Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 20, 2010, 05:45:24 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
373168
Posts
41398
Topics
94082
Members
Latest Member:
francescobongiovannj
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Virus/Malware Removal Assistance
Heur.Pck.MoleBox
« previous
next »
Pages:
[
1
]
2
Author
Topic: Heur.Pck.MoleBox (Read 14038 times)
Wesly Gibson
Newbie
Offline
Posts: 2
Heur.Pck.MoleBox
«
on:
February 23, 2009, 03:15:11 PM »
Here we go again!! I hate viruses !!! poo!!
Heur.Pck.MoleBox this thing has me baffled..Can someone let me know how to get rid of this?? I used CIS to locate it CIS found it I deleted it and it comes right back I'll try and install a program and it says it doesnt recoginze it.....
Logged
lavenderpretty
Newbie
Offline
Posts: 3
Re: Heur.Pck.MoleBox
«
Reply #1 on:
February 23, 2009, 05:31:39 PM »
I got this same virus today from a progam called "folder lock 6". Been on my PC for a fews now and comodo just now red flaged it. Its shareware program I am using but I had it quarantine to be on the safe side. I had no problem with getting rid of it.
Logged
Wesly Gibson
Newbie
Offline
Posts: 2
Re: Heur.Pck.MoleBox
«
Reply #2 on:
February 24, 2009, 03:29:05 AM »
I still cant get rid of it..have you ever caught yourself saying I dont have time for this!!
Ive never had a monster like this while using CIS How did it get through a firewall and comodo without making some sort of racket to find out after it got inside I might be looking to RE/RE which I really dont have time for..Hmm
THEN it gets redflagged?? let me know if theres a way to remove it I did a scan and it found it Quaranteed it deleted it and it comes right back Hmm..
Logged
Kyle
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 3369
Re: Heur.Pck.MoleBox
«
Reply #3 on:
February 24, 2009, 03:32:13 AM »
Hey Wesly, Sorry about the troubles - Can you please PMessage me the download link?
I will have a look into it and see what can be done...
Untill then..This
may
be of some help to you..
You could try adding that file into the "my blocked files" inside of defense+, Setting Comodo to auto-quarintine so you don't get constant pop-ups.
In that same folder the malware is located, Click -> Tools -> Folder options -> View -> Show hidden files and folders.
It's possible that there is a hidden file in there..(Something like auto.inf)
«
Last Edit: February 24, 2009, 03:35:30 AM by Dr. Kyle
»
Logged
Windows XP
E5200 2.5ghz [at] 3.33ghz, POV 9800gt 512mb, 2gb DDR2 RAM. 500gb. HDD
Ubuntu
P4 [at] 3ghz, Radeon x300 128mb
1gb DDR2 Ram 80GB HDD
Jacob
Global Moderator
Comodo's Hero
Offline
Posts: 546
Re: Heur.Pck.MoleBox
«
Reply #4 on:
February 24, 2009, 03:34:33 AM »
Hello,
Have you tried:
Download & Install SuperantiSpyware (Free) From
http://downloads.superantispyware.com/downloads/SUPERAntiSpyware.exe
Updating It,
Then Restarting In Safe Mode, Then Doing A Complete Scan?
(To Boot In Safe Mode While Starting Up Hit F8 Then Choose Safe Mode)
Did This Help?
- Jacob
Logged
The Forum Policy
-My System Specs-
40 GB HD
1 GB RAM
WinXP Pro
tsec
Comodo Family Member
Offline
Posts: 99
Re: Heur.Pck.MoleBox
«
Reply #5 on:
February 24, 2009, 03:49:30 AM »
CIS just informed me that I had something similar inside a restore point...
Logged
jay2007tech
Malware Research Group
Comodo's Hero
Offline
Posts: 645
Re: Heur.Pck.MoleBox
«
Reply #6 on:
February 24, 2009, 09:25:55 PM »
If folder lock 6 is legit andwant it back do this
If you want folder lock 6 back and comodo to leave it alone Do this
To get Folder Lock 6 out of quarantine do this.
