when was the last time anyone found a real live virus ?

Discussion in 'other anti-virus software' started by Long View, Dec 7, 2007.

Thread Status:
Not open for further replies.
  1. Kerodo

    Kerodo Registered Member

    Joined:
    Oct 5, 2004
    Posts:
    8,013
    Last time I saw one live was in 2001, while downloading an executable file via p2p.
     
  2. Xenophobe

    Xenophobe Registered Member

    Joined:
    May 26, 2007
    Posts:
    174
    Just last year.
    Kaspersky couldn't clean it, so I did in safemode. :cool:
     
  3. Osaban

    Osaban Registered Member

    Joined:
    Apr 11, 2005
    Posts:
    5,618
    Location:
    Milan and Seoul
  4. jmc777

    jmc777 Registered Member

    Joined:
    Aug 6, 2004
    Posts:
    244
    You are correct.
     
  5. flyrfan111

    flyrfan111 Registered Member

    Joined:
    Jun 1, 2004
    Posts:
    1,229
    If Eset detected it he would not need to send it to them, so I would guess NOD didn't detect it and Eset has not added it yet.
     
  6. Macstorm

    Macstorm Registered Member

    Joined:
    Mar 7, 2005
    Posts:
    2,642
    Location:
    Sneffels volcano
    i betcha on that :D
     
  7. rothko

    rothko Registered Member

    Joined:
    Jan 12, 2005
    Posts:
    579
    Location:
    UK
    never that long before it turns into a bashing thread :rolleyes:
     
  8. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Agree. I go as far as implimenting any FD-ISR snapshot (system) along with Power Shadow/Returnil & SandboxIE, now thats bulletproof.

    The last time any virus caught me by surprise was during research on the Parite file infector virus. Nasty little worm that also hops into any other HD or Partition connected to the main system.

    Nothing on the internet via drive-by stands a chance anymore HA! HA!

    I occasionally probe dodgy sites laced with downloaders the second the browser lands on them but EQSecure (HIPS) suspends them immediately in mid-flight while i get to look them over and capture them instead of vice-versa. Even so, if something was to skirt the HIPS then SandboxIE would trap it too, and as if that wasn't enough, Power Shadow on reboot would remove it anyway. And if some new form of malware happened to be gifted with supernatural bypassing abilities, theres always either of 2 alternate choices, an FD-ISR archive (duplicate) and (Image) to put Humpty-Dumpty all back together again. :D
     
  9. Antarctica

    Antarctica Registered Member

    Joined:
    Feb 25, 2003
    Posts:
    2,180
    Location:
    Canada
    Long,long time ago. It was with Windows 95.:cool: My daughter brought a infected diskete from University. A friend of mine managed to clean it with McAfee ,if my memory is good.:D
     
  10. dawgg

    dawgg Registered Member

    Joined:
    Jun 18, 2006
    Posts:
    818
    Last time my AV detected malware (when I didn't expect it) was yesterday while on a Bank's website... Trojan-Clicker.HTML.IFrame.ey and Trojan-Clicker.JS.Agent.h and at one point, Exploit.Win32.MS06-078.a was also detected on it.

    Sent a e-mail about it to 2-3 e-mail addresses mentioned on the website yesterday and have not received a reply about it.... also both the Trojan-Clicker warnings are still coming up today :eek:

    Thank god there's no OnlineBanking on there! (website looks pretty amature anyway). Still wont expect it from a bank!


    Last time I was actually infected was years ago with tenga.a.. can remember my AV popping up constantly warning about it... even after i do a PC scan and removed it all, it kept coming back a few hours later until I done a scan with another AV which got rid of it for good!
     
  11. dr pan k

    dr pan k Registered Member

    Joined:
    Nov 22, 2007
    Posts:
    204
    1)in the last weeks (months): kalpurush knight disk: unwanted application to usb pen,half the university got infected through a copy store,cleaned through linux on the key and safe mode for the pc.

    2)rogue antivirus + trojan downloader but never got active

    3)big time sasser variant (send that to eset,got it with adv.heuristics)

    4)small stuff when uninstalling avast and migrating to eset (keylogger and a trojan...)

    5)p2p can give u some "fun" if u try downloading cracks and other similar stuff...
     
