Welcome, Guest. Please login or register.
September 05, 2008, 06:15:45 AM

Login with username, password and session length

188549 Posts
21993 Topics
52780 Members

Latest Member: donzxc

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Anti-Viruspyware (CAVS)
| | |-+  Virus/Malware Removal Assistance
| | | |-+  Virus Sample!!!
« previous next »
Pages: [1] Go Down Print
Author Topic: Virus Sample!!!  (Read 1551 times)
bigben
Newbie
*
Offline Offline

Posts: 15


« on: December 12, 2007, 09:22:55 PM »

Hi... Comodo team.
Here i submit the virus sample (3 files attached, password: virus) to this forum. Because CAVS with Virus Database version: 2.0.0.371 cannot detect it. AntiVir PE detected as 'TR/Crypt.CFI.Gen'.
Sorry if i submit in the wrong room because i cannot find sticky thread to submit suspect virus.
Thank you.
« Last Edit: December 13, 2007, 02:24:27 AM by panic » Logged

OS: Win Vista Business x32, CFP 3.0.25.378, Comodo BackUp 1.0.4.337, Mozilla Firefox 3.0, Mozilla Thunderbird 2.0.0.14, FreePOPs v0.2.7, 7-Zip 4.58B, OpenOffice 2.4.1.
Ganda
president of anti-kyle coalition
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2726


teehee, peace


« Reply #1 on: December 12, 2007, 09:56:29 PM »

hi big ben  Wave
are you indonesian? maybe PCmedia AV can detects it? you can submit the sample via CAVS quarantine  menu
Logged

kyle is guilty Angry
everybody hate kyle Angry
let's all blame kyle Angry
evil prevails when kyle's around Angry
bigben
Newbie
*
Offline Offline

Posts: 15


« Reply #2 on: December 12, 2007, 11:41:16 PM »

Hi... Ganda. Yes I am Indonesian.   Smiler
Thx ur advice. Yes i submitted thru CAVS.
I can say that most of indonesian virus cannot be detected by CAVS. That's why if possible i'd like to submit for them to analyse.
Logged

OS: Win Vista Business x32, CFP 3.0.25.378, Comodo BackUp 1.0.4.337, Mozilla Firefox 3.0, Mozilla Thunderbird 2.0.0.14, FreePOPs v0.2.7, 7-Zip 4.58B, OpenOffice 2.4.1.
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5366


... and I say to myself, "What a wonderful world"


« Reply #3 on: December 13, 2007, 02:31:33 AM »

Hi... Comodo team.
Here i submit the virus sample (3 files attached, password: virus) to this forum. Because CAVS with Virus Database version: 2.0.0.371 cannot detect it. AntiVir PE detected as 'TR/Crypt.CFI.Gen'.
Sorry if i submit in the wrong room because i cannot find sticky thread to submit suspect virus.
Thank you.

While we appreciate your intentions, please do not post live virus samples on this public forum.

Please submit the samples thourgh the CAVS File Submission function in future.

Thanks in advance,
Ewen :-)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
bigben
Newbie
*
Offline Offline

Posts: 15


« Reply #4 on: December 14, 2007, 01:22:58 AM »

Yes sir mod panic...
Next time i will know, thx for ur editing post.

Today CAVS v2.0.17.58 with virus database version 2.0.0.372 already can detect as 'Worm.W32.VB.jr', cannot be disinfect but quarantined it.

Thx comodo research lab for fast action.

N.B.: I do not dare to infect to myself so I am sorry that I cannot tell you now the symptom of infection.
Logged

OS: Win Vista Business x32, CFP 3.0.25.378, Comodo BackUp 1.0.4.337, Mozilla Firefox 3.0, Mozilla Thunderbird 2.0.0.14, FreePOPs v0.2.7, 7-Zip 4.58B, OpenOffice 2.4.1.
Burillo
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 324


Bunghole


« Reply #5 on: December 14, 2007, 01:57:49 AM »

well you can try infecting a sandbox and see what files does it change... or infect a Virtual Machine, that's how i used to do... pretty effective - create a snapshot with the program like Ashampoo Uninstaller, infect and then create snapshot again and find the difference :-))
Logged

Some people are dumb... (c) Butt-head

Remember! CIA is watching you!
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5366


... and I say to myself, "What a wonderful world"


« Reply #6 on: December 14, 2007, 03:13:11 AM »

Yes sir mod panic...
Next time i will know, thx for ur editing post.

Today CAVS v2.0.17.58 with virus database version 2.0.0.372 already can detect as 'Worm.W32.VB.jr', cannot be disinfect but quarantined it.

Thx comodo research lab for fast action.

N.B.: I do not dare to infect to myself so I am sorry that I cannot tell you now the symptom of infection.

No problems - thanks for helping.

Ewen :-)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
Tags: virus sample 
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.512 seconds with 20 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com