Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 06, 2008, 08:44:59 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
197721
Posts
22760
Topics
54696
Members
Latest Member:
itman2000my
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo BOClean Anti-Malware
Comodo BOClean Saved my day, even though I had an AV installed!!
« previous
next »
Pages:
1
[
2
]
3
Author
Topic: Comodo BOClean Saved my day, even though I had an AV installed!! (Read 22072 times)
~cat~
Global Moderator
Comodo's Hero
Offline
Posts: 964
CBO "...there is nothing better."
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #15 on:
April 28, 2007, 11:31:42 PM »
Okay, I found "Best CashBook 3.3.3" there, not looking good...
Virus Total shows it as containing a Trojan/Worm (eSafe) and suspicious (Fortinet).
Complete scanning result of "BestCash333.exe", received in VirusTotal at 04.29.2007, 06:25:46 (CET).
File size: 3886592 bytes
MD5: 965d0b7ab870d2c40c4cca1699899705
SHA1: 95088ef7d73568eacd55afc903b6ed48b133ec47
packers: UPX
packers: UPX
packers: UPX
BOClean doesn't like it.
It drops IFNST27.exe into the Windows\prefetch
Drops IFinst27.exe keys at:
HKEY_USERS\S-1-5-21-823518204-651377827-839522115-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\WINDOWS
and
HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache
«
Last Edit: April 28, 2007, 11:49:53 PM by ~cat~
»
Logged
Parched dry and thirsty, knee deep in the river of life.
innerpeace
Comodo Family Member
Offline
Posts: 55
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #16 on:
April 29, 2007, 12:53:39 AM »
Thanks for posting a BOClean alert. Now I know what they look like. I installed boc and uninstalled because I'm trying other software and troubleshooting my cd/dvd burner
.
There are a lot of links about the exe, but the few I checked didn't give a definitive answer as whether is was truly bad or not. Seems a lot of people don't like it though. I believe I would avoid it.
http://fileinfo.prevx.com/QQ701d19146308-IFIN46439/IFINST27.EXE.html
http://www.castlecops.com/t171457-navil_toolbar.html
Logged
~cat~
Global Moderator
Comodo's Hero
Offline
Posts: 964
CBO "...there is nothing better."
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #17 on:
April 30, 2007, 03:24:32 PM »
Whoops! I forgot to follow up on this...
Kevin confirmed this to be a bad boy yesterday.
Logged
Parched dry and thirsty, knee deep in the river of life.
TonyKlein
Comodo Family Member
Offline
Posts: 85
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #18 on:
May 02, 2007, 02:28:29 PM »
Quote from: ~cat~ on April 30, 2007, 03:24:32 PM
Kevin confirmed this to be a bad boy yesterday.
Yup, it certainly is:
http://www.castlecops.com/tk30823-NavilToolbar_dll.html
Logged
Tony
CLSID List
-
Autostart Locations
Glendaloch
Newbie
Offline
Posts: 21
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #19 on:
May 06, 2007, 03:57:03 PM »
Well, Comodo BOClean saved the day for me. I downloaded a Zlob from MajorGeeks EU France.
05/06/2007 03:18:29: ZLOB256 MALWARE STOPPED by BOCLEAN!
Trojan horse was found in memory.
C:\PROGRAM FILES\K-MELEON\SETDEFAULT.EXE contained the trojan.
Active trojan horse WAS shut down. System now safe.
Logged in user: xxxxxxxx
CBOC jumped in as soon as it tried to execute. My Avira PE Premium spotted nothing so I'm very thankful that I had CBOC on the box. Sure there's an annoying update error message that pops up from time to time but I'm not complaining; the protection is top class. Who cares if there's an a harmless bug in the system when the application performs so well. It sure did what it's designed to do.
BTW, this particular trojan tried to thrash my internet connection (wireless); I've had no trouble since CBOC disposed of it. Looks like the automatic cleanup of my winsock worked as well.
Take a bow CBOC.
«
Last Edit: May 06, 2007, 04:00:20 PM by Glendaloch
»
Logged
~cat~
Global Moderator
Comodo's Hero
Offline
Posts: 964
CBO "...there is nothing better."
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #20 on:
May 06, 2007, 05:00:27 PM »
Was "SETDEFAULT.EXE" the name of the downloaded file?
They're pushing "K-Meleon1.1RC.exe" out currently.
Logged
Parched dry and thirsty, knee deep in the river of life.
LeoniAquila
Über Minimalist™ Defender of Resources Bloatware Fighter
Global Moderator
Comodo's Hero
Offline
Posts: 3498
Leone & Aquila
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #21 on:
May 07, 2007, 03:31:44 AM »
Actually, BOClean saved me too
(yesterday) from something that CAVS missed. It was an exe-file I got from a friend. UNFORTUNATELY I didn't save the log, thought it might be interesting for Comodo to add that virus (or whatever it was) definition to CAVS. But since BOClean picked it up I guess it's alright.
I was almost happy to get this virus:
Since I get malware so seldom, and I wanted to see how BOClean works, the program now performed detection and removal for me to watch. Well done, Comodo! I can't remember if I've ever seen a program really REMOVE malware before, so after the first "shock" I was just smiling and felt secure... Thanks Comodo!
Logged
» Windows XP Home Edition SP3 nLite
» COMODO Internet Security 3.5.52396.411
TonyKlein
Comodo Family Member
Offline
Posts: 85
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #22 on:
May 07, 2007, 05:54:54 AM »
Quote from: Glendaloch on May 06, 2007, 03:57:03 PM
05/06/2007 03:18:29: ZLOB256 MALWARE STOPPED by BOCLEAN!
Trojan horse was found in memory.
C:\PROGRAM FILES\K-MELEON\SETDEFAULT.EXE contained the trojan.
Active trojan horse WAS shut down. System now safe.
Still, you'd have to ask whether this was indeed a correct detection for K-Meleon's SetDefault.exe ... It would be worth while uploading that file to Virustotal in order to get a few second and third opinions:
http://www.virustotal.com/en/indexf.html
Logged
Tony
CLSID List
-
Autostart Locations
Glendaloch
Newbie
Offline
Posts: 21
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #23 on:
May 07, 2007, 10:30:08 AM »
Quote from: ~cat~ on May 06, 2007, 05:00:27 PM
Was "SETDEFAULT.EXE" the name of the downloaded file?
They're pushing "K-Meleon1.1RC.exe" out currently.
Cat, I can't say for sure.
Logged
~cat~
Global Moderator
Comodo's Hero
Offline
Posts: 964
CBO "...there is nothing better."
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #24 on:
May 07, 2007, 02:51:04 PM »
This one could go either way.
Quote
Complete scanning result of "SetDefault.exe", received in VirusTotal at 05.07.2007, 21:36:25 (CET).
eSafe 7.0.15.0 05.07.2007 suspicious Trojan/Worm
Fortinet 2.85.0.0 05.07.2007 suspicious
Ikarus T3.1.1.7 05.07.2007 Trojan-Downloader.Win32.Zlob.aiv
Webwasher-Gateway 6.0.1 05.07.2007 Win32.ModifiedUPX.gen!90 (suspicious)
File size: 82667 bytes
MD5: 50309924050783c5af19d9c7b17c9d21
SHA1: 868a0b0c28c8e070e4770ef982b61cfc9836a693
packers: UPX
packers: UPX, BINARYRES
packers: UPX
I've submitted it to Kevin and crew for ananlysis.
Logged
Parched dry and thirsty, knee deep in the river of life.
TonyKlein
Comodo Family Member
Offline
Posts: 85
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #25 on:
May 07, 2007, 03:02:50 PM »
By the looks of it it's mostly generic detection, probably because of the presence of certain packers. Very likely a FP, I'd say...
«
Last Edit: May 07, 2007, 03:51:14 PM by TonyKlein
»
Logged
Tony
CLSID List
-
Autostart Locations
FJR1300
Newbie
Offline
Posts: 8
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #26 on:
May 13, 2007, 11:07:10 AM »
Quote from: innerpeace on April 28, 2007, 11:17:04 PM
I saw that program too. It has a bunch of downloads. The OP also mentioned a program called BestCash in another post. I think there is a little confusion with the name.
http://forums.comodo.com/index.php/topic,8348.msg60676.html#msg60676
I was going to download it an submit it to Jotti or VirusTotal to see if they found anything. Maybe the OP can do that and let us know what the filename is and the results.
Download dot com is not the best place to find software. Softpedia and MajorGeeks are much better and safer.
Softpedia maybe safer but they charge you for downloads. If its just a few MP3s you want then bearshare or whatever is good enough because its free. Just make sure you use good security software to check the files.
Logged
innerpeace
Comodo Family Member
Offline
Posts: 55
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #27 on:
May 13, 2007, 10:28:58 PM »
Hi FJR1300, I have downloaded a few small freeware programs from Softpedia for free (no charge). Some of their programs you have to pay for. I do agree with you about scanning all downloaded programs. I use no less than 3 scanners on all downloads, even known security programs.
Cheers, innerpeace
Logged
sandybeach
Comodo Member
Offline
Posts: 29
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #28 on:
May 17, 2007, 12:37:19 AM »
I don't download anything via download.com. Made the mistake once, several years ago of 1 game and Spybot saved my tail then removing 40 some files. Not fair perhaps as Download.com doesn't write the software and other possible maneuvers may by- pass what checking they do/ have done. They have posted that they take no responsibility for quality or content of downloaded items.
In principle I prefer to download ONLY from an Authors site if at all possible. Next from mirrors listed on his/her site. Must admit I brought down a few from Mjr.G without problems 'tho sometimes the program may be a late beta (gotta watch out for that). JMHO.
Logged
wshaw
Newbie
Offline
Posts: 8
Re: Comodo BOClean Saved my day, even though I had an AV installed!!
«
Reply #29 on:
May 19, 2007, 10:37:18 AM »
Comodo BO CLEAN also saved my life.
I downloaded a weather report tool from the internet along with some bonus downloads and came out with the following report from BO-CLEAN. Comodo Anti-virus didn't detect it, nor did spybot search and destroy 1.4, or Ad-aware.
------------------------------
05/12/2007 21:48:36: SAVENOW3 MALWARE STOPPED by BOCLEAN!
Trojan horse was found in memory.
C:\DOCUME~1\WALLAC~1\LOCALS~1\TEMP\IS-8GSC2.TMP\VVSNINST.EXE contained the trojan.
Active trojan horse WAS shut down. System now safe.
Logged in user: Wallace Shaw
------------------------------
05/12/2007 21:48:50: WHENU/WSNI MALWARE STOPPED by BOCLEAN!
Trojan horse was found in memory.
C:\DOCUME~1\WALLAC~1\LOCALS~1\TEMP\IS-8GSC2.TMP\VVSNINST.EXE contained the trojan.
Active trojan horse WAS shut down. System now safe.
Logged in user: Wallace Shaw
COMODO BO-CLEAN ROCKS!
Wally Shaw
Logged
wshaw
Tags:
Pages:
1
[
2
]
3
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.106 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com