Welcome, Guest. Please login or register.
March 19, 2010, 10:31:33 PM

Login with username, password and session length

373096 Posts
41383 Topics
94057 Members

Latest Member: nsane

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Virus/Malware Removal Assistance
| | |-+  SoulRock® ScriptSyntax
« previous next »
Pages: 1 [2] 3 4 5 Go Down Print
Author Topic: SoulRock® ScriptSyntax  (Read 20158 times)
martin11ph
Comodo Family Member
***
Offline Offline

Posts: 96



« Reply #15 on: May 23, 2008, 12:33:59 PM »

Here is a screenshot with a larger detail tab.
Logged
martin11ph
Comodo Family Member
***
Offline Offline

Posts: 96



« Reply #16 on: May 23, 2008, 12:35:22 PM »

Here is the command line:
"C:\WINDOWS\System32\WScript.exe" "C:\WINDOWS\ScriptSyntax.dll.vbs"
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5364


I'm not a complete idiot, some bits are missing.


« Reply #17 on: May 23, 2008, 12:39:30 PM »

Hmm.. and that previous shot you posted shows wscript.exe asking for things about C:\WINDOWS\ScriptSyntax.dll.vbs.. does that file exists? If so, please email to me (zipped). Thanks. Also check NOD32s virus definitions are up to date, it is monitoring this activity.
Logged

Windows 7 Ultimate x32 with CIS 3.14 & Firefox 3.6 & Becky! 2.54
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
martin11ph
Comodo Family Member
***
Offline Offline

Posts: 96



« Reply #18 on: May 23, 2008, 12:43:12 PM »

I don't see the file in the Windows folder. I guess it appears only when it creates the file again. Yes NOD32 is updated.
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5364


I'm not a complete idiot, some bits are missing.


« Reply #19 on: May 23, 2008, 12:54:27 PM »

OK, it might still be a legitimate use. I assume you're running CFPs Defense+? We could deny wscript.exe access to.. well.. everything actually. It would obviously break what was using it & that might yield some useful information.. might not. But, it will certainly stop it.
Logged

Windows 7 Ultimate x32 with CIS 3.14 & Firefox 3.6 & Becky! 2.54
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
martin11ph
Comodo Family Member
***
Offline Offline

Posts: 96



« Reply #20 on: May 23, 2008, 12:56:52 PM »

Err. . .I register it as a New Blocked Application in the firewall or terminate and quarantine in the defense+?
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5364


I'm not a complete idiot, some bits are missing.


« Reply #21 on: May 23, 2008, 01:01:25 PM »

I guess adding wscript.exe to your Quarantined files is the easiest to do & undo. I'm uncertain if having existing rules impacts this (never considered testing that). But, I'm sure you'd find out fairly quickly. Smiley
Logged

Windows 7 Ultimate x32 with CIS 3.14 & Firefox 3.6 & Becky! 2.54
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
martin11ph
Comodo Family Member
***
Offline Offline

Posts: 96



« Reply #22 on: May 23, 2008, 01:02:33 PM »

I guess adding wscript.exe to your Quarantined files is the easiest to do & undo. I'm uncertain if having existing rules impacts this (never considered testing that). But, I'm sure you'd find out fairly quickly. Smiley

I don't quite get what you mean about the rules. Sorry. Embarrassed
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5364


I'm not a complete idiot, some bits are missing.


« Reply #23 on: May 23, 2008, 01:06:37 PM »

Sorry, nothing of importance. It will either work & block wscript.exe totally once its quarantined or it will not work.
Logged

Windows 7 Ultimate x32 with CIS 3.14 & Firefox 3.6 & Becky! 2.54
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
martin11ph
Comodo Family Member
***
Offline Offline

Posts: 96



« Reply #24 on: May 23, 2008, 01:09:55 PM »

Well, I quarantined wscript.exe but the files are still created.
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5364


I'm not a complete idiot, some bits are missing.


« Reply #25 on: May 23, 2008, 01:12:43 PM »

Anything in the Defense+ Log? Check Process Explorer again.. wscript.exe still running?
Logged

Windows 7 Ultimate x32 with CIS 3.14 & Firefox 3.6 & Becky! 2.54
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
martin11ph
Comodo Family Member
***
Offline Offline

Posts: 96



« Reply #26 on: May 23, 2008, 01:15:42 PM »

Defense + just shows the process monitor accessing the memory. wscript.exe is still in the process explorer but there is no more icon, description and company name.
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5364


I'm not a complete idiot, some bits are missing.


« Reply #27 on: May 23, 2008, 01:19:50 PM »

Yes, that's because Process Explorer cannot query it any more because CFP has quarantined it. I was going to suggest killing it, but I don't think CFP would let you do that! So, how about a reboot?
Logged

Windows 7 Ultimate x32 with CIS 3.14 & Firefox 3.6 & Becky! 2.54
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
martin11ph
Comodo Family Member
***
Offline Offline

Posts: 96



« Reply #28 on: May 23, 2008, 01:27:11 PM »

Will you look a that. Delete and it stays deleted. Thanks a lot kail for guiding me the whole time. Really appreciate it. Viva Comodo

Off-topic: How are you all so good at this? Is it experience,profession or maybe both? Coz you know, I am currently a computer engineering student, no major subjects yet though. Will we learn about this stuff as well?
« Last Edit: May 23, 2008, 01:29:19 PM by martin11ph » Logged
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5364


I'm not a complete idiot, some bits are missing.


« Reply #29 on: May 23, 2008, 01:35:38 PM »

Will you look a that. Delete and it stays deleted. Thanks a lot kail for guiding me the whole time. Really appreciate it.
Erm.. sorry, but we didn't actually fix it.. whatever it is. We merely broke it so it couldn't work anymore. You should check the Defense+ log now to see what tried to gain access to wscript.exe.

..
Off-topic: How are you all so good at this? Is it experience,profession or maybe both? Coz you know, I am currently a computer engineering student, no major subjects yet though. Will we learn about this stuff as well?
I'm sorry, I don't know. I'm way too old to know what they teach you, or not, these days.  Laugh Someone.. younger.. might know. Smiley I could call one of the younger Mods? Grin

edit: Ooo sorry. Sort of both: Experience caused by Profession & a cat-like curiosity.
« Last Edit: May 23, 2008, 01:45:57 PM by kail » Logged

Windows 7 Ultimate x32 with CIS 3.14 & Firefox 3.6 & Becky! 2.54
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
Tags:
Pages: 1 [2] 3 4 5 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.051 seconds with 16 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com