 siljalineI'm lovin' that double widePremium join:2002-10-12 Montreal, QC kudos:17 | reply to Smokey Bear
Re: Beware of Combofix - contains infected file That would be a fair assumtion that other A/V vendors do. Since I loan a hand with ESET support, the link I provided was an example. Additionally, some here run ESET A/V. |
|
 siljalineI'm lovin' that double widePremium join:2002-10-12 Montreal, QC kudos:17 | reply to Smokey Bear Noted: A Query of MS MMPC yields: »www.microsoft.com/security/porta···y=Sality |
|
 therube join:2004-11-11 Randallstown, MD | reply to therube
quote: SHA256 Hashes of known affected versions are:
4524611a78ddd40afa7e13238da230302786c546d1f824e6e7dea480a5d55333 e5341c3c32a9726a2d3dd1ac0b90f13d896581ab8707dd0a17431df061a2a71d 4524611a78ddd40afa7e13238da230302786c546d1f824e6e7dea480a5d55333 e95f77fd437b16312fbd66a02fed8b179968a7615c1bd3cd3b2fd86879b4bbc8
quote: Added hashes of the known affected version to first post. Hashes can be found below as well:
SHA256: 4524611a78ddd40afa7e13238da230302786c546d1f824e6e7dea480a5d55333 MD5: c71b0515ef1200755ae61a5c4c9e8a86
» www.bleepingcomputer.com/forums/···431.html(Now we need an SHA256 to MD5 converter  .) So presumably what I had gotten earlier, 1 day prior, is OK. (It came from Softpedia, though I notified them of this issue so don't know if they're still hosting or not?) |
|
 Jrb2Premium join:2001-08-31 kudos:3 | The file, which I scanned earlier at VT, was the one with checksums: SHA256: 4524611a78ddd40afa7e13238da230302786c546d1f824e6e7dea480a5d55333 MD5: c71b0515ef1200755ae61a5c4c9e8a86
I did post those checksums in my previous post in this thread, along with the results at VT at that moment, and with the alert by NOD32. I wasn't at that moment the first one who had scanned it there. |
|
 Jrb2Premium join:2001-08-31 kudos:3 | reply to Jrb2 Postings by Grinler at BleepingComputer: »www.bleepingcomputer.com/forums/···431.html
quote: ComboFix is now live, clean, and available to download from its normal links.
On a question whether Combofix would deal with the Sality infection:
quote: I would avoid ComboFix until you have confirmed your computer is not infected with Sality. Ironically, CF will quarantine Sality infected files, other than OS files, if they are found.
About the version I downloaded from BleepingComputer about an half hour ago:
ComboFix.exe
Version 13.1.30.4
SHA256: a1ed6bc74db51c219c08d6126d7de5c60570b2f76c60ce602bf602096d2f85a1 MD5: 4f973e9d3fdaeb5347243e8e169714e7
VT: 2/45
AntiVir TR/Crypt.XPACK.Gen Jiangmin Trojan/JmGenGeneric.boe |
|
 trparkyApple... YUMPremium,MVM join:2000-05-24 Cleveland, OH kudos:2 Reviews:
·Time Warner Cable
| I downloaded the same file you did, the signatures (MD5 and SHA256) match. I scanned the file with both Webroot and MalwareBytes AntiMalware using the latest definitions, no infection found.
»www.virustotal.com/file/a1ed6bc7···9592743/ -- Tom Boycott AT&T uVerse! | Tom's Android Blog | AOKP (The Android Open Kang Project) |
|
 TheJokerPremium,VIP,MVM join:2001-04-26 Charlottesville, VA kudos:5 | From Grinler:
quote: ComboFix is now live, clean, and available to download from its normal links.
»www.bleepingcomputer.com/forums/···_2962394 -- Proud ASAP member since 2005 Microsoft MVP/Consumer Security 2009-2010 |
|
 siljalineI'm lovin' that double widePremium join:2002-10-12 Montreal, QC kudos:17 | reply to Jrb2 Combofix: a cocktail of infective factors • »blog.eset.com/2013/02/01/combofi···-factors |
|
 Mele20Premium join:2001-06-05 Hilo, HI kudos:4 | That was a good blog. It can never be said enough that users should NOT use sites like download.com to get applications but should always go to the vendor's site as that is where it is least likely one will get infected from a tainted download. Plus, as the blog points out, the official host site/vendor's site will react very rapidly if made aware of a problem, whereas, mirror sites may not...especially those that mirror without permission. If users would stop using sites like download.com maybe sites like it would disappear which would be good. -- When governments fear people, there is liberty. When the people fear the government, there is tyranny. Thomas Jefferson |
|
 siljalineI'm lovin' that double widePremium join:2002-10-12 Montreal, QC kudos:17 Reviews:
·Bell Sympatico
| Your welcome for the ESET Blog entry, it was well thought-out and well penned. Also see from Bill P of Win Patrol: »billpstudios.blogspot.ca/2012/10···are.html |
|
|
|
 siljalineI'm lovin' that double widePremium join:2002-10-12 Montreal, QC kudos:17 | reply to Jrb2 A new ESET Blog blog entry on combofix. »blog.eset.com/2013/02/05/combofi···e-to-use |
|
 therube join:2004-11-11 Randallstown, MD 1 edit | Very well written & said. Here, here, Goretsky! |
|
 Mele20Premium join:2001-06-05 Hilo, HI kudos:4 | I think you mean "hear, hear".  |
|
 EGeezerGo CatsPremium join:2002-08-04 Midwest kudos:8 | said by Mele20:I think you mean "hear, hear".  Unless he's inviting Goretsky over for a congratulatory beer  -- Buckle Up. It makes it harder for the aliens to suck you out of your car.
|
|
 | reply to Jrb2 ESET's blog said:
BleepingComputers, upon notification, immediately pulled the infected executables and shortly after that, sUBs issued an apology and an explanation. In short, the combination of being overly busy working for a good cause and a faulty mouse issuing a double-click rather than a single click while looking at malware in an infected archive triggered the infection of his system. It is true but unhelpful to state that malware should never be looked at and handled on a production system as it only takes a minor mistake as this one to cause an infection on production software.. Production systems are indeed not the best place to mess around with malware samples. -- Limited User Accounts. Software Restriction Policies. |
|