Welcome, Guest. Please login or register.
November 18, 2008, 05:46:45 PM

Login with username, password and session length

212218 Posts
24528 Topics
57708 Members

Latest Member: zebadee

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Virus/Malware Removal Assistance
| | | |-+  Downloader.Small.58.AG
« previous next »
Pages: [1] Go Down Print
Author Topic: Downloader.Small.58.AG  (Read 2538 times)
UK_DUDE
Newbie
*
Offline Offline

Posts: 19


« on: March 23, 2007, 10:35:11 AM »

Guess what.  I found a Trojan on my PC this morning in IE tempoary internet folder.  AVG found it, but Avast seemed to miss it!! 

Could the UDP scan have been something to do with the Trojan?
Logged
Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6023



« Reply #1 on: March 23, 2007, 10:43:28 AM »

I guess it could be...  it'd be nice to confirm, that's for sure.

What was the trojan you found?  And were you able to remove it?

LM
Logged

date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
UK_DUDE
Newbie
*
Offline Offline

Posts: 19


« Reply #2 on: March 23, 2007, 11:26:04 AM »

Can't remember the name off the top of my head (at work at the moment) but I'll post it when I get home.  It was in a file called 'click1'.  I tried googling the name but not alot of info could be found.

I usually use FF but sometimes use IE when FF is having problems displaying or running something.

I'm just a bit worried, as I've been using my online banking services.

I haven't deleted it, but it been flagged by AVG.  I'm temped just to delete it. 
Logged
Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6023



« Reply #3 on: March 23, 2007, 11:33:44 AM »

If AVG can't clean it, at least quarantine it, flag it to be blocked in the firewall, upload it to http://www.virustotal.com/en/indexx.html or http://virusscan.jotti.org/ (some online site) for analysis), etc.  You want to make sure you're protected.  Watch your bank accounts for changes.

It's always possible that it's a false positive; it does happen!  That's the problem with deleting files... they can be legit, and some malware uses the same filenames as legit ones, so it can be confusing.

LM
Logged

date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
UK_DUDE
Newbie
*
Offline Offline

Posts: 19


« Reply #4 on: March 23, 2007, 12:20:31 PM »

Hi.  Its called 'Downloader.Small.58.AG'.

Can AVG delete it safely?  In the Virus Vault there are action buttons 'Wipe' and 'Heal'.  I'll have to read the AVG help and see which one to press, if any.

How can I go about blocking it on Comodo? 
Logged
Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6023



« Reply #5 on: March 23, 2007, 01:28:09 PM »

UK_DUDE, in AVG, Wipe = Delete, Heal = Disinfect/Clean.  The Vault is the Quarantine; if it's in there you should be okay with it for the time being.

As far as how to block it in Comodo, this is what you'd do:
If the bugger has an executable file, you'll set an Application Monitor rule for it as the application.  "Skip" the parent.  Block.  Protocol TCP/UDP.  Any Destination IP/Port.  Leave Miscellaneous empty.  OK.
If the bugger doesn't have an executable (like it's a .dll or something), add it to Component Monitor.  You'll have to navigate to the path once the Add window opens.  Then set it to Block.  Press the Apply button.

Reboot computer.

Now, if indeed AVG has quarantined it (which sounds like, if it's in the Vault), you may not be able to access the file to add rules in CFP (shouldn't be able to, anyway!).  If you can, that's kinda scary about AVG's quarantining!  However, that's okay.  If you can't get to the file, it should be locked up where it is, and contained.

Do make a note of the filename and path, and keep an eye out for CFP to give you an alert that it's trying to use another application to get out (part of the Application Behavior Analysis).

LM

PS:  I separated this aspect of your issue from the original post (here:  http://forums.comodo.com/index.php/topic,7376.msg53831.html#msg53831 ), and moved it here for better, more appropriate coverage.
Logged

date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
UK_DUDE
Newbie
*
Offline Offline

Posts: 19


« Reply #6 on: March 23, 2007, 03:26:18 PM »

Much appreciated LittleMac.  Thanks for separating the thread.  Makes sense.

Well I've just wiped the two viruses that were in the Vault (had a trojan from a few months ago that seemed to come from a freeware net metering program).  I hope they've been deleted from my PC.

I've also had another flood attack this evening.  I managed to get Battlefield 2 working by forwarding some TCP/UDP ports and it seemed to happen when I was online playing BF2.  Sad

Arghh PC's their really doing my head in at the moment.  Embarrassed Embarrassed Tongue  Why is there so much nastiness in cyberspace?  Huh
Logged
Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6023



« Reply #7 on: March 23, 2007, 03:31:25 PM »

Have you followed up with any online scans?

http://housecall.trendmicro.com/
http://www.bitdefender.com/scan8/ie.html
http://usa.kaspersky.com/services/free-virus-scanner.php

There are others; those are just three...

Not being resident scanners, they can be a little more effective at times, and not be vulnerable to malware disabling them.  There's also some resources here:  http://forums.comodo.com/index.php/topic,4845.0.html

LM
« Last Edit: March 23, 2007, 03:33:02 PM by Little Mac » Logged

date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Soyabeaner
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7455



« Reply #8 on: March 23, 2007, 03:32:18 PM »

Why is there so much nastiness in cyberspace?  Huh
Because it's easy for the malware creators to spread them and they have too much time on their hands Nerd

How can I go about blocking it on Comodo? 
Comodo will only detect and block the actions of the trojan at the network level if it attempts to connect out, for example.  I thought trojans connect out, but why didn't this one?  There were no reports of an alert.  Is it either a lousy trojan or a false positive?  (or a cunning new one that can leak through CFP? Shocked)
« Last Edit: March 23, 2007, 03:42:13 PM by Soya » Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.388 seconds with 19 queries.
Powered by SMF 1.1.7 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com