Author Topic: probably bypass CIMA  (Read 19573 times)

Offline a256886572008

  • Star Group
  • Comodo's Hero
  • *****
  • Posts: 963
probably bypass CIMA
« on: May 05, 2011, 05:11:17 AM »
1.
http://camas.comodo.com/cgi-bin/ ... c4d9a18a3b7a6fd05c6

no actions detected

Quote
2011-05-05 16:30:56   C:\Documents and Settings\Roger\桌面\virus\movie.avi\Hnf.exe   Sandboxed As   Partially Limited 
 
2011-05-05 16:30:57   C:\Documents and Settings\Roger\Local Settings\Temp\sshnas21.dll   Sandboxed As   Partially Limited
   
2011-05-05 16:31:04   C:\Documents and Settings\Roger\桌面\virus\movie.avi\Hnf.exe   Modify File   C:\WINDOWS\system32\sshnas21.dll 
 
2011-05-05 16:31:04   C:\Documents and Settings\Roger\桌面\virus\movie.avi\Hnf.exe   Modify Key   HKLM\SYSTEM\ControlSet001\Services\SSHNAS 
 
2011-05-05 16:31:04   C:\Documents and Settings\Roger\Local Settings\Temp\sshnas21.dll   Access Memory   System   

2.
http://camas.comodo.com/cgi-bin/submit?file=24b0fcb16e677bf84867b5cd7ddb56e9a5e37475ca45e3c435356e6fc93365da

no actions detected


Quote
2011-05-05 16:39:04   C:\Documents and Settings\Roger\桌面\virus\movie.avi\Hng.exe   Sandboxed As   Partially Limited   

2011-05-05 16:39:10   C:\Documents and Settings\Roger\桌面\virus\movie.avi\Hng.exe   Modify File   C:\WINDOWS\Tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job   

2011-05-05 16:39:27   C:\Documents and Settings\Roger\桌面\virus\movie.avi\Hng.exe   Modify Key   HKUS\S-1-5-21-2000478354-583907252-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\   

2011-05-05 16:39:34   C:\Documents and Settings\Roger\桌面\virus\movie.avi\Hng.exe   Modify Key   HKUS\S-1-5-21-2000478354-583907252-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable

3.
http://camas.comodo.com/cgi-bin/submit?file=0318362813d8d2b4fc22de49cbeea586eeb6f2a407d0b892ff2da53bc455b103

no actions detected

Quote
2011-05-05 16:42:30   C:\Documents and Settings\Roger\桌面\virus\movie.avi\Hnh.exe   Sandboxed As   Partially Limited
 
2011-05-05 16:42:42   C:\Documents and Settings\Roger\桌面\virus\movie.avi\Hnh.exe   Modify Key   HKUS\S-1-5-21-2000478354-583907252-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run\R8388QA8U8

 

Seo4Smf 2.0 © SmfMod.Com Smf Destek