CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Complainterator download infected?

 
Post new topic   Reply to topic       All -> FavForums -> Complainterator [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
biggestal

Trooper
Trooper


Joined: Mar 27, 2008
Posts: 17
Location: UK

PostPosted: Mon Apr 14, 2008 7:22 pm    Post subject: Complainterator download infected?
Reply with quote

Downloaded complainterator zip-file complainterator21_156.zip from www.castlecops.com/modules/Forums/attachments/ today.

After unzipping and trying to run the .exe file I was warned of virus IM-Worm.Win32.Sohanad.gy which was immediately quarantined by Comodo antivirus!!!

Obviously surprised - is there a real problem?

Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2945

Blue Security Premium

PostPosted: Mon Apr 14, 2008 7:46 pm    Post subject:
Reply with quote

I can't find it on that link.

Downloads are available from CastleCops Link/t218903-Complainterator_Version_21_0_April_4_2008.html or from http://complainterator.com

Please elaborate on how to find the one you downloaded

Back to top
View users profile Send private message Visit posters website AIM Address
biggestal

Trooper
Trooper


Joined: Mar 27, 2008
Posts: 17
Location: UK

PostPosted: Mon Apr 14, 2008 8:11 pm    Post subject:
Reply with quote

followed download from this link CastleCops Link/t218903-Complainterator_Version_21_0_April_4_2008.html. The link I reported is the one shown for download in free download manager - does that make sense?

Back to top
View users profile Send private message
biggestal

Trooper
Trooper


Joined: Mar 27, 2008
Posts: 17
Location: UK

PostPosted: Mon Apr 14, 2008 8:33 pm    Post subject:
Reply with quote

Screenshot of freedownloadmanager related to complainerator download attached, if that helps




complainteratorpic.jpg
 Description:
 Filesize:  110.62 KB
 Viewed:  52 Time(s)

complainteratorpic.jpg


Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2945

Blue Security Premium

PostPosted: Mon Apr 14, 2008 8:49 pm    Post subject:
Reply with quote

OK, I have submitted current and previous releases of complainterator.exe to virustotal.com

The program is written in an interpretive language and then compiled. The compiler creates the exe in a packed format. This format sometimes triggers false positives. Furthermore, Complainterator generates keystrokes and places them into your browser, then examines the results posted back by the web sites, such as dnsstuff.com. Because it is sending keystrokes, it can be wrongly interpreted by the lesser virus scanners as performing functions similar to keyloggers and malware.

I have compiled some other harmless programs and submitted them to virustotal.com

False positives are reported for Complainterator V19 by
http://www.virustotal.com/analisis/3089b7f4cebb2a439e699aa2d2595c0c

eSafe 7.0.15.0 2008.04.09 suspicious Trojan/Worm
Rising 20.40.02.00 2008.04.14 Trojan.Win32.BrandStep.a


Another harmless compiled program, AutoBlog.exe, has false positives
CAT-QuickHeal 9.50 2008.04.14 I-Worm.Sohanad.fg
eSafe 7.0.15.0 2008.04.09 suspicious Trojan/Worm
NOD32v2 3026 2008.04.14 archive damaged
TheHacker 6.2.92.277 2008.04.14 W32/Sohanad.gh


Finally, I sent a compiled program that says "Hello World" (hw.exe)
http://www.virustotal.com/analisis/2580364a8100c0ec28df66dd342809c4

False positives for "Hello World" (hw.exe)
CAT-QuickHeal 9.50 2008.04.14 I-Worm.Sohanad.fg
eSafe 7.0.15.0 2008.04.09 suspicious Trojan/Worm
NOD32v2 3026 2008.04.14 archive damaged
TheHacker 6.2.92.277 2008.04.14 W32/Sohanad.gh


These are all given a clean report by the big players - AVG, Avast, McAfee, Microsoft, Kaspersky, Symantec

Conclusion
The programs are clean, the less credible scanners are defective.


Please report your Comodo problem to them so they can fix their product.

Back to top
View users profile Send private message Visit posters website AIM Address
biggestal

Trooper
Trooper


Joined: Mar 27, 2008
Posts: 17
Location: UK

PostPosted: Mon Apr 14, 2008 9:10 pm    Post subject:
Reply with quote

tembow, many thanks for quick response and reassurance.

My objective was to flag possible issue, not to alarm.

Virus checker I used was Comodo Antivirus beta2, www.comodo.com fyi.

Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2945

Blue Security Premium

PostPosted: Mon Apr 14, 2008 10:23 pm    Post subject:
Reply with quote

No problem, it is good to reassure you and anyone else who detects faults in scanners and who may come to the wrong conclusion.

As their user, I leave it to you to alert them to their problem.

Back to top
View users profile Send private message Visit posters website AIM Address
biggestal

Trooper
Trooper


Joined: Mar 27, 2008
Posts: 17
Location: UK

PostPosted: Mon Apr 14, 2008 10:55 pm    Post subject:
Reply with quote

Have started posting with comodo av (https://forums.comodo.com/feedbackcommentsannouncementsnews_about_cavs/false_positive_complainterator_v210-t21857.0.html ) and will advise response.

Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2945

Blue Security Premium

PostPosted: Fri Apr 18, 2008 7:57 am    Post subject:
Reply with quote

Comodo has fixed the false positive

Quote:
Thanks for your information. False positive is fixed for
"Complainterator " files.

Regards
Malcolm
Technical Support

Back to top
View users profile Send private message Visit posters website AIM Address
biggestal

Trooper
Trooper


Joined: Mar 27, 2008
Posts: 17
Location: UK

PostPosted: Fri Apr 18, 2008 7:16 pm    Post subject:
Reply with quote

Confirming Comodo AV now happy on my PC, will try complainterator over weekend.

Ran file this evening through virustotal.com and pleased to confirm that majority of well known/trusted checkers agree no problem.

Several hours on castlecops confirmed to me that you are major, major battler against spam, tenbow. Thanks for all your efforts.

As newcomer to stopping, rather than blocking spam, I salute you.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Complainterator All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer