Welcome, Guest. Please login or register.
Did you miss your activation email?
May 18, 2013, 12:36:28 PM

Login with username, password and session length

662883 Posts
70570 Topics
145132 Members

Latest Member: winklecap

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Virus/Malware Removal Assistance
| | |-+  a bug found,I can't find a solution
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: a bug found,I can't find a solution  (Read 9976 times)
goved
Newbie
*
Offline Offline

Posts: 18


« on: December 25, 2011, 03:12:49 AM »

hi,i have something in my PC that doesn't allow to work properly.Some parts of start menu disappeared,the screen is blue-it has a picture on the desktop,some office documents can't be opened,and there are some office documents that are renamed but not by me.If i try to delete they appear again or even can't delete. I use Windows XP/Pro version 2002,SP3,have two accounts-administrative one and user one.Found a archived file in directory D: which can't delete,it says "it is used by another program".MBAM scanning didn't find anything wrong.Any help?
Logged
wasgij6
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3062



WWW
« Reply #1 on: December 25, 2011, 03:36:04 AM »

Try following this guide to see if you are infected.
Logged

| Win 7 Ultimate (x32) SP1; Admin | UAC Disabled | CIS 6.1.276867.2813 | CD 26.2 | CID 20.0.1 | VMWare Workstation; XP (x32), 7 (x64) |
goved
Newbie
*
Offline Offline

Posts: 18


« Reply #2 on: December 25, 2011, 04:01:30 AM »

i can't star Killswitch program.I 've been used Deffoger.Is it reason KIllswitch to fail to load?
Logged
wasgij6
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3062



WWW
« Reply #3 on: December 25, 2011, 04:16:22 AM »

are you gtting an error when trying to run it? malware might be preventing it from running

try holding the shift key when you double click killswitch. thaat will run it in agressive mode
Logged

| Win 7 Ultimate (x32) SP1; Admin | UAC Disabled | CIS 6.1.276867.2813 | CD 26.2 | CID 20.0.1 | VMWare Workstation; XP (x32), 7 (x64) |
goved
Newbie
*
Offline Offline

Posts: 18


« Reply #4 on: December 25, 2011, 04:52:24 AM »

i done it,there is no unsafe applications.When i ran autorun.exe there are 46 unsafe items
Logged
goved
Newbie
*
Offline Offline

Posts: 18


« Reply #5 on: December 25, 2011, 05:01:43 AM »

also my ClamWin scanner found SymbOS.Spy.Smsanywhere 
Logged
wasgij6
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3062



WWW
« Reply #6 on: December 25, 2011, 01:33:30 PM »

its hard to say whats going on here.

it sounds like your computer is infected but nothing can be found. the only thing i can think of is to try Kaspersky Rescue Disk

Maybe somone else get give some more insight to the problem
Logged

| Win 7 Ultimate (x32) SP1; Admin | UAC Disabled | CIS 6.1.276867.2813 | CD 26.2 | CID 20.0.1 | VMWare Workstation; XP (x32), 7 (x64) |
Chiron
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5563



« Reply #7 on: December 26, 2011, 12:12:08 AM »

Did Kaspersky TDSSKiller find any problems?

Also, did you check out the files you found with Comodo Autoruns? If so then please post links to the Valkyrie results.

Thanks.
Logged

goved
Newbie
*
Offline Offline

Posts: 18


« Reply #8 on: December 26, 2011, 03:17:30 AM »

TrueSight         FLS.Unknown   C:\WINDOWS\system32\drivers\TrueSight.sys

00nView   NVIDIA Desktop Explorer, Version 110.49    NVIDIA Corporation   FLS.Unknown   C:\WINDOWS\system32\nvshell.dll

These are files recognized  as unsafe by Autorun analizer.The second one is reported 99.9% normal by Valkyrie and only one detector reports it as malware.First file Valkyrie says that it is active process,unkown final result.
TDSS didn't find anything wrong.I ran a COMODO'S cloud scanner ,it found some problems but still i don't delete them
Logged
goved
Newbie
*
Offline Offline

Posts: 18


« Reply #9 on: December 26, 2011, 04:06:40 AM »

i did scan with Sergiva portable toolkit.It found Trojan DownloaderWin32.Agent.au .This is located in Adobe \reader\ExtendScript.dll
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 16652



« Reply #10 on: December 26, 2011, 10:45:27 AM »

Run gmer anti rootkit scanner and post a screenshot of it. It is best to download the .exe file. The site will then send you the scanner with a random name.

Also let Hitman Pro, Super Antispyware, Spybot Search and Destroy, McAfee Stinger and Norton Power Eraser scan to see if they come up with something.
Logged

goved
Newbie
*
Offline Offline

Posts: 18


« Reply #11 on: December 27, 2011, 02:23:35 AM »

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-12-20 10:37:40
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP5T0L0-14 WDC_WD6400AAKS-08A7B0 rev.01.03B01
Running: gmer.exe; Driver: C:\DOCUME~1\User1\LOCALS~1\Temp\pxtdapow.sys


---- Kernel code sections - GMER 1.0.15 ----

.text  C:\WINDOWS\system32\DRIVERS\nv4_mini.sys                                                             section is writeable [0xBA040360, 0x2456AE, 0xE8000020]
?      C:\DOCUME~1\User1\LOCALS~1\Temp\mbr.sys                                                              The system cannot find the file specified. !