1)Go to the antivirus section in Comodo
2)If Antivirus realtime is on, disable it
3)Click on "quarantine iteams"
4)Highlight the program you want back "In this case, folder lock 6"
5)Now click the "Restore" button,NOW ITS BACK TO IT'S ORIGINAL SPOT
6)KEEP THE ANTIVIRUS REALTIME DISABLED, UNTIL YOU FINISH THE NEXT SECTION
Now to get comodo to leave "folder lock 6 alone"
1)Make sure antivirus realtime is disabled
2)Go to the antivurs section in comodo
3)click on "scanner settings"
4)Now click on "exclusions"
5)Now click on "add"
6)Now click on "browse"
7)Go find the file you want comodo to leave alone. (In this case it's folder lock 6)
8)Click ok
9)After the file you want is added to exclusion, go to "scanner settings"
10)Adjust the antivirus program back to realtime
11)exit comodo
12)Your done
===============================================================
To the other person
Quote
CIS just informed me that I had something similar inside a restore point...
delete all the system restore points, when sure that the virus is gone and doesn't come back, create a new system restore point
Generally viruses, spyware, trojans, etc that keep coming back. You should go to windows safe mode to clean the infections
«
Last Edit: February 24, 2009, 09:32:07 PM by jay2007tech
»
Logged
It's hard being a crooked Admin when the files won't pass an md5checksum test. But like any other good crooked Admin it can be done, it just takes time(and lots of it) and a few aspirins
hischild828
Newbie
Offline
Posts: 2
Re: Heur.Pck.MoleBox
«
Reply #7 on:
February 26, 2009, 07:34:57 AM »
I am so very new to all this and I think anti virus etc are very confusing BUT I do like Comodo BUT just now while trying to download think its called Flash Player and also update Adobe Reader and I got that Virus Heur. I wasn't surer what to do so I quarantined BUT now I can't find them (3) to remove. AM I in Big trouble??? The Virus Defense does say 3 three threats detected. There was also a "line" asking to accept ActiveX... not sure if that caused the problem. Any suggestions for this trouble
Logged
jay2007tech
Malware Research Group
Comodo's Hero
Offline
Posts: 645
Re: Heur.Pck.MoleBox
«
Reply #8 on:
February 26, 2009, 10:13:34 AM »
lets start here
Quote
I wasn't surer what to do so I quarantined BUT now I can't find them (3) to remove.
If you followed my step by steps in getting it out of quarantine , and the files are NOT there, then you must have somehow gave it permission to delete it when it first got detected
Quote
while trying to download think its called Flash Player and also update Adobe Reader and I got that Virus Heur
I guess the obvious question for this is where did you get the programs from ( WEBSITE ).
Quote
There was also a "line" asking to accept ActiveX... not sure if that caused the problem
That's sounds like internet explorer., For some program that pops up. Flash player can be used in a web browser for various stuff like , watch movies on youtube. <---an example
I haven't read anywhere elses here, someone thats having the same problem, I curios on where you downloaded from.
If its for the program itself that popped-up for an update, what website were you on when the pop-up occured
Lets start with that
Logged
It's hard being a crooked Admin when the files won't pass an md5checksum test. But like any other good crooked Admin it can be done, it just takes time(and lots of it) and a few aspirins
John Buchanan
Behold, There be dragons beyond these walls
Global Moderator
Comodo's Hero
Offline
Posts: 2744
Behold, there be Dragons here!
Re: Heur.Pck.MoleBox
«
Reply #9 on:
February 26, 2009, 10:23:24 AM »
Very much like IE7 (8 if updated).
The single bar asking to install the ActiveX - that was your browser requesting permission to run the application.
If this is from a valid site (i.e. adobe.com), it is safe to run.
