Welcome, Guest. Please login or register.
January 08, 2010, 12:57:19 PM

Login with username, password and session length

349104 Posts
38584 Topics
87740 Members

Latest Member: janderson

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Virus/Malware Removal Assistance
| | | |-+  Virus Sample!!!
« previous next »
Pages: [1] Go Down Print
Author Topic: Virus Sample!!!  (Read 3708 times)
bigben
Comodo Member
**
Offline Offline

Posts: 29


« on: December 12, 2007, 09:22:55 PM »

Hi... Comodo team.
Here i submit the virus sample (3 files attached, password: virus) to this forum. Because CAVS with Virus Database version: 2.0.0.371 cannot detect it. AntiVir PE detected as 'TR/Crypt.CFI.Gen'.
Sorry if i submit in the wrong room because i cannot find sticky thread to submit suspect virus.
Thank you.
« Last Edit: December 13, 2007, 02:24:27 AM by panic » Logged

OS: Win Vista Business x32 SP2 & CIS 3.13.121240.574
ganda claus
soya's mentor
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5638


ho ho ho


« Reply #1 on: December 12, 2007, 09:56:29 PM »

hi big ben  Wave
are you indonesian? maybe PCmedia AV can detects it? you can submit the sample via CAVS quarantine  menu
Logged
bigben
Comodo Member
**
Offline Offline

Posts: 29


« Reply #2 on: December 12, 2007, 11:41:16 PM »

Hi... Ganda. Yes I am Indonesian.   Smiler
Thx ur advice. Yes i submitted thru CAVS.
I can say that most of indonesian virus cannot be detected by CAVS. That's why if possible i'd like to submit for them to analyse.
Logged

OS: Win Vista Business x32 SP2 & CIS 3.13.121240.574
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7738


... and I say to myself, "What a wonderful world"


« Reply #3 on: December 13, 2007, 02:31:33 AM »

Hi... Comodo team.
Here i submit the virus sample (3 files attached, password: virus) to this forum. Because CAVS with Virus Database version: 2.0.0.371 cannot detect it. AntiVir PE detected as 'TR/Crypt.CFI.Gen'.
Sorry if i submit in the wrong room because i cannot find sticky thread to submit suspect virus.
Thank you.

While we appreciate your intentions, please do not post live virus samples on this public forum.

Please submit the samples thourgh the CAVS File Submission function in future.

Thanks in advance,
Ewen :-)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
bigben
Comodo Member
**
Offline Offline

Posts: 29


« Reply #4 on: December 14, 2007, 01:22:58 AM »

Yes sir mod panic...
Next time i will know, thx for ur editing post.

Today CAVS v2.0.17.58 with virus database version 2.0.0.372 already can detect as 'Worm.W32.VB.jr', cannot be disinfect but quarantined it.

Thx comodo research lab for fast action.

N.B.: I do not dare to infect to myself so I am sorry that I cannot tell you now the symptom of infection.
Logged

OS: Win Vista Business x32 SP2 & CIS 3.13.121240.574
Burillo
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 324


Bunghole


« Reply #5 on: December 14, 2007, 01:57:49 AM »

well you can try infecting a sandbox and see what files does it change... or infect a Virtual Machine, that's how i used to do... pretty effective - create a snapshot with the program like Ashampoo Uninstaller, infect and then create snapshot again and find the difference :-))
Logged

Some people are dumb... (c) Butt-head

Remember! CIA is watching you!
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7738


... and I say to myself, "What a wonderful world"


« Reply #6 on: December 14, 2007, 03:13:11 AM »

Yes sir mod panic...
Next time i will know, thx for ur editing post.

Today CAVS v2.0.17.58 with virus database version 2.0.0.372 already can detect as 'Worm.W32.VB.jr', cannot be disinfect but quarantined it.

Thx comodo research lab for fast action.

N.B.: I do not dare to infect to myself so I am sorry that I cannot tell you now the symptom of infection.

No problems - thanks for helping.

Ewen :-)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
Tags: virus sample 
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.039 seconds with 17 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com