<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;Beware of Combofix - contains infected file&#x27; in forum &#x27;Security&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Beware-of-Combofix-contains-infected-file-27957360</link>
<description></description>
<language>en</language>
<pubDate>Fri, 24 May 2013 04:24:04 EDT</pubDate>
<lastBuildDate>Fri, 24 May 2013 04:24:04 EDT</lastBuildDate>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27988946</link>
<description><![CDATA[Tuulilapsi posted : ESET's blog said:<br><blockquote>BleepingComputers, upon notification, immediately pulled the infected executables and shortly after that, &#147;sUBs&#148; issued an apology and an explanation. In short, the combination of being overly busy working for a good cause and a faulty mouse issuing a double-click rather than a single click while looking at malware in an infected archive triggered the infection of his system. It is true but unhelpful to state that malware should never be looked at and handled on a production system as it only takes a minor mistake as this one to cause an infection on production software..</blockquote><br><br>Production systems are indeed not the best place to mess around with malware samples. <br><small>--<br><A HREF="http://www.microsoft.com/nz/protect/computer/advanced/useraccount.mspx">Limited User Accounts.</a><br><A HREF="http://technet.microsoft.com/en-us/library/cc507878.aspx">Software Restriction Policies.</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27988946</guid>
<pubDate>Thu, 07 Feb 2013 15:01:38 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27983136</link>
<description><![CDATA[EGeezer posted : <div class="bquote"><said>said by <a href="/profile/403861" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=403861');">Mele20</a>:</said><p>I think  you mean "hear, hear".  :D<br> </p></div>Unless he's inviting Goretsky over for a congratulatory beer  :D<br><small>--<br>Buckle Up. It makes it harder for the aliens to suck you out of your car.<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27983136</guid>
<pubDate>Tue, 05 Feb 2013 21:39:29 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27982851</link>
<description><![CDATA[Mele20 posted : I think  you mean "hear, hear".  :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27982851</guid>
<pubDate>Tue, 05 Feb 2013 20:16:34 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27982608</link>
<description><![CDATA[therube posted : <b>Very</b> well written & said.<br>Here, here, Goretsky!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27982608</guid>
<pubDate>Tue, 05 Feb 2013 19:00:21 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27982319</link>
<description><![CDATA[siljaline posted : A new <ahref="http://blog.eset.com/>ESET Blog</a> blog entry on combofix. <br>&raquo;<A HREF="http://blog.eset.com/2013/02/05/combofix-fixed-popular-utility-safe-to-use" >blog.eset.com/2013/02/05/combofi&middot;&middot;&middot;e-to-use</A> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27982319</guid>
<pubDate>Tue, 05 Feb 2013 17:31:42 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27970957</link>
<description><![CDATA[siljaline posted : Your welcome for the ESET Blog entry, it was well thought-out and well penned. <br>Also see from Bill P of Win Patrol:<br>&raquo;<A HREF="http://billpstudios.blogspot.ca/2012/10/the-dangers-of-downloading-free-software.html" >billpstudios.blogspot.ca/2012/10&middot;&middot;&middot;are.html</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27970957</guid>
<pubDate>Fri, 01 Feb 2013 21:10:42 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27970919</link>
