Welcome, Guest. Please login or register.
October 12, 2008, 01:46:10 PM

Login with username, password and session length

199672 Posts
22924 Topics
55009 Members

Latest Member: vic6

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo BOClean Anti-Malware
| | |-+  Comodo BOClean Saved my day, even though I had an AV installed!!
« previous next »
Pages: [1] 2 3 Go Down Print
Author Topic: Comodo BOClean Saved my day, even though I had an AV installed!!  (Read 22437 times)
Eric Cryptid
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1090


Security Saskquatch


« on: April 27, 2007, 07:11:35 AM »

BOClean saved my **** today!

I Downloaded a Program from www.download.com which is usually really reliable. It was a program called EasyCash which I wanted for keeping track of my finances. I downloaded it with no detection from anything not CPF Nor Antivir PE Preimium nor Spyware Terminator and then click to install the program still no detection from the above and and then the installer didn't fully install / stopped and closed in the middle of copying files. I looked at my BOClean log to find!!!

04/27/2007 12:55:45: IFSKEYLOG17 MALWARE STOPPED by BOCLEAN!   
Trojan horse was found in memory.
C:\WINDOWS\IFINST27.EXE contained the trojan.
Active trojan horse WAS shut down. System now safe.
Logged in user: ******

OMG! Not even my Antivirus or anti-spyware caught that one! It stopped it and removed it before it had a chance to do anything!

I LOVE BOCLEAN!!!!!!!!!!!!!!!!!!!!



EDITED
******
topic splitted and Subject line modified to reflect the post..
« Last Edit: June 30, 2007, 09:46:39 AM by Melih » Logged

Cryptid - Any animal or creature that has been reported to have existed, but has not been proven to.

Security Fanatic

Please Read Forum Policy Before Posting - https://forums.comodo.com/new_member_information/forum_policy-t1516.0.html
FishStyx
Newbie
*
Offline Offline

Posts: 9


« Reply #1 on: April 27, 2007, 10:41:45 AM »

BOClean saved my **** today!

I Downloaded a Program from www.download.com which is usually really reliable. It was a program called EasyCash which I wanted for keeping track of my finances. I downloaded it with no detection from anything not CPF Nor Antivir PE Preimium nor Spyware Terminator and then click to install the program still no detection from the above and and then the installer didn't fully install / stopped and closed in the middle of copying files. I looked at my BOClean log to find!!!

04/27/2007 12:55:45: IFSKEYLOG17 MALWARE STOPPED by BOCLEAN!   
Trojan horse was found in memory.
C:\WINDOWS\IFINST27.EXE contained the trojan.
Active trojan horse WAS shut down. System now safe.
Logged in user: ******

OMG! Not even my Antivirus or anti-spyware caught that one! It stopped it and removed it before it had a chance to do anything!

I LOVE BOCLEAN!!!!!!!!!!!!!!!!!!!!

Very interesting.  I'm curious as to what IFinst27.exe is and why BOClean identifies it as malware.  I Google IFSKEYLOG17 and come up with nothing.  I Google IFinst27.exe and find the same "virus removal" thread on several support web sites, but no explanation of what IFinst27.exe is, no proof that IFinst27.exe was the problem, or that it is in fact malware.

The other applications didn't flag it because there seems to be no record of it.  Evidently no harm done in removing it, just wondering what it actually is...    Huh
« Last Edit: April 27, 2007, 06:13:58 PM by Melih » Logged

Comodo Firewall Pro 2.4 || Avast! 4.7 || Comodo BOClean 4.23
Ad-Aware SE Personal 1.06r1 || Spybot S&D 1.4 || Windows Defender
N.T.T.W.
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1124


A minute of your time can help many.


« Reply #2 on: April 27, 2007, 10:50:09 AM »

I only found one link that seemed useful:

http://www.castlecops.com/t171457-navil_toolbar.html

This seems to say that IFINST27.EXE is something to do with W32/Downloader.AOLK

 Smiler
« Last Edit: April 27, 2007, 06:14:14 PM by Melih » Logged

Post proelia praemia.
Die dulci fruere.
FishStyx
Newbie
*
Offline Offline

Posts: 9


« Reply #3 on: April 27, 2007, 11:05:08 AM »

I only found one link that seemed useful:

http://www.castlecops.com/t171457-navil_toolbar.html

This seems to say that IFINST27.EXE is something to do with W32/Downloader.AOLK

 Smiler

Thanks Anderow, good catch.  Looks like a browser hijack.
Good work BOClean!    Viva Comodo
« Last Edit: April 27, 2007, 06:14:31 PM by Melih » Logged

Comodo Firewall Pro 2.4 || Avast! 4.7 || Comodo BOClean 4.23
Ad-Aware SE Personal 1.06r1 || Spybot S&D 1.4 || Windows Defender
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 5695



WWW
« Reply #4 on: April 27, 2007, 05:41:40 PM »

Thanks Anderow, good catch.  Looks like a browser hijack.
Good work BOClean!    Viva Comodo


Now you know what we mean by saying:
You should have Comodo BOClean in addition to your AV products   Kewl

Its a tool that every PC should have no matter what AV they use!!! 

Melih
« Last Edit: April 27, 2007, 06:14:48 PM by Melih » Logged

oOeagleOo
Comodo Loves me
****
Offline Offline

Posts: 104


« Reply #5 on: April 27, 2007, 07:11:38 PM »

uhm when BOClean detects something, should it not then come with an alert.?

because it sounds like you didnt get an alrt and that the only way you did find out BOClean did find the trojan was because you looked in the BOClean log.

Or do you have "permanently hide traybar icon and alerts" on
Logged

Firewall : Comodo Firewall Pro V3. (With hips)
Anti Virus : Avira Antivir.
Anti Spyware: SUPERAntiSpyware Pro V4.0
mike6688
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2021


« Reply #6 on: April 27, 2007, 07:13:49 PM »

uhm when BOClean detects something, should it not then come with an alert.?

because it sounds like you didnt get an alrt and that the only way you did find out BOClean did find the trojan was because you looked in the BOClean log.

Or do you have "permanently hide traybar icon and alerts" on

Hi,

There is an option in Boclean for 'unattended cleanup and removal'.  With this enabled BOClean will noy display alerts.  If this is not enabled, you will be given an alert and an option for what you want to do.

Mike
Logged

C.O.M.O.D.O: CIS + SafeSurf | VEngine | TrustConnect | CRC
XP SP3 32bit | 2.16GHz | 2GB Ram
oOeagleOo
Comodo Loves me
****
Offline Offline

Posts: 104


« Reply #7 on: April 27, 2007, 07:29:06 PM »

Hi,

There is an option in Boclean for 'unattended cleanup and removal'.  With this enabled BOClean will noy display alerts.  If this is not enabled, you will be given an alert and an option for what you want to do.

Mike

ok  Cheers
Logged

Firewall : Comodo Firewall Pro V3. (With hips)
Anti Virus : Avira Antivir.
Anti Spyware: SUPERAntiSpyware Pro V4.0
Rednose
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 1329


Ganda's sleepy ( in his wildest dreams )


« Reply #8 on: April 27, 2007, 07:52:43 PM »

Now I am confused Undecided When you guys talk about the BOClean log, do you talk about the report you get when clicking " Examine report ", or about something else Huh

Greetz, Red.
Logged

XP 32x SP3  CFP 2.4  SSM 2.0 Free  Avast! 4.8 Home  CBOClean 4.27  CMF 2.0  SAS 4.21 Free  MBAM 1.28
oOeagleOo
Comodo Loves me
****
Offline Offline

Posts: 104


« Reply #9 on: April 27, 2007, 07:55:07 PM »

Now I am confused Undecided When you guys talk about the BOClean log, do you talk about the report you get when clicking " Examine report ", or about something else Huh

Greetz, Red.

I am talking about the "Examine report" because i think thats the one he is talking about  Nerd
Logged

Firewall : Comodo Firewall Pro V3. (With hips)
Anti Virus : Avira Antivir.
Anti Spyware: SUPERAntiSpyware Pro V4.0
Rednose
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 1329


Ganda's sleepy ( in his wildest dreams )


« Reply #10 on: April 27, 2007, 08:07:54 PM »

Yeah, that is what I thought too Smiley

Greetz, Red.
Logged

XP 32x SP3  CFP 2.4  SSM 2.0 Free  Avast! 4.8 Home  CBOClean 4.27  CMF 2.0  SAS 4.21 Free  MBAM 1.28
mike6688
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2021


« Reply #11 on: April 28, 2007, 12:02:22 PM »

ok  Cheers

No problem.  Wink    Cheers
Logged

C.O.M.O.D.O: CIS + SafeSurf | VEngine | TrustConnect | CRC
XP SP3 32bit | 2.16GHz | 2GB Ram
weaselthatbites
Newbie
*
Offline Offline

Posts: 14


« Reply #12 on: April 28, 2007, 02:44:24 PM »

Just downloaded the easy cash program from download.com...and it came out totally clean. Not only that...but there is no such file on my hard drive as described on my hard drive after installlation.


So where the heck did you get it from...lol. Either that or I downloaded the wrong program...
Logged
~cat~
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 964


CBO "...there is nothing better."


« Reply #13 on: April 28, 2007, 05:31:12 PM »

This one?
Easy Cash Manager 3.0.1
http://www.download.com/Easy-Cash-Manager/3000-2057_4-10642669.html
Logged

Parched dry and thirsty, knee deep in the river of life.
innerpeace
Comodo Family Member
***
Offline Offline

Posts: 55


« Reply #14 on: April 28, 2007, 11:17:04 PM »

I saw that program too. It has a bunch of downloads. The OP also mentioned a program called BestCash in another post. I think there is a little confusion with the name.

http://forums.comodo.com/index.php/topic,8348.msg60676.html#msg60676
I was going to download it an submit it to Jotti or VirusTotal to see if they found anything. Maybe the OP can do that and let us know what the filename is and the results.

Download dot com is not the best place to find software. Softpedia and MajorGeeks are much better and safer.  Wink
Logged
Tags:
Pages: [1] 2 3 Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.115 seconds with 19 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com