Welcome, Guest. Please login or register.
November 18, 2008, 06:04:15 PM

Login with username, password and session length

212222 Posts
24530 Topics
57711 Members

Latest Member: b.emmerich1

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Virus/Malware Removal Assistance
| | | |-+  Is This New/Unknown malware?
« previous next »
Pages: [1] Go Down Print
Author Topic: Is This New/Unknown malware?  (Read 1498 times)
panopticon
Newbie
*
Offline Offline

Posts: 2


« on: March 22, 2007, 02:10:27 PM »

I work for an attorney in my city, and my duties range from billable client work to a variety of general office tasks. Today I was asked to scrub one of his home computers of viruses and other malware.

First thing I noticed besides running slowly was that the computer had no firewall, and that his kids liked to download stuff off torrents. I fixed that with a download of Comodo. I then noticed that IE 6 acted funny by denying access to some sites (Yahoo, sometimes Google) but had no problems accessing other sites. I installed Firefox and had no problems from there. I also downloaded a host of anti-spyware programs and they cleaned up a number of adware and spyware programs.

I checked the computer's copy of Avast! antivirus and noted that it intercepted several viruses in the recent past... but once Comodo came online and started monitoring Web-enabled programs, I noticed that many of them were related to this system file:

C:WINDOWS\System32\sorcpnz.exe


Comodo would prompt me and tell me that sorcpnz.exe "has modified <program> in memory. This is typical of Virus, Trojan and Spyware behaviour." This included necessary programs such as Firefox and IE. I Googled and Yahoo'd sorcpnz and found nothing. Absolutely nothing!

So, is sorcpnz.exe a legitimate system file (I've never heard of it before, and never saw it reported on my own computer's copy of Comodo, or is it an as-yet unknown malware/virus program? Comodo had nothing on the sorcpnz either, but I made sure to send it to Comodo for analysis, as well as block further attempts to connect to the internet.

If anyone can help, please do so. I don't want to have to mindwipe my employer's computer if I don't have to.
« Last Edit: March 22, 2007, 02:43:20 PM by panopticon » Logged
Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6023



« Reply #1 on: March 22, 2007, 02:37:16 PM »

have you tried any online scanner, to see what they might come up with?

http://www.bitdefender.com/scan8/ie.html
http://housecall.trendmicro.com/
http://usa.kaspersky.com/services/free-virus-scanner.php

You can also submit the file tohttp://www.virustotal.com/en/indexx.html for checking and a response.

I didn't turn up anything on searches either, not even with full path, or filename only (with no extension).  I sure would be suspicious, though.  The rule of thumb with CFP and the ABA alerts like you're getting is that if you know the applications in question, you may safely allow.  If you do not know them, there may be a problem and it should be denied.

Can you manually quarantine the file with Antivir?

LM
Logged

date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
panopticon
Newbie
*
Offline Offline

Posts: 2


« Reply #2 on: March 22, 2007, 02:40:37 PM »

I'm running TrendMicro's utility right now. I'll post results when it's done. As for the programs in question, I recognized the vast majority of them, but sorcpnz has tried to modify nearly all of them. I'll see if Avast! can quarantine the file. Avast hasn't even identified it as a problem file. 
Logged
Soyabeaner
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7455



« Reply #3 on: March 22, 2007, 02:43:32 PM »

This topic should be moved from CFP Help to malware removal or something more fitting, but I don't know which one.

sorcpnz.exe is not on google Shocked

Try this thread: Good Removal Programs
Jotti: http://virusscan.jotti.org/
« Last Edit: March 22, 2007, 02:50:13 PM by Soya » Logged
Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6023



« Reply #4 on: March 22, 2007, 02:58:19 PM »

Try this thread: Good Removal Programs
I knew that was somewhere!

This topic should be moved from CFP Help to malware removal or something more fitting, but I don't know which one.
It is in malware removal...

LM
Logged

date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Rotty
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 793

http://www.venganza.org/ - Noodly Appendage


« Reply #5 on: March 23, 2007, 01:36:33 AM »

If you want to post a Hijackthis log, i am more than happy to look it over!!
Logged

The opinions expressed in my posts are my own. 
They do NOT necessarily represent or reflect the views of my employer.
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in -0.128 seconds with 19 queries.
Powered by SMF 1.1.7 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com