LandzDown Forum

Security => Security Software Programs => Topic started by: JOSEPH on November 04, 2006, 05:11:11 AM

Title: Strong Intrusion Results
Post by: JOSEPH on November 04, 2006, 05:11:11 AM
I need to know the best place to SUBMIT some malware files where they can be reversed and studied for their scale of threat.
I been looking for the site i D/L this junk from but failed sp far to locate it again. I have several files (maybe new ones) that i let FileMap byBB QUARANTINE so they are intact and not disturbed, only moved to a safer confinement folder.
It effectively disabled System Restore plus Task Manager plus disabled loading many normal exe file programs. Could's even get RootKit Detectors to identify the locations. I lost the installer from panic since i resorted to using ERUNT to replace the registry (Thank Goodness), but i have the files it dropped in quarantine for someone to better research.

What is the best place to SUBMIT those? It was a pretty formidable file that disrupted the system even after reboot because of the payloads it brought along. Everything is back to normal but would like some place or someone to review and identify (if they can), if this is a new variant of something else. It used the Group Policy editor on XP to effectively disable the basic viewing programs like regedit and task manager and i spent all night trying to return those settings with no success so resorted to ERUNT. That proggy is a Life-Saver indeed in a case like this one was.

Thanks   EASTER
Title: Re: Strong Intrusion Results
Post by: Corrine on November 04, 2006, 01:07:30 PM
First go to  http://virusscan.jotti.org/ and scan the file to ensure it is new.  In "File to upload & scan" browse to the location of the file and select it. If the file is not detected, see the LandzDown Forum Submission Procedure (http://www.landzdown.com/index.php?topic=4652.0) as well as the link in Assarbad's signature.