◎ comp.exe is NOT VIRUS!!!(OK now,Thanks)

Comp.exe
is NOT VIRUS!!!

Download:
http://www.badongo.com/file/23645513

http://www.virustotal.com/analisis/807d98b7a9f9ed263cb63b60352256550aae7b9719b37469761c0030be4c8eea-1279028759

OS:XP SP3
Avast! Free AntiVirus 5.0.594

If only GData and avast detect it - GData uses avast as one of its two scanners so counts as 1 detection and almost certainly an FP.
Send the sample to avast as a False Positive:
Open the chest and right click on the file and select ‘Submit to virus lab…’ complete the form and submit, the file will be uploaded during the next update.

  • In the meantime (if you accept the risk), add it to the exclusions lists:
    File System Shield, Expert Settings, Exclusions, Add and
    avast Settings, Exclusions

Restore it to its original location, periodically check it (scan it in the chest), there should still be a copy in the chest even though you restored it to the original location. When it is no longer detected then you can also remove it from the File System Shield and avast Settings, exclusions lists.

Hi folks,

But detection is supported here: http://hosts-file.net/?s=badongo.com
Wepawet gives additional potentional malware: http://wepawet.iseclab.org/view.php?hash=79e23a2610168c2e6223b9edfb67a2e0&t=1279040712&type=js
But unmasked parasites make it fall through with 5 suspicious scripts, and 1 hidden external link found:
http://www.UnmaskParasites.com/security-report/?page=www.badongo.com/file/23645513
See image of the five suspicious inline script detected attached,

polonus

It’s OK NOW

Thanks!

http://www.virustotal.com/analisis/807d98b7a9f9ed263cb63b60352256550aae7b9719b37469761c0030be4c8eea-1279073649

That’s good, avast are usually quick to correct an FP when confirmed.

Thanks for the feedback.