Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 21, 2010, 02:23:10 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
373366
Posts
41414
Topics
94139
Members
Latest Member:
robbie73
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Virus/Malware Removal Assistance
bad malware...
« previous
next »
Pages:
[
1
]
Author
Topic: bad malware... (Read 4250 times)
ma3hd
Newbie
Offline
Posts: 5
bad malware...
«
on:
September 05, 2007, 03:40:57 AM »
Hello my dears...
i have an trojan when i open any site it download auto into my computer .... i have nod32 anti virus and i delete this trojan and i formatting my hard ..
put the trojan still appear when i browsing any site such that microsoft
trojan from 832821.com/ rr.html" (added 'space' after '/' to remove direct link (Garry))
832821.cn/ sysdown.exe (added 'space' after '/' to remove direct link (Garry))
i hope to help me
Edit: Removed WWW. to disable remaining link. N.T.T.W.
«
Last Edit: September 10, 2007, 09:06:07 AM by N.T.T.W.
»
Logged
N.T.T.W.
Global Moderator
Comodo's Hero
Offline
Posts: 1124
A minute of your time can help many.
Re: bad malware...
«
Reply #1 on:
September 05, 2007, 04:36:03 AM »
Hi ma3hd,
please could you post the name of the trojan deleted by nod32.
Do you get the trojan when viewing the website in your post - I get nothing from this site apart from a pop-up which is blocked by Firefox.
Logged
Post proelia praemia.
Die dulci fruere.
ma3hd
Newbie
Offline
Posts: 5
Re: bad malware...
«
Reply #2 on:
September 05, 2007, 05:10:37 AM »
thanks sir for fast reply....
trojan is more one...such as ...
sysdonwn.exe >>> trojan.delf.wh
win32/trojandownloader.ani.gen trojan
that i remember now...
Logged
~cat~
Global Moderator
Comodo's Hero
Offline
Posts: 969
CBO "...there is nothing better."
Re: bad malware...
«
Reply #3 on:
September 05, 2007, 05:14:09 AM »
Is BoClean installed?
Logged
Parched dry and thirsty, knee deep in the river of life.
ma3hd
Newbie
Offline
Posts: 5
Re: bad malware...
«
Reply #4 on:
September 05, 2007, 05:40:33 AM »
what it is BoClean ?...
i only have nod32 full verison with antispyware...
Logged
ma3hd
Newbie
Offline
Posts: 5
Re: bad malware...
«
Reply #5 on:
September 05, 2007, 05:42:03 AM »
and is it deny this trojan to hit me every time i open the browsing
Logged
N.T.T.W.
Global Moderator
Comodo's Hero
Offline
Posts: 1124
A minute of your time can help many.
Re: bad malware...
«
Reply #6 on:
September 05, 2007, 06:31:05 AM »
Quite a nasty trojan.
Do you currently use any Comodo products?
You could try installing BOClean:
http://www.comodo.com/boclean/boclean.html
I am not sure if this will remove this trojan but it is a great antimalware program that can also repair hosts files etc when it removes malware.
Comodo Firewall may also help as it should warn you about any connection attempts if your system is infected.
For removing this nasty with NOD32 (assuming NOD32 detects it) then you should first disable system restore on your computer and then run a full scan with NOD32.
Logged
Post proelia praemia.
Die dulci fruere.
ma3hd
Newbie
Offline
Posts: 5
Re: bad malware...
«
Reply #7 on:
September 05, 2007, 06:35:31 AM »
thanks sir for help ..
i install boclean ...and it never see the trojan ...before i install nod32 i used antivirus here ...
but trojan still appear ...
important note :
i used and dsl internet ( lan network ) ...i try to open my friend computer and i see also the trojan try to open itself ....and i try another computer in lan ...and i see this trojan ...
i think it from router of lan ....
is you have any idea to fixed it ?...
Logged
N.T.T.W.
Global Moderator
Comodo's Hero
Offline
Posts: 1124
A minute of your time can help many.
Re: bad malware...
«
Reply #8 on:
September 05, 2007, 07:17:19 AM »
As you are using NOD32 and you have said it detects the trojan your best bet may be to post on the forum for this product on Wilders:
http://www.wilderssecurity.com/forumdisplay.php?f=16
I am sure someone there will be able to help you with either removal or submitting the trojan.
I am surprised BOClean does not detect this malware. If you manage to obtain a copy of the trojan perhaps you would consider submitting it to Comodo to help improve detection in BOClean and CAVS:
You can email them to: malwaresubmit [ at ] avlab.comodo.com .
You may want to specify in the subject line "Malware?" for clarity's sake.
Zip and password protect the file with "infected" including that information in the email body.
Logged
Post proelia praemia.
Die dulci fruere.
nubiatech
Comodo Family Member
Offline
Posts: 91
Re: bad malware...
«
Reply #9 on:
September 05, 2007, 07:30:58 AM »
Quote from: ma3hd on September 05, 2007, 05:40:33 AM
what it is BoClean ?...
Sorry for the OT, but this is Boclean forum!!
And the websites you referenced are not the same:
832821
.com
/rr.html
832821
.cn
/sysdown.exe
And, what are the rules for posting direct links to malware?
Could a mod please look at this post to protect the innocent ...
Edit:
Forum Policy:
Quote
* Live Malware. Comodo is in the business of helping secure the internet, not propagating malware. Thus, it is not the appropriate place to attach or link live malware (viruses, trojans, rootkits, etc) to posts. In general, a link to the download site for 'malware' tests/demos and other 'proof of concept' applications are acceptable, provided they are not intended or designed to cause harm to a computer.
http://forums.comodo.com/new_member_information/forum_policy-t1516.0.html
EDIT: Removed WWW to disable remaining link. N.T.T.W
«
Last Edit: September 10, 2007, 08:59:27 AM by N.T.T.W.
»
Logged
garry
Comodo's Hero
Offline
Posts: 410
Re: bad malware...
«
Reply #10 on:
September 05, 2007, 07:51:35 AM »
Quote from: nubiatech on September 05, 2007, 07:30:58 AM
832821
.com
/rr.html
832821
.cn
/sysdown.exe
And, what are the rules for posting direct links to malware?
Could a mod please look at this post to protect the innocent ...
Hi,
I have added a 'space' after '/' to remove direct link.
Garry
EDIT: Removed WWW to disable remaining link. N.T.T.W
«
Last Edit: September 10, 2007, 08:58:53 AM by N.T.T.W.
»
Logged
Allan
Comodo's Hero
Offline
Posts: 208
Creating Trust Online
Re: bad malware...
«
Reply #11 on:
September 10, 2007, 08:24:51 AM »
Please Admin, to remove the link.
More Info:
REPORT SiteAdvisor
Thx,
Allan
Logged
N.T.T.W.
Global Moderator
Comodo's Hero
Offline
Posts: 1124
A minute of your time can help many.
Re: bad malware...
«
Reply #12 on:
September 10, 2007, 09:03:36 AM »
Quote from: Allan on September 10, 2007, 08:24:51 AM
Please Admin, to remove the link.
More Info:
REPORT SiteAdvisor
Thx,
Allan
I have removed the www to disable the links in these posts.
«
Last Edit: September 10, 2007, 09:05:55 AM by N.T.T.W.
»
Logged
Post proelia praemia.
Die dulci fruere.
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 0.056 seconds with 18 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com