Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 19, 2013, 07:55:26 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663101
Posts
70495
Topics
153494
Members
Latest Member:
flowdesee
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Virus/Malware Removal Assistance
HELP, rootkit.hiddenfolder, rootkit.hiddenfile
« previous
next »
Pages:
1
[
2
]
3
Author
Topic: HELP, rootkit.hiddenfolder, rootkit.hiddenfile (Read 17716 times)
panic
Global Moderator
Comodo's Hero
Offline
Posts: 11173
Linux is free only if your time is worthless.;-)
Re: HELP, rootkit.hiddenfolder, rootkit.hiddenfile
«
Reply #15 on:
June 21, 2012, 07:03:31 PM »
[at]pisselone,
Your links to freefilehosting.net do not work. Can tou please attach the logs (as an attachment) to a post on these forums, rather than uploading to a 3rd party site and linking to them.
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you can't conform, don't use the forum.
Grosbébé
Comodo Member
Offline
Posts: 48
Re: HELP, rootkit.hiddenfolder, rootkit.hiddenfile
«
Reply #16 on:
June 21, 2012, 10:31:01 PM »
Hello
Yes, it's better if your logs are attached. Freefilehosting is blocked by WOT and Norton ConnectSafe.
Well, I read your logs and one thing which appeared in your first post is still here.
Are you using both Microsoft Security Essentials and Comodo Antivirus ? Having two active antivirus can lead to major bugs. If you have these two antivirus, I advise you to uninstall one of them.
Download ComboFix from one of these locations:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
* IMPORTANT !!! Save ComboFix.exe to your Desktop
Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon (disable Defense+ and Antivirus). They may otherwise interfere with our tools.
Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the
C:\ComboFix.txt
log in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Logged
pisellone
Newbie
Offline
Posts: 14
Re: HELP, rootkit.hiddenfolder, rootkit.hiddenfile
«
Reply #17 on:
June 22, 2012, 05:30:18 AM »
"attach"
i didn't see this option before !!!
OTL.Txt
(195.65 KB - downloaded 2 times.)
Logged
pisellone
Newbie
Offline
Posts: 14
Re: HELP, rootkit.hiddenfolder, rootkit.hiddenfile
«
Reply #18 on:
June 22, 2012, 05:31:32 AM »
and the other
Extras.Txt
(31.87 KB - downloaded 1 times.)
Extras.Txt
(31.87 KB - downloaded 1 times.)
Logged
pisellone
Newbie
Offline
Posts: 14
Re: HELP, rootkit.hiddenfolder, rootkit.hiddenfile
«
Reply #19 on:
June 22, 2012, 05:40:22 AM »
to Grosbébé:
(sorry again for my bad english)
i'm using microft essential and comodo because the virus was on my pc, has disabled a lot of security options..
virus has removed, but damages are remained
now i can't use microsoft firewall
i can't open security center
and i can't deactivate microsoft security essential
.. now i try combofix
EDIT:
combofix does nothing.. only created 2 folders:
32788R22FWJFW
ComboFix
«
Last Edit: June 22, 2012, 06:39:00 AM by pisellone
»
Logged
languy99
Global Moderator
Comodo's Hero
Offline
Posts: 3943
Re: HELP, rootkit.hiddenfolder, rootkit.hiddenfile
«
Reply #20 on:
June 22, 2012, 06:54:31 AM »
try using Comodo cleaning essentials, open up killswitch and try the Quick repair from the tool bar at the bottom.
Logged
http://www.youtube.com/languy99
Software Reviews for all.
Follow me on Twitter
http://twitter.com/#!/languy99
pisellone
Newbie
Offline
Posts: 14
Re: HELP, rootkit.hiddenfolder, rootkit.hiddenfile
«
Reply #21 on:
June 25, 2012, 09:10:04 AM »
combofix deleted ROOTKIT.ZEROACCESS
comodo scan gives 0 infections now
thanks to all
Logged
Grosbébé
Comodo Member
Offline
Posts: 48
Re: HELP, rootkit.hiddenfolder, rootkit.hiddenfile
«
Reply #22 on:
June 25, 2012, 03:04:32 PM »
Hello
Quote from: pisellone on June 22, 2012, 05:40:22 AM
to Grosbébé:
(sorry again for my bad english)
No problem, english is not my mother tongue, I understand how difficult it is
Quote
i'm using microft essential and comodo because the virus was on my pc, has disabled a lot of security options..
virus has removed, but damages are remained
Ok, and now, do you still see something unusual ?
By the way, you should only keep one real time protection, please uninstall Microsoft Security Essentials or CIS.
Quote
combofix deleted ROOTKIT.ZEROACCESS
comodo scan gives 0 infections now
Great, could you please attach the combofix log ? Absence of symptoms does not mean that everything is clear.
Regards.
Logged
pisellone
Newbie
Offline
Posts: 14
Re: HELP, rootkit.hiddenfolder, rootkit.hiddenfile
«
Reply #23 on:
June 25, 2012, 03:52:51 PM »
the only thing changed is the pc speed: now is good !
microsoft s. essential uninstalled from control panel
and this is combofix.txt, but it doesnt tell a lot:
ComboFix 12-06-21.03 - merdows7 25/06/2012 15:23:04.1.2 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1252.39.1040.18.958.460 [GMT 2:00]
Eseguito da: C:\Users\merdows7\Desktop\ComboFix.exe
AV: COMODO Antivirus *Enabled/Updated* {458BB331-2324-0753-3D5F-1472EB102AC0}
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
FW: COMODO Firewall *Enabled* {7DB03214-694B-060B-1600-BD4715C36DBB}
SP: COMODO Defense+ *Enabled/Updated* {FEEA52D5-051E-08DD-07EF-2F009097607D}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
Logged
Grosbébé
Comodo Member
Offline
Posts: 48
Re: HELP, rootkit.hiddenfolder, rootkit.hiddenfile
«
Reply #24 on:
June 29, 2012, 03:02:32 AM »
Indeed.
Could you please run it again. Then attach the log
If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.
Logged
pisellone
Newbie
Offline
Posts: 14
Re: HELP, rootkit.hiddenfolder, rootkit.hiddenfile
«
Reply #25 on:
June 29, 2012, 12:08:30 PM »
never done money operations from pc... they cannot stone nothing !!
ok: the second scan with combofix is clean, the report is longer than first, and he talks about the cleaning action of the first scan,
attached the file.txt
but when it finish, comodo gives this:
edit: uhm.. I think is a test file, not a malware
ComboFix.txt
(12.16 KB - downloaded 3 times.)
«
Last Edit: June 29, 2012, 12:10:17 PM by pisellone
»
Logged
Grosbébé
Comodo Member
Offline
Posts: 48
Re: HELP, rootkit.hiddenfolder, rootkit.hiddenfile
«
Reply #26 on:
June 29, 2012, 03:15:47 PM »
Hello
The Combofix