Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
November 18, 2008, 06:04:15 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
212222
Posts
24530
Topics
57711
Members
Latest Member:
b.emmerich1
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Virus/Malware Removal Assistance
Is This New/Unknown malware?
« previous
next »
Pages:
[
1
]
Author
Topic: Is This New/Unknown malware? (Read 1498 times)
panopticon
Newbie
Offline
Posts: 2
Is This New/Unknown malware?
«
on:
March 22, 2007, 02:10:27 PM »
I work for an attorney in my city, and my duties range from billable client work to a variety of general office tasks. Today I was asked to scrub one of his home computers of viruses and other malware.
First thing I noticed besides running slowly was that the computer had no firewall, and that his kids liked to download stuff off torrents. I fixed that with a download of Comodo. I then noticed that IE 6 acted funny by denying access to some sites (Yahoo, sometimes Google) but had no problems accessing other sites. I installed Firefox and had no problems from there. I also downloaded a host of anti-spyware programs and they cleaned up a number of adware and spyware programs.
I checked the computer's copy of Avast! antivirus and noted that it intercepted several viruses in the recent past... but once Comodo came online and started monitoring Web-enabled programs, I noticed that many of them were related to this system file:
C:WINDOWS\System32\
sorcpnz.exe
Comodo would prompt me and tell me that sorcpnz.exe "has modified <program> in memory. This is typical of Virus, Trojan and Spyware behaviour." This included necessary programs such as Firefox and IE. I Googled and Yahoo'd sorcpnz and found nothing. Absolutely nothing!
So, is sorcpnz.exe a legitimate system file (I've never heard of it before, and never saw it reported on my own computer's copy of Comodo, or is it an as-yet unknown malware/virus program? Comodo had nothing on the sorcpnz either, but I made sure to send it to Comodo for analysis, as well as block further attempts to connect to the internet.
If anyone can help, please do so. I don't want to have to mindwipe my employer's computer if I don't have to.
«
Last Edit: March 22, 2007, 02:43:20 PM by panopticon
»
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6023
Re: Is This New/Unknown malware?
«
Reply #1 on:
March 22, 2007, 02:37:16 PM »
have you tried any online scanner, to see what they might come up with?
http://www.bitdefender.com/scan8/ie.html
http://housecall.trendmicro.com/
http://usa.kaspersky.com/services/free-virus-scanner.php
You can also submit the file to
http://www.virustotal.com/en/indexx.html
for checking and a response.
I didn't turn up anything on searches either, not even with full path, or filename only (with no extension). I sure would be suspicious, though. The rule of thumb with CFP and the ABA alerts like you're getting is that if you know the applications in question, you may safely allow. If you do not know them, there may be a problem and it should be denied.
Can you manually quarantine the file with Antivir?
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
panopticon
Newbie
Offline
Posts: 2
Re: Is This New/Unknown malware?
«
Reply #2 on:
March 22, 2007, 02:40:37 PM »
I'm running TrendMicro's utility right now. I'll post results when it's done. As for the programs in question, I recognized the vast majority of them, but sorcpnz has tried to modify nearly all of them. I'll see if Avast! can quarantine the file. Avast hasn't even identified it as a problem file.
Logged
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 7455
Re: Is This New/Unknown malware?
«
Reply #3 on:
March 22, 2007, 02:43:32 PM »
This topic should be moved from CFP Help to malware removal or something more fitting, but I don't know which one.
sorcpnz.exe is not on google
Try this thread:
Good Removal Programs
Jotti:
http://virusscan.jotti.org/
«
Last Edit: March 22, 2007, 02:50:13 PM by Soya
»
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6023
Re: Is This New/Unknown malware?
«
Reply #4 on:
March 22, 2007, 02:58:19 PM »
Quote from: Soya on March 22, 2007, 02:43:32 PM
Try this thread:
Good Removal Programs
I knew that was somewhere!
Quote from: Soya on March 22, 2007, 02:43:32 PM
This topic should be moved from CFP Help to malware removal or something more fitting, but I don't know which one.
It is in malware removal...
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Rotty
Global Moderator
Comodo's Hero
Offline
Posts: 793
http://www.venganza.org/ - Noodly Appendage
Re: Is This New/Unknown malware?
«
Reply #5 on:
March 23, 2007, 01:36:33 AM »
If you want to post a Hijackthis log, i am more than happy to look it over!!
Logged
The opinions expressed in my posts are my own.
They do NOT necessarily represent or reflect the views of my employer.
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in -0.128 seconds with 19 queries.
Powered by SMF 1.1.7
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com