Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 07, 2008, 11:53:08 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
198008
Posts
22789
Topics
54752
Members
Latest Member:
NaruZap
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Anti-Viruspyware (CAVS)
Virus/Malware Removal Assistance
bad malware...
« previous
next »
Pages:
[
1
]
Author
Topic: bad malware... (Read 2201 times)
ma3hd
Newbie
Offline
Posts: 5
bad malware...
«
on:
September 05, 2007, 03:40:57 AM »
Hello my dears...
i have an trojan when i open any site it download auto into my computer .... i have nod32 anti virus and i delete this trojan and i formatting my hard ..
put the trojan still appear when i browsing any site such that microsoft
trojan from 832821.com/ rr.html" (added 'space' after '/' to remove direct link (Garry))
832821.cn/ sysdown.exe (added 'space' after '/' to remove direct link (Garry))
i hope to help me
Edit: Removed WWW. to disable remaining link. N.T.T.W.
«
Last Edit: September 10, 2007, 09:06:07 AM by N.T.T.W.
»
Logged
N.T.T.W.
Global Moderator
Comodo's Hero
Offline
Posts: 1124
A minute of your time can help many.
Re: bad malware...
«
Reply #1 on:
September 05, 2007, 04:36:03 AM »
Hi ma3hd,
please could you post the name of the trojan deleted by nod32.
Do you get the trojan when viewing the website in your post - I get nothing from this site apart from a pop-up which is blocked by Firefox.
Logged
Post proelia praemia.
Die dulci fruere.
ma3hd
Newbie
Offline
Posts: 5
Re: bad malware...
«
Reply #2 on:
September 05, 2007, 05:10:37 AM »
thanks sir for fast reply....
trojan is more one...such as ...
sysdonwn.exe >>> trojan.delf.wh
win32/trojandownloader.ani.gen trojan
that i remember now...
Logged
~cat~
Global Moderator
Comodo's Hero
Offline
Posts: 964
CBO "...there is nothing better."
Re: bad malware...
«
Reply #3 on:
September 05, 2007, 05:14:09 AM »
Is BoClean installed?
Logged
Parched dry and thirsty, knee deep in the river of life.
ma3hd
Newbie
Offline
Posts: 5
Re: bad malware...
«
Reply #4 on:
September 05, 2007, 05:40:33 AM »
what it is BoClean ?...
i only have nod32 full verison with antispyware...
Logged
ma3hd
Newbie
Offline
Posts: 5
Re: bad malware...
«
Reply #5 on:
September 05, 2007, 05:42:03 AM »
and is it deny this trojan to hit me every time i open the browsing
Logged
N.T.T.W.
Global Moderator
Comodo's Hero
Offline
Posts: 1124
A minute of your time can help many.
Re: bad malware...
«
Reply #6 on:
September 05, 2007, 06:31:05 AM »
Quite a nasty trojan.
Do you currently use any Comodo products?
You could try installing BOClean:
http://www.comodo.com/boclean/boclean.html
I am not sure if this will remove this trojan but it is a great antimalware program that can also repair hosts files etc when it removes malware.
Comodo Firewall may also help as it should warn you about any connection attempts if your system is infected.
For removing this nasty with NOD32 (assuming NOD32 detects it) then you should first disable system restore on your computer and then run a full scan with NOD32.
Logged
Post proelia praemia.
Die dulci fruere.
ma3hd
Newbie
Offline
Posts: 5
Re: bad malware...
«
Reply #7 on:
September 05, 2007, 06:35:31 AM »
thanks sir for help ..
i install boclean ...and it never see the trojan ...before i install nod32 i used antivirus here ...
but trojan still appear ...
important note :
i used and dsl internet ( lan network ) ...i try to open my friend computer and i see also the trojan try to open itself ....and i try another computer in lan ...and i see this trojan ...
i think it from router of lan ....
is you have any idea to fixed it ?...
Logged
N.T.T.W.
Global Moderator
Comodo's Hero
Offline
Posts: 1124
A minute of your time can help many.
Re: bad malware...
«
Reply #8 on:
September 05, 2007, 07:17:19 AM »
As you are using NOD32 and you have said it detects the trojan your best bet may be to post on the forum for this product on Wilders:
http://www.wilderssecurity.com/forumdisplay.php?f=16
I am sure someone there will be able to help you with either removal or submitting the trojan.
I am surprised BOClean does not detect this malware. If you manage to obtain a copy of the trojan perhaps you would consider submitting it to Comodo to help improve detection in BOClean and CAVS:
You can email them to: malwaresubmit [ at ] avlab.comodo.com .
You may want to specify in the subject line "Malware?" for clarity's sake.
Zip and password protect the file with "infected" including that information in the email body.
Logged
Post proelia praemia.
Die dulci fruere.
nubiatech
Comodo Family Member
Offline
Posts: 70
Re: bad malware...
«
Reply #9 on:
September 05, 2007, 07:30:58 AM »
Quote from: ma3hd on September 05, 2007, 05:40:33 AM
what it is BoClean ?...
Sorry for the OT, but this is Boclean forum!!
And the websites you referenced are not the same:
832821
.com
/rr.html
832821
.cn
/sysdown.exe
And, what are the rules for posting direct links to malware?
Could a mod please look at this post to protect the innocent ...
Edit:
Forum Policy:
Quote
* Live Malware. Comodo is in the business of helping secure the internet, not propagating malware. Thus, it is not the appropriate place to attach or link live malware (viruses, trojans, rootkits, etc) to posts. In general, a link to the download site for 'malware' tests/demos and other 'proof of concept' applications are acceptable, provided they are not intended or designed to cause harm to a computer.
http://forums.comodo.com/new_member_information/forum_policy-t1516.0.html
EDIT: Removed WWW to disable remaining link. N.T.T.W
«
Last Edit: September 10, 2007, 08:59:27 AM by N.T.T.W.
»
Logged
garry
Comodo's Hero
Offline
Posts: 410
Re: bad malware...
«
Reply #10 on:
September 05, 2007, 07:51:35 AM »
Quote from: nubiatech on September 05, 2007, 07:30:58 AM
832821
.com
/rr.html
832821
.cn
/sysdown.exe
And, what are the rules for posting direct links to malware?
Could a mod please look at this post to protect the innocent ...
Hi,
I have added a 'space' after '/' to remove direct link.
Garry
EDIT: Removed WWW to disable remaining link. N.T.T.W
«
Last Edit: September 10, 2007, 08:58:53 AM by N.T.T.W.
»
Logged
Allan
Comodo Loves me
Offline
Posts: 196
Creating Trust Online
Re: bad malware...
«
Reply #11 on:
September 10, 2007, 08:24:51 AM »
Please Admin, to remove the link.
More Info:
REPORT SiteAdvisor
Thx,
Allan
Logged
N.T.T.W.
Global Moderator
Comodo's Hero
Offline
Posts: 1124
A minute of your time can help many.
Re: bad malware...
«
Reply #12 on:
September 10, 2007, 09:03:36 AM »
Quote from: Allan on September 10, 2007, 08:24:51 AM
Please Admin, to remove the link.
More Info:
REPORT SiteAdvisor
Thx,
Allan
I have removed the www to disable the links in these posts.
«
Last Edit: September 10, 2007, 09:05:55 AM by N.T.T.W.
»
Logged
Post proelia praemia.
Die dulci fruere.
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 1 seconds with 20 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com