<description><![CDATA[Mele20 posted : That was a good blog. It can never be said enough that users should NOT use sites like download.com to get applications but should always go to the vendor's site as that is where it is least likely one will get infected from a tainted download. Plus, as the blog points out, the official host site/vendor's site will react very rapidly if made aware of a problem, whereas, mirror sites may not...especially those that mirror without permission. If users would stop using sites like download.com maybe sites like it would disappear which would be good. <br><small>--<br>When governments fear people, there is liberty. When the people fear the government, there is tyranny.  Thomas Jefferson</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27970919</guid>
<pubDate>Fri, 01 Feb 2013 21:00:01 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27970872</link>
<description><![CDATA[siljaline posted : Combofix: a cocktail of infective factors<br>&#8226;  &raquo;<A HREF="http://blog.eset.com/2013/02/01/combofix-a-cocktail-of-infective-factors" >blog.eset.com/2013/02/01/combofi&middot;&middot;&middot;-factors</A> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27970872</guid>
<pubDate>Fri, 01 Feb 2013 20:43:00 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27963538</link>
<description><![CDATA[TheJoker posted : From Grinler:<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>ComboFix is now live, clean, and available to download from its normal links.<HR></BLOCKQUOTE><br><br>&raquo;<A HREF="http://www.bleepingcomputer.com/forums/topic483431.html/page__view__findpost__p__2962394" >www.bleepingcomputer.com/forums/&middot;&middot;&middot;_2962394</A><br><small>--<br>Proud ASAP member since 2005<br>Microsoft MVP/Consumer Security 2009-2010</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27963538</guid>
<pubDate>Wed, 30 Jan 2013 21:50:16 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27963156</link>
<description><![CDATA[trparky posted : I downloaded the same file you did, the signatures (MD5 and SHA256) match.  I scanned the file with both Webroot and MalwareBytes AntiMalware using the latest definitions, no infection found.<br><br>&raquo;<A HREF="https://www.virustotal.com/file/a1ed6bc74db51c219c08d6126d7de5c60570b2f76c60ce602bf602096d2f85a1/analysis/1359592743/" >www.virustotal.com/file/a1ed6bc7&middot;&middot;&middot;9592743/</A><br><small>--<br>Tom<br><A HREF="http://on.fb.me/k8VIVy">Boycott AT&T uVerse!</a> | <A HREF="http://www.toms-world.org/blog/android">Tom's Android Blog</a> | <A HREF="http://bit.ly/RNSReP">AOKP (The Android Open Kang Project)</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27963156</guid>
<pubDate>Wed, 30 Jan 2013 19:43:28 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27962606</link>
<description><![CDATA[Jrb2 posted : Postings by Grinler at BleepingComputer:<br>&raquo;<A HREF="http://www.bleepingcomputer.com/forums/topic483431.html" >www.bleepingcomputer.com/forums/&middot;&middot;&middot;431.html</A><br><br>  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>ComboFix is now live, clean, and available to download from its normal links. <br><HR></BLOCKQUOTE><br><br>On a question whether Combofix would deal with the Sality infection:<br><br>  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>I would avoid ComboFix until you have confirmed your computer is not infected with Sality. Ironically, CF will quarantine Sality infected files, other than OS files, if they are found. <br><HR></BLOCKQUOTE><br><br>About the version I downloaded from BleepingComputer about an half hour ago:<br><br>ComboFix.exe<br><br>Version 13.1.30.4<br><br>SHA256: a1ed6bc74db51c219c08d6126d7de5c60570b2f76c60ce602bf602096d2f85a1 <br>MD5: 4f973e9d3fdaeb5347243e8e169714e7 <br><br>VT:<br>2/45<br><br>AntiVir TR/Crypt.XPACK.Gen <br>Jiangmin Trojan/JmGenGeneric.boe ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27962606</guid>
<pubDate>Wed, 30 Jan 2013 16:27:54 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27959700</link>