---- User code sections - GMER 1.0.15 ----

.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtCreateFile + 6               7C90D0B4 4 Bytes  [28, 00, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtCreateFile + B               7C90D0B9 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtMapViewOfSection + 6         7C90D524 1 Byte  [28]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtMapViewOfSection + 6         7C90D524 4 Bytes  [28, 03, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtMapViewOfSection + B         7C90D529 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtOpenFile + 6                 7C90D5A4 4 Bytes  [68, 00, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtOpenFile + B                 7C90D5A9 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtOpenProcess + 6              7C90D604 4 Bytes  [A8, 01, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtOpenProcess + B              7C90D609 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtOpenProcessToken + 6         7C90D614 4 Bytes  CALL 7B90EC1A
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtOpenProcessToken + B         7C90D619 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtOpenProcessTokenEx + 6       7C90D624 4 Bytes  [A8, 02, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtOpenProcessTokenEx + B       7C90D629 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtOpenThread + 6               7C90D664 4 Bytes  [68, 01, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtOpenThread + B               7C90D669 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtOpenThreadToken + 6          7C90D674 4 Bytes  [68, 02, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtOpenThreadToken + B          7C90D679 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtOpenThreadTokenEx + 6        7C90D684 4 Bytes  CALL 7B90EC8B
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtOpenThreadTokenEx + B        7C90D689 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtQueryAttributesFile + 6      7C90D714 4 Bytes  [A8, 00, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtQueryAttributesFile + B      7C90D719 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtQueryFullAttributesFile + 6  7C90D7B4 4 Bytes  CALL 7B90EDB9
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtQueryFullAttributesFile + B  7C90D7B9 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtSetInformationFile + 6       7C90DC64 4 Bytes  [28, 01, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtSetInformationFile + B       7C90DC69 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtSetInformationThread + 6     7C90DCB4 4 Bytes  [28, 02, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtSetInformationThread + B     7C90DCB9 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtUnmapViewOfSection + 6       7C90DF14 1 Byte  [68]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtUnmapViewOfSection + 6       7C90DF14 4 Bytes  [68, 03, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3224] ntdll.dll!NtUnmapViewOfSection + B       7C90DF19 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtCreateFile + 6               7C90D0B4 4 Bytes  [28, 00, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtCreateFile + B               7C90D0B9 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtMapViewOfSection + 6         7C90D524 1 Byte  [28]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtMapViewOfSection + 6         7C90D524 4 Bytes  [28, 03, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtMapViewOfSection + B         7C90D529 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtOpenFile + 6                 7C90D5A4 4 Bytes  [68, 00, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtOpenFile + B                 7C90D5A9 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtOpenProcess + 6              7C90D604 4 Bytes  [A8, 01, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtOpenProcess + B              7C90D609 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtOpenProcessToken + 6         7C90D614 4 Bytes  CALL 7B90EC1A
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtOpenProcessToken + B         7C90D619 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtOpenProcessTokenEx + 6       7C90D624 4 Bytes  [A8, 02, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtOpenProcessTokenEx + B       7C90D629 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtOpenThread + 6               7C90D664 4 Bytes  [68, 01, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtOpenThread + B               7C90D669 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtOpenThreadToken + 6          7C90D674 4 Bytes  [68, 02, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtOpenThreadToken + B          7C90D679 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtOpenThreadTokenEx + 6        7C90D684 4 Bytes  CALL 7B90EC8B
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtOpenThreadTokenEx + B        7C90D689 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtQueryAttributesFile + 6      7C90D714 4 Bytes  [A8, 00, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtQueryAttributesFile + B      7C90D719 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtQueryFullAttributesFile + 6  7C90D7B4 4 Bytes  CALL 7B90EDB9
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtQueryFullAttributesFile + B  7C90D7B9 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtSetInformationFile + 6       7C90DC64 4 Bytes  [28, 01, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtSetInformationFile + B       7C90DC69 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtSetInformationThread + 6     7C90DCB4 4 Bytes  [28, 02, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtSetInformationThread + B     7C90DCB9 1 Byte  [E2]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtUnmapViewOfSection + 6       7C90DF14 1 Byte  [68]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtUnmapViewOfSection + 6       7C90DF14 4 Bytes  [68, 03, 16, 00]
.text  C:\Program Files\Google\Chrome\Application\chrome.exe[3324] ntdll.dll!NtUnmapViewOfSection + B       7C90DF19 1 Byte  [E2]

---- EOF - GMER 1.0.15 ----
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 16652



« Reply #12 on: December 27, 2011, 12:49:11 PM »

Gmer detects only the Chrome. Which is expected as chrome runs its tabs as sandboxed processes.

Did the other scanners bring any solace to your situation?
Logged

goved
Newbie
*
Offline Offline

Posts: 18


« Reply #13 on: December 30, 2011, 03:48:26 PM »

after dr.web scaning i found trojan.MulDrop .Any solutions?
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 16652



« Reply #14 on: December 30, 2011, 08:16:15 PM »

What file(s) and registry keys make this trojan according to Dr. Web? Can you post a screenshot of the Dr Web results.
Logged

Tags:
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.061 seconds with 21 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com