Welcome, Guest. Please login or register.
October 11, 2008, 09:37:58 AM

Login with username, password and session length

199207 Posts
22889 Topics
54937 Members

Latest Member: bdesilva

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Anti-Viruspyware (CAVS)
| | |-+  Virus/Malware Removal Assistance
| | | |-+  bad malware...
« previous next »
Pages: [1] Go Down Print
Author Topic: bad malware...  (Read 2217 times)
ma3hd
Newbie
*
Offline Offline

Posts: 5


« on: September 05, 2007, 03:40:57 AM »

Hello my dears...

i have an trojan when i open any site it download auto into my computer .... i have nod32 anti virus and i delete this trojan and i formatting my hard ..

put the trojan still appear when i browsing any site such that microsoft

trojan from 832821.com/ rr.html" (added 'space' after '/' to remove direct link (Garry))

832821.cn/ sysdown.exe (added 'space' after '/' to remove direct link (Garry))

i hope to help me

Edit: Removed WWW. to disable remaining link. N.T.T.W.
« Last Edit: September 10, 2007, 09:06:07 AM by N.T.T.W. » Logged
N.T.T.W.
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1124


A minute of your time can help many.


« Reply #1 on: September 05, 2007, 04:36:03 AM »

Hi ma3hd,

please could you post the name of the trojan deleted by nod32.

Do you get the trojan when viewing the website in your post - I get nothing from this site apart from a pop-up which is blocked by Firefox.

 Smiler
Logged

Post proelia praemia.
Die dulci fruere.
ma3hd
Newbie
*
Offline Offline

Posts: 5


« Reply #2 on: September 05, 2007, 05:10:37 AM »

thanks sir for fast reply....

trojan is more one...such as ...

sysdonwn.exe >>> trojan.delf.wh

win32/trojandownloader.ani.gen trojan
 
that i remember now...
Logged
~cat~
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 964


CBO "...there is nothing better."


« Reply #3 on: September 05, 2007, 05:14:09 AM »

Is BoClean installed?
Logged

Parched dry and thirsty, knee deep in the river of life.
ma3hd
Newbie
*
Offline Offline

Posts: 5


« Reply #4 on: September 05, 2007, 05:40:33 AM »

what it is BoClean ?...

i only have nod32 full verison with antispyware...
Logged
ma3hd
Newbie
*
Offline Offline

Posts: 5


« Reply #5 on: September 05, 2007, 05:42:03 AM »

and is it deny this trojan to hit me every time i open the browsing
Logged
N.T.T.W.
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1124


A minute of your time can help many.


« Reply #6 on: September 05, 2007, 06:31:05 AM »

Quite a nasty trojan.

Do you currently use any Comodo products?

You could try installing BOClean:

http://www.comodo.com/boclean/boclean.html

I am not sure if this will remove this trojan but it is a great antimalware program that can also repair hosts files etc when it removes malware.

Comodo Firewall may also help as it should warn you about any connection attempts if your system is infected.

For removing this nasty with NOD32 (assuming NOD32 detects it) then you should first disable system restore on your computer and then run a full scan with NOD32.
Logged

Post proelia praemia.
Die dulci fruere.
ma3hd
Newbie
*
Offline Offline

Posts: 5


« Reply #7 on: September 05, 2007, 06:35:31 AM »

thanks sir for help ..

i install boclean ...and it never see the trojan ...before i install nod32 i used antivirus here ...

but trojan still appear ...

important note :

i used and dsl internet ( lan network ) ...i try to open my friend computer and i see also the trojan try to open itself ....and i try another computer in lan ...and i see this trojan ...

i think it from router of lan ....

is you have any idea to fixed it ?...

Logged
N.T.T.W.
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1124


A minute of your time can help many.


« Reply #8 on: September 05, 2007, 07:17:19 AM »

As you are using NOD32 and you have said it detects the trojan your best bet may be to post on the forum for this product on Wilders:

http://www.wilderssecurity.com/forumdisplay.php?f=16

I am sure someone there will be able to help you with either removal or submitting the trojan.

I am surprised BOClean does not detect this malware. If you manage to obtain a copy of the trojan perhaps you would consider submitting it to Comodo to help improve detection in BOClean and CAVS:

You can email them to: malwaresubmit [ at ] avlab.comodo.com .
You may want to specify in the subject line "Malware?" for clarity's sake.
Zip and password protect the file with "infected" including that information in the email body.

 Smiler
Logged

Post proelia praemia.
Die dulci fruere.
nubiatech
Comodo Family Member
***
Offline Offline

Posts: 70


« Reply #9 on: September 05, 2007, 07:30:58 AM »

what it is BoClean ?...

Sorry for the OT, but this is Boclean forum!!

And the websites you referenced are not the same:
832821.com/rr.html
832821.cn/sysdown.exe

And, what are the rules for posting direct links to malware?
Could a mod please look at this post to protect the innocent ...

Edit:
Forum Policy:
Quote
    * Live Malware. Comodo is in the business of helping secure the internet, not propagating malware.  Thus, it is not the appropriate place to attach or link live malware (viruses, trojans, rootkits, etc) to posts.  In general, a link to the download site for 'malware' tests/demos and other 'proof of concept' applications are acceptable, provided they are not intended or designed to cause harm to a computer.

http://forums.comodo.com/new_member_information/forum_policy-t1516.0.html

EDIT: Removed WWW to disable remaining link. N.T.T.W
« Last Edit: September 10, 2007, 08:59:27 AM by N.T.T.W. » Logged
garry
Comodo's Hero
*****
Offline Offline

Posts: 410



« Reply #10 on: September 05, 2007, 07:51:35 AM »

832821.com/rr.html
832821.cn/sysdown.exe

And, what are the rules for posting direct links to malware?
Could a mod please look at this post to protect the innocent ...


Hi,

I have added a 'space' after '/' to remove direct link.

Garry

EDIT: Removed WWW to disable remaining link. N.T.T.W
« Last Edit: September 10, 2007, 08:58:53 AM by N.T.T.W. » Logged
Allan
Comodo Loves me
****
Offline Offline

Posts: 196


Creating Trust Online


WWW
« Reply #11 on: September 10, 2007, 08:24:51 AM »

Please Admin, to remove the link.

More Info:
REPORT SiteAdvisor

Thx,
Allan

 Nerd
Logged
N.T.T.W.
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1124


A minute of your time can help many.


« Reply #12 on: September 10, 2007, 09:03:36 AM »

Please Admin, to remove the link.

More Info:
REPORT SiteAdvisor

Thx,
Allan

 Nerd

I have removed the www to disable the links in these posts.  Smiley
« Last Edit: September 10, 2007, 09:05:55 AM by N.T.T.W. » Logged

Post proelia praemia.
Die dulci fruere.
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.133 seconds with 20 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com