<description><![CDATA[Jrb2 posted : The file, which I scanned earlier at VT, was the one with checksums:<br>SHA256: <br>4524611a78ddd40afa7e13238da230302786c546d1f824e6e7dea480a5d55333<br>MD5: c71b0515ef1200755ae61a5c4c9e8a86 <br><br>I did post those checksums in my previous post in this thread, along with the results at VT at that moment, and with the alert by NOD32.<br>I wasn't at that moment the first one who had scanned it there.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27959700</guid>
<pubDate>Tue, 29 Jan 2013 20:03:03 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27959633</link>
<description><![CDATA[therube posted :   <BLOCKQUOTE><SMALL>quote:</SMALL><HR>SHA256 Hashes of known affected versions are:<br><br>4524611a78ddd40afa7e13238da230302786c546d1f824e6e7dea480a5d55333<br>e5341c3c32a9726a2d3dd1ac0b90f13d896581ab8707dd0a17431df061a2a71d<br>4524611a78ddd40afa7e13238da230302786c546d1f824e6e7dea480a5d55333<br>e95f77fd437b16312fbd66a02fed8b179968a7615c1bd3cd3b2fd86879b4bbc8<br><HR></BLOCKQUOTE><br><br>  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Added hashes of the known affected version to first post. Hashes can be found below as well:<br><br>SHA256:<br>4524611a78ddd40afa7e13238da230302786c546d1f824e6e7dea480a5d55333<br>MD5: c71b0515ef1200755ae61a5c4c9e8a86<br><HR></BLOCKQUOTE><br><br>&raquo;<A HREF="http://www.bleepingcomputer.com/forums/topic483431.html" >www.bleepingcomputer.com/forums/&middot;&middot;&middot;431.html</A><br><br>(Now we need an SHA256 to MD5 converter ;-).)<br><br>So presumably what I had gotten earlier, 1 day prior, is OK.<br>(It came from Softpedia, though I notified them of this issue so don't know if they're still hosting or not?)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27959633</guid>
<pubDate>Tue, 29 Jan 2013 19:40:05 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27959349</link>
<description><![CDATA[siljaline posted : Noted: A Query of MS MMPC yields: <br>&raquo;<A HREF="http://www.microsoft.com/security/portal/threat/encyclopedia/search.aspx?query=Sality" >www.microsoft.com/security/porta&middot;&middot;&middot;y=Sality</A> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27959349</guid>
<pubDate>Tue, 29 Jan 2013 18:10:31 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27959085</link>
<description><![CDATA[siljaline posted : That would be a fair assumtion that other A/V vendors do.<br>Since I loan a hand with ESET support, the link I provided was an example. Additionally, some here run ESET A/V. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27959085</guid>
<pubDate>Tue, 29 Jan 2013 16:37:27 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27959044</link>
<description><![CDATA[Smokey Bear posted :  <BLOCKQUOTE><SMALL>said by <a href="/profile/703015" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=703015');">siljaline</a>:</SMALL><HR>ESET users have some level of protection from <ahref="http://go.eset.com/us/threat-center/threatsense-updates/search/?q=Sality>Sality</a> <br><br> <HR></BLOCKQUOTE><br>Most other vendors offer protection too, it's not just ESET.<br><small>--<br><i>&raquo;<A HREF="http://bit.ly/gUqYaH" >bit.ly/gUqYaH</A> - C. Brian Smith: Think of the exclamation point as a car horn: a little goes a long way. Lay on it too hard and everyone’s going to think you’re a moron.</i><br><i>&raquo;<A HREF="http://bit.ly/V5mACB" >bit.ly/V5mACB</A> - How-To: Destroying a faulty keyboard</i></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27959044</guid>
<pubDate>Tue, 29 Jan 2013 16:23:23 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27958671</link>
<description><![CDATA[siljaline posted : <i>fwiw</i>,  Jrb2 <A HREF="/useremail/u/465492"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :D<br><br>ESET users have some level of protection from <ahref="http://go.eset.com/us/threat-center/threatsense-updates/search/?q=Sality>Sality</a> <br><br>I hope that an uninfected version of combofix is made available soon. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27958671</guid>
<pubDate>Tue, 29 Jan 2013 14:32:25 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27958261</link>
