlation.
So where the heck did you get it from...lol. Either that or I downloaded the wrong program...
Logged
~cat~
Global Moderator
Comodo's Hero
Offline
Posts: 964
CBO "...there is nothing better."
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #13 on:
April 28, 2007, 05:31:12 PM »
This one?
Easy Cash Manager 3.0.1
http://www.download.com/Easy-Cash-Manager/3000-2057_4-10642669.html
Logged
Parched dry and thirsty, knee deep in the river of life.
innerpeace
Comodo Family Member
Offline
Posts: 55
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #14 on:
April 28, 2007, 11:17:04 PM »
I saw that program too. It has a bunch of downloads. The OP also mentioned a program called BestCash in another post. I think there is a little confusion with the name.
http://forums.comodo.com/index.php/topic,8348.msg60676.html#msg60676
I was going to download it an submit it to Jotti or VirusTotal to see if they found anything. Maybe the OP can do that and let us know what the filename is and the results.
Download dot com is not the best place to find software. Softpedia and MajorGeeks are much better and safer.
Logged
Tags:
Pages:
[
1
]
2
3
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.228 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com