  12. kdcdq

    kdcdq Registered Member

    Joined:
    Apr 19, 2002
    Posts:
    815
    Location:
    A Non-Sh*thole State
    Hello all,

    I build/upgrade/fix PCs (hardware & software) for friends and people at work for "fun".

    Last month, I removed over one hundred forms of malware from one such computer, including botnets (5), viruses (65) , trojans (7), and spyware/adware of all kinds. This XP computer was running with no security software for about 18 months.
     
  13. dawgg

    dawgg Registered Member

    Joined:
    Jun 18, 2006
    Posts:
    818
    I normally recommend a format if 20 or more malware is detected at a time if its anything other than adware detected (depending on what else is detected)
     
  14. solcroft

    solcroft Registered Member

    Joined:
    Jun 1, 2006
    Posts:
    1,639
    Just curious, but how do you remove a botnet from a computer? Or five botnets, for that matter...
     
  15. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Do any of you remember the notorious group that enjoyed a round of great success for awhile releasing and even updating COOLWEBSEARCH?:ninja:
     
  16. C.S.J

    C.S.J Massive Poster

    Joined:
    Oct 16, 2006
    Posts:
    5,029
    Location:
    this forum is biased!
    i think everyone has encountered coolwebsearch on their machine in the past. :rolleyes:
     
  17. HURST

    HURST Registered Member

    Joined:
    Jul 20, 2007
    Posts:
    1,419
    My last real virus: today
    Not exactly "mine", since it was at my father-in-law's computer, but the removal fun was all mine to enjoy. Went to his house today and he said hello with a big smile and an "I need your help".:cautious:
    Toughest battle against malware in years!
    It was a rootkit named kernelw.sys, and a ton of tojans, adware and spyware.
    In the middle of the SAS scan, i kept receiving BSOD's, until I could catch the file name (very short BSOD's).
    AVG anti-rootkit and Dr.Web CureIt saved the day, but I know the computer is not 100% clean. Still showing pop-ups inviting to download "antispyware". So tomorrow comes part 2 of my fun weekend.
    Anyways, that computer must be a malware magnet: McAfee enterprise edition had signatures dated JULY, 2007!!!!:eek: :eek: :eek: :eek: :eek:
    Browser was IE6.:blink:
    (updated McAfee, added BOClean and SpywareBlaster...just for a start)
     
  18. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    Don't forget to update those files to Virustotal :cool:
    I think that fcukdat may want some samples too.
     
  19. HURST

    HURST Registered Member

    Joined:
    Jul 20, 2007
    Posts:
    1,419
    I don´t think that the rootkit is still there. Connecting to the internet caused a BSOD too, so I had to do the cleaning offline...Submiting to Virustotal was not possible. Didn't think of keeping a copy in an USB-drive.
    If I find something else, I'll keep it. Maybe I'll even test SandboxIE and Returnil on my computer.
     
  20. C.S.J

    C.S.J Massive Poster

    Joined:
    Oct 16, 2006
    Posts:
    5,029
    Location:
    this forum is biased!
    hi hurst,

    glad to hear drweb cureit has helped you out, ;)

    the problem is, the malware has probably already damaged system files that you need, so even though the malware has been cleaned, its still an unstable machine.

    if possible, try to repair your OS installation.

    and good luck to ya ;)
     
  21. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    Well, you can always restore files from the quarantine of SAS and CureIt and/or use the copy file function of Rootkit Unhooker and Icesword.
     
  22. NAMOR

    NAMOR Registered Member

    Joined:
    May 19, 2004
    Posts:
    1,530
    Location:
    St. Louis, MO
    I saw one last month on a hotel's File Server, one last week on a managers workstaion, and one this week on a POS (Point of Sale) terminal.
     
  23. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    Perhaps you enabled the option "Terminate memory threats before quarantining". This option shouldn't be checked.
     
  24. HURST

    HURST Registered Member

    Joined:
    Jul 20, 2007
    Posts:
    1,419
    Indeed.
    Next time i'll let it unchecked.
     
  25. kdcdq

    kdcdq Registered Member

    Joined:
    Apr 19, 2002
    Posts:
    815
    Location:
    A Non-Sh*thole State
    OK, you got me on this one! I wanted to say that this particular computer had five "rootkits" on it, not five "botnets". You know, I really should re-read my posts before hitting the "Submit Reply" button........
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.