<description><![CDATA[Grinler posted : Waiting on this information from the developer.  At the same time, if you scan your current version and it shows clean in virustotal then you are good to go.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27958261</guid>
<pubDate>Tue, 29 Jan 2013 12:46:45 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27958257</link>
<description><![CDATA[therube posted : Sure would be nice if they posted a hash of the infected version.<br>And better yet if they also posted hashes for their prior, known good versions.<br><br>(So like is my 1-28 version good or bad, or have I lucked out by a few hours?)<br><br>If mine is good, then maybe I could use Combofix to fix Combofix ;-).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27958257</guid>
<pubDate>Tue, 29 Jan 2013 12:45:24 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27958254</link>
<description><![CDATA[Grinler posted : The affected file was not nircmd.  It was a different file unfortunately.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27958254</guid>
<pubDate>Tue, 29 Jan 2013 12:44:03 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27958235</link>
<description><![CDATA[therube posted : What version & size of nircmd.exe ?<br><br>In what I have (Combofix.exe), both firefox.exe.VIR & iexplore.exe.VIR (both lower case, the .VIR added by me) are 256,000 bytes (& are exactly the same, chameleons if you will) but neither compare in any way to any nircmd.exe that I have?<br><br>VirusTotal (1 / 46) <A HREF="https://www.virustotal.com/file/ae0f5cc54e4b133df66a54572a7ce52faff11f8fd0caeab088aad3699d6ec924/analysis/" >iexplore.exe</A>.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27958235</guid>
<pubDate>Tue, 29 Jan 2013 12:39:48 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27958107</link>
<description><![CDATA[therube posted : A 28th Jan version gives this md5 hash:<br><br>0f6d28a70471051c4c7785335acba626<br><br>And oddly, VirusTotal only shows 1 / 46 for it: <A HREF="https://www.virustotal.com/file/361548f74415a41f00d5345b3e3c489b3282b302c0c51266880eda586db01a12/analysis/" >ComboFix_13-01-28.01.exe</A><br><br>Edit to include SHA265 hash (that's like 256+9 for good luck):<br><br>SHA256: 361548f74415a41f00d5345b3e3c489b3282b302c0c51266880eda586db01a12]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27958107</guid>
<pubDate>Tue, 29 Jan 2013 11:59:47 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27958094</link>
<description><![CDATA[Jrb2 posted : Two posts at BleepingComputer:<br><br>1.<br>&raquo;<A HREF="http://www.bleepingcomputer.com/forums/topic483407.html" >www.bleepingcomputer.com/forums/&middot;&middot;&middot;407.html</A><br><br>By Grinler:<br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>The download has been pulled since earlier this morning as sUBs investigates the reports. At this time, I unfortunately do not have any other information for anyone. <br><br>Stay tuned. <br><HR></BLOCKQUOTE><br><br>2.<br>&raquo;<A HREF="http://www.bleepingcomputer.com/forums/topic483431.html" >www.bleepingcomputer.com/forums/&middot;&middot;&middot;431.html</A><br><br>By Grinler<br>Information about ComboFix being infected and what you should do <br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Unfortunately it has come to light that the program ComboFix had a file in it that is infected with the Sality virus. The minute we heard about this, we pulled the executable so that it is no longer available from BleepingComputer.com. Unfortunately we have no control over other sites that may have mirrored ComboFix without permission, so please do not attempt to download it elsewhere.<br><br>The developer, sUBs, is currently looking into what happened and when I have a full update, I will be sure to let you know. From the limited information that I have, it appears that the affected version has been available since approximately 2am EST on January 29th. If this timeframe changes, I will update this topic to let you know. If you have used a new copy of ComboFix downloaded after 2am EST, then you should examine your system for possible infection. If you have used a copy of ComboFix prior to this version, then you should be ok.