bypass valkyrie

valkyrie report:
http://valkyrie.comodo.com/Result.aspx?sha1=19b7a719bf92c9a5f1e1cd32b7d5199c74ef595c&&query=1&&filename=temp.exe

the result is normal :cry:

CIMA report:
http://camas.comodo.com/cgi-bin/submit?file=d1301b90c1012bf9b917731a792bd5f2612fb3ca0b1977a5370484f54763763c

the result is undetected :cry:

I double click on the malware. >:-D

defense+ event:

2011-08-24 09:17:51 C:\Documents and Settings\Roger\摌青\virus\temp\temp.exe Sandboxed As Partially Limited

2011-08-24 09:17:54 C:\Recycle.Bin\B6232F3AAE2.exe Sandboxed As Partially Limited

2011-08-24 09:17:54 C:\Documents and Settings\Roger\摌青\virus\temp\temp.exe Access Memory C:\WINDOWS\explorer.exe

2011-08-24 09:17:54 C:\Recycle.Bin\B6232F3AAE2.exe Access Memory C:\WINDOWS\explorer.exe

2011-08-24 09:17:54 C:\DOCUME~1\Roger\LOCALS~1\Temp\3OKEF.exe Sandboxed As Partially Limited

2011-08-24 09:18:04 C:\Recycle.Bin\B6232F3AAE2.exe Modify Key HKLM\SYSTEM\ControlSet001\Control\Session Manager\PendingFileRenameOperations

2011-08-24 09:18:04 C:\Documents and Settings\Roger\Local Settings\Temp\3OKEF.exe Modify Key HKUS\S-1-5-21-1935655697-436374069-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Run\4Y3Y0C3AUF7W1HYESOIU

2011-08-24 09:18:04 C:\Documents and Settings\Roger\Local Settings\Temp\3OKEF.exe Access Memory C:\WINDOWS\system32\winlogon.exe

2011-08-24 09:18:04 C:\Documents and Settings\Roger\Local Settings\Temp\3OKEF.exe Modify Key HKUS\S-1-5-21-1935655697-436374069-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyHttp1.1

2011-08-24 09:18:18 C:\Documents and Settings\Roger\Local Settings\Temp\3OKEF.exe Modify Key HKUS\S-1-5-21-1935655697-436374069-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable

http://i.imgur.com/0UIC1.png

Can you send me the sample ?

Mistakes sometimes happen, it’s just heuristic.

another one

http://valkyrie.comodo.com/Result.aspx?sha1=42244ef3bbb8c42f163e16bdee91174fc4f216d5

the result is normal :-X

technically vakyrie is stil in beta since it isnt a part of the fls as intended. improvements are still being made. im expecting better detection once the dynamic detectors are improved and implemented which fanny said is in the making. valkyrie will never be 100% but it will get β– β– β– β–  close

http://valkyrie.comodo.com/Result.aspx?sha1=67346fa5ca22f1d6dc6806efc0c6c46b64757908&&query=0&&filename=contacts.exe

the result is normal :-[

but, Camas Verdict is Suspicious++ ???