The AV warning is probably a FP. If unsure, you can always test it with CIMA
http://camas.comodo.com/cgi-bin/submit
As Jay2007tech has asked, let's start there. What website?
Logged
Please follow
Comodo Forum Policy
Maximus III Formula, i7-860 [at] 3.7GHz, 8GB DDR3-1600, Win7 Ultimate x64
salmon
Malware Research Group
Comodo Family Member
Offline
Posts: 93
Re: Heur.Pck.MoleBox
«
Reply #10 on:
February 26, 2009, 12:29:45 PM »
Quote from: hischild828 on February 26, 2009, 07:34:57 AM
I am so very new to all this and I think anti virus etc are very confusing BUT I do like Comodo BUT just now while trying to download think its called Flash Player and also update Adobe Reader and I got that Virus Heur. I wasn't surer what to do so I quarantined BUT now I can't find them (3) to remove. AM I in Big trouble??? The Virus Defense does say 3 three threats detected. There was also a "line" asking to accept ActiveX... not sure if that caused the problem. Any suggestions for this trouble
I was download Adobe flash reader on high heuristics on file fox and it detected part of the file as it was downloading. It was a legit site. Not sure ifs its fixed now?
Logged
footerwsi
Newbie
Offline
Posts: 1
Re: Heur.Pck.MoleBox
«
Reply #11 on:
March 12, 2009, 11:02:45 AM »
Can someone tell me what this virus does. I just found it on my laptop running vista business? I have tried CIS to remove but it keeps re installing. What problems will this cause me?
And I need to figure out how to remove it as well. I'm not super techy.
Thanks!
Logged
jay2007tech
Malware Research Group
Comodo's Hero
Offline
Posts: 645
Re: Heur.Pck.MoleBox
«
Reply #12 on:
March 14, 2009, 04:17:19 PM »
Jabob wrote
Quote
Have you tried:
Download & Install SuperantiSpyware (Free) From
http://downloads.superantispyware.com/downloads/SUPERAntiSpyware.exe
Updating It,
Then Restarting In Safe Mode, Then Doing A Complete Scan?
(To Boot In Safe Mode While Starting Up Hit F8 Then Choose Safe Mode)
Did This Help?
After you do the scan and delete in safe mode, run it again to make sure its still gone
Also, go to "system restore and delete all the old system restore points, then create a new one.
To get to system restore "Click on START", Click on "All Files", Click on accessories, Click on System Tools
, Click on Sytem Restore"
P.S. sometimes "auslogic defrag" program shows up as Heur.Pck.MoleBox (just to let you know)
Logged
It's hard being a crooked Admin when the files won't pass an md5checksum test. But like any other good crooked Admin it can be done, it just takes time(and lots of it) and a few aspirins
pelokee
Newbie
Offline
Posts: 2
Re: Heur.Pck.MoleBox
«
Reply #13 on:
March 19, 2009, 01:46:36 PM »
I just got this while running a Quickbooks tutorial. I am still of the opinion that the new Heuristics engine is not yet up to scratch and am disabling it until these events stop popping up.
Logged
Old Techie
Newbie
Offline
Posts: 1
Re: Heur.Pck.MoleBox
«
Reply #14 on:
May 31, 2009, 08:51:01 PM »
I think that if you go to the Molebox website -
www.molebox.com
- you'll find that Molebox is an application virtualization application. (Yeah, I know "department of redundancy department") It enables an application to be installed without it having to be "installed." All of its required executables, support files, dll files, etc., are contained within one .exe, and no installer is required to be run.
SO, that being said, it can also be a rather subtle means of distributing malware, hence its detection (heuristically) as a virus. If Comodo AV is detecting a program that you use and know isn't a problem, just tell Comodo AV to ignore it, or to move it to your safe files.
On the other hand, remember that the internet can be a nasty, scary place, full of truly bad malware for your computer and act accordingly.
OT
Logged
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 0.073 seconds with 18 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com