<br><br>In the meantime, it is important for those who may have used ComboFix recently and are concerned they are infected to get the help they need. As the Sality infection has been around for a while, almost all antivirus vendors will have detected it and blocked it when you ran ComboFix. Unfortunately, not everyone has up-to-date virus definitions or uses an AV program, so it is important to examine your system if you have downloaded a new copy and used it since 2am EST.<br><HR></BLOCKQUOTE><br><br>Read more at that second link!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27958094</guid>
<pubDate>Tue, 29 Jan 2013 11:56:25 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957958</link>
<description><![CDATA[alien8 posted : I downloaded Combofix on the 23rd Jan, from the mirror and<br>it's got this md5 hash:<br><br>2D928456F2238FBB9C06F173691B0B83<br><br>So, look like the new version got put there since 23rd??<br><small>--<br>&raquo;<A HREF="http://sanesecurity.blogspot.com/" >sanesecurity.blogspot.com/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957958</guid>
<pubDate>Tue, 29 Jan 2013 11:17:29 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957877</link>
<description><![CDATA[therube posted :  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>IExplorer.exe file is Nircmd.exe(renamed)<HR></BLOCKQUOTE><br>Why would they do that, unless to act like a <A HREF="http://www.malwarebytes.org/products/chameleon/" >chameleon</A>?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957877</guid>
<pubDate>Tue, 29 Jan 2013 10:52:26 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957841</link>
<description><![CDATA[TheJoker posted : And I notified sUBs this morning just in case.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957841</guid>
<pubDate>Tue, 29 Jan 2013 10:41:00 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957789</link>
<description><![CDATA[trog posted : From wilders:<br><br> <BLOCKQUOTE><SMALL>said by Blade Z :</SMALL><HR>Hello,<br><br>Just letting you know that the mirror at Bleeping Computer has been deactivated until this gets sorted out.  So that should go a ways towards minimizing the exposure.<br><br>A big thanks to Marcos as it was this thread that first alerted our staff to the issue.<br><br>~Blade<br>Bleeping Computer Forum Administrator<HR></BLOCKQUOTE>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957789</guid>
<pubDate>Tue, 29 Jan 2013 10:23:57 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957563</link>
<description><![CDATA[dandelion posted : This is almost unheard of. Did this happen just on that site or to the entire program?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957563</guid>
<pubDate>Tue, 29 Jan 2013 08:55:34 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957549</link>
<description><![CDATA[Robotics posted : All I can say is wow!<br><br>How the hell did this happen? Is anyone saying yet?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957549</guid>
<pubDate>Tue, 29 Jan 2013 08:51:51 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957533</link>
<description><![CDATA[Jrb2 posted : Thread at BleepingComputer forum:<br>&raquo;<A HREF="http://www.bleepingcomputer.com/forums/topic483407.html" >www.bleepingcomputer.com/forums/&middot;&middot;&middot;407.html</A><br><br>No official responce yet there.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957533</guid>
<pubDate>Tue, 29 Jan 2013 08:45:22 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957471</link>
