Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 19, 2010, 10:31:33 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
373096
Posts
41383
Topics
94057
Members
Latest Member:
nsane
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Virus/Malware Removal Assistance
SoulRock® ScriptSyntax
« previous
next »
Pages:
1
[
2
]
3
4
5
Author
Topic: SoulRock® ScriptSyntax (Read 20158 times)
martin11ph
Comodo Family Member
Offline
Posts: 96
Re: SoulRock® ScriptSyntax
«
Reply #15 on:
May 23, 2008, 12:33:59 PM »
Here is a screenshot with a larger detail tab.
Logged
martin11ph
Comodo Family Member
Offline
Posts: 96
Re: SoulRock® ScriptSyntax
«
Reply #16 on:
May 23, 2008, 12:35:22 PM »
Here is the command line:
"C:\WINDOWS\System32\WScript.exe" "C:\WINDOWS\ScriptSyntax.dll.vbs"
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
Offline
Posts: 5364
I'm not a complete idiot, some bits are missing.
Re: SoulRock® ScriptSyntax
«
Reply #17 on:
May 23, 2008, 12:39:30 PM »
Hmm.. and that previous shot you posted shows wscript.exe asking for things about C:\WINDOWS\ScriptSyntax.dll.vbs.. does that file exists? If so, please email to me (zipped). Thanks. Also check NOD32s virus definitions are up to date, it is monitoring this activity.
Logged
Windows 7 Ultimate x32 with CIS 3.14 & Firefox 3.6 & Becky! 2.54
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
martin11ph
Comodo Family Member
Offline
Posts: 96
Re: SoulRock® ScriptSyntax
«
Reply #18 on:
May 23, 2008, 12:43:12 PM »
I don't see the file in the Windows folder. I guess it appears only when it creates the file again. Yes NOD32 is updated.
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
Offline
Posts: 5364
I'm not a complete idiot, some bits are missing.
Re: SoulRock® ScriptSyntax
«
Reply #19 on:
May 23, 2008, 12:54:27 PM »
OK, it might still be a legitimate use. I assume you're running CFPs Defense+? We could deny wscript.exe access to.. well.. everything actually. It would obviously break what was using it & that might yield some useful information.. might not. But, it will certainly stop it.
Logged
Windows 7 Ultimate x32 with CIS 3.14 & Firefox 3.6 & Becky! 2.54
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
martin11ph
Comodo Family Member
Offline
Posts: 96
Re: SoulRock® ScriptSyntax
«
Reply #20 on:
May 23, 2008, 12:56:52 PM »
Err. . .I register it as a New Blocked Application in the firewall or terminate and quarantine in the defense+?
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
Offline
Posts: 5364
I'm not a complete idiot, some bits are missing.
Re: SoulRock® ScriptSyntax
«
Reply #21 on:
May 23, 2008, 01:01:25 PM »
I guess adding wscript.exe to your Quarantined files is the easiest to do & undo. I'm uncertain if having existing rules impacts this (never considered testing that). But, I'm sure you'd find out fairly quickly.
Logged
Windows 7 Ultimate x32 with CIS 3.14 & Firefox 3.6 & Becky! 2.54
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
martin11ph
Comodo Family Member
Offline
Posts: 96
Re: SoulRock® ScriptSyntax
«
Reply #22 on:
May 23, 2008, 01:02:33 PM »
Quote from: kail on May 23, 2008, 01:01:25 PM
I guess adding wscript.exe to your Quarantined files is the easiest to do & undo. I'm uncertain if having existing rules impacts this (never considered testing that). But, I'm sure you'd find out fairly quickly.
I don't quite get what you mean about the rules. Sorry.
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
Offline
Posts: 5364
I'm not a complete idiot, some bits are missing.
Re: SoulRock® ScriptSyntax
«
Reply #23 on:
May 23, 2008, 01:06:37 PM »
Sorry, nothing of importance. It will either work & block wscript.exe totally once its quarantined or it will not work.
Logged
Windows 7 Ultimate x32 with CIS 3.14 & Firefox 3.6 & Becky! 2.54
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
martin11ph
Comodo Family Member
Offline
Posts: 96
Re: SoulRock® ScriptSyntax
«
Reply #24 on:
May 23, 2008, 01:09:55 PM »
Well, I quarantined wscript.exe but the files are still created.
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
Offline
Posts: 5364
I'm not a complete idiot, some bits are missing.
Re: SoulRock® ScriptSyntax
«
Reply #25 on:
May 23, 2008, 01:12:43 PM »
Anything in the Defense+ Log? Check Process Explorer again.. wscript.exe still running?
Logged
Windows 7 Ultimate x32 with CIS 3.14 & Firefox 3.6 & Becky! 2.54
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
martin11ph
Comodo Family Member
Offline
Posts: 96
Re: SoulRock® ScriptSyntax
«
Reply #26 on:
May 23, 2008, 01:15:42 PM »
Defense + just shows the process monitor accessing the memory. wscript.exe is still in the process explorer but there is no more icon, description and company name.
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
Offline
Posts: 5364
I'm not a complete idiot, some bits are missing.
Re: SoulRock® ScriptSyntax
«
Reply #27 on:
May 23, 2008, 01:19:50 PM »
Yes, that's because Process Explorer cannot query it any more because CFP has quarantined it. I was going to suggest killing it, but I don't think CFP would let you do that! So, how about a reboot?
Logged
Windows 7 Ultimate x32 with CIS 3.14 & Firefox 3.6 & Becky! 2.54
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
martin11ph
Comodo Family Member
Offline
Posts: 96
Re: SoulRock® ScriptSyntax
«
Reply #28 on:
May 23, 2008, 01:27:11 PM »
Will you look a that. Delete and it stays deleted. Thanks a lot kail for guiding me the whole time. Really appreciate it.
Off-topic: How are you all so good at this? Is it experience,profession or maybe both? Coz you know, I am currently a computer engineering student, no major subjects yet though. Will we learn about this stuff as well?
«
Last Edit: May 23, 2008, 01:29:19 PM by martin11ph
»
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
Offline
Posts: 5364
I'm not a complete idiot, some bits are missing.
Re: SoulRock® ScriptSyntax
«
Reply #29 on:
May 23, 2008, 01:35:38 PM »
Quote from: martin11ph on May 23, 2008, 01:27:11 PM
Will you look a that. Delete and it stays deleted. Thanks a lot kail for guiding me the whole time. Really appreciate it.
Erm.. sorry, but we didn't actually fix it.. whatever it is. We merely broke it so it couldn't work anymore. You should check the Defense+ log now to see what tried to gain access to wscript.exe.
Quote from: martin11ph on May 23, 2008, 01:27:11 PM
..
Off-topic: How are you all so good at this? Is it experience,profession or maybe both? Coz you know, I am currently a computer engineering student, no major subjects yet though. Will we learn about this stuff as well?
I'm sorry, I don't know. I'm way too old to know what they teach you, or not, these days.
Someone.. younger.. might know.
I could call one of the younger Mods?
edit: Ooo sorry. Sort of both: Experience caused by Profession & a cat-like curiosity.
«
Last Edit: May 23, 2008, 01:45:57 PM by kail
»
Logged
Windows 7 Ultimate x32 with CIS 3.14 & Firefox 3.6 & Becky! 2.54
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
Tags:
Pages:
1
[
2
]
3
4
5
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 0.051 seconds with 16 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com