<description><![CDATA[Jrb2 posted : Scanned at VirusTotal:<br>30/45<br><br>Agnitum Win32.Sality.BL 20130128 <br>AhnLab-V3 - 20130129 <br>AntiVir W32/Sality.AT 20130129 <br>Antiy-AVL - 20130129 <br>Avast Win32:Sality 20130129 <br>AVG Win32/Sality 20130129 <br>BitDefender Win32.Sality.3 20130129 <br>ByteHero - 20130123 <br>CAT-QuickHeal W32.Sality.U 20130129 <br>ClamAV - 20130129 <br>Commtouch W32/Sality.gen2 20130129 <br>Comodo Virus.Win32.Sality.Gen 20130129 <br>DrWeb Win32.Sector.22 20130129 <br>Emsisoft Win32.Sality.3 (B) 20130129 <br>eSafe - 20130127 <br>ESET-NOD32 Win32/Sality.NBA 20130129 <br>F-Prot W32/Sality.gen2 20130129 <br>Fortinet - 20130129 <br>GData Win32.Sality.3 20130129 <br>Ikarus Virus.Win32.Sality 20130129 <br>Jiangmin Trojan/JmGenGeneric.boe 20121221 <br>K7AntiVirus Virus 20130128 <br>Kaspersky Virus.Win32.Sality.gen 20130129 <br>Kingsoft - 20130121 <br>Malwarebytes - 20130129 <br>McAfee W32/Sality.gen.z 20130129 <br>McAfee-GW-Edition - 20130129 <br>Microsoft Virus:Win32/Sality.AT 20130129 <br>MicroWorld-eScan Win32.Sality.3 20130129 <br>NANO-Antivirus Virus.Win32.Sality.beygb 20130129 <br>Norman Sality.ZGZ 20130129 <br>nProtect Win32.Sality.3 20130129 <br>Panda W32/Sality.AA 20130128 <br>PCTools - 20130129 <br>Rising Win32.KUKU.ky 20130129 <br>Sophos Mal/Sality-D 20130129 <br>SUPERAntiSpyware - 20130129 <br>Symantec - 20130129 <br>TheHacker - 20130128 <br>TotalDefense - 20130129 <br>TrendMicro PE_SALITY.RL-O 20130129 <br>TrendMicro-HouseCall PE_SALITY.RL-O 20130129 <br>VBA32 Virus.Win32.Sality.bakc 20130129 <br>VIPRE Virus.Win32.Sality.at (v) 20130129 <br>ViRobot - 20130129 <br><br>SHA256: 4524611a78ddd40afa7e13238da230302786c546d1f824e6e7dea480a5d55333 <br><br>MD5: c71b0515ef1200755ae61a5c4c9e8a86 ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957471</guid>
<pubDate>Tue, 29 Jan 2013 08:00:15 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957466</link>
<description><![CDATA[Jrb2 posted : Downloaded from BleepingComputer.<br>Eset (NOD32) warning: see screenshot<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/27957466?c=2070340&ret=L2ZvcnVtL3IyNzk1NzM2MC54bWw%3D"><IMG TITLE="9614 bytes" BORDER=0 WIDTH=439 HEIGHT=203 SRC="/r0/download/2070340~eb1efc3be727f07438afac6f2542ffb4/NOD32_2013_01_29_1.gif"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957466</guid>
<pubDate>Tue, 29 Jan 2013 07:56:47 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957384</link>
<description><![CDATA[anon posted : Unsure where Eset got their installer from but the official Combofix download link is at Bleepingcomputer.<br><br>The IExplorer.exe file is Nircmd.exe(renamed) with MD5 753BC16326FEE4A421ACB636CCD602F4<br><br>VT report would not say Sality for that file as its 3 year old legitimate tool.<br>&raquo;<A HREF="https://www.virustotal.com/file/24ca5ceb560f68b37c7cd4e548303a3617bb230c3b7478fe61ae804b8f128e4a/analysis/" >www.virustotal.com/file/24ca5ceb&middot;&middot;&middot;nalysis/</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957384</guid>
<pubDate>Tue, 29 Jan 2013 07:46:29 EDT</pubDate>
</item>

<item>
<title>Re: Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957391</link>
<description><![CDATA[norwegian posted : April 1st isn't here yet? :)<br><br>Wow, no one is bulletproof then?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Beware-of-Combofix-contains-infected-file-27957391</guid>
<pubDate>Tue, 29 Jan 2013 07:17:22 EDT</pubDate>
</item>

<item>
<title>Beware of Combofix - contains infected file</title>
<link>http://www.dslreports.com/forum/Beware-of-Combofix-contains-infected-file-27957360</link>
<description><![CDATA[Jrb2 posted : Warning by Marcos at the ESET forum:<br>&raquo;<A HREF="http://www.wilderssecurity.com/showthread.php?t=340693" >www.wilderssecurity.com/showthre&middot;&middot;&middot;t=340693</A><br><br>Quote:<br>We have discovered that the current installer of Combofix contains iexplore.exe infected with the Sality virus. It's pretty well detected by other vendors as well.<br>We do not recommend downloading and using it until the author remedies the issue.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Beware-of-Combofix-contains-infected-file-27957360</guid>
<pubDate>Tue, 29 Jan 2013 06:55:00 EDT</pubDate>
</item>

</channel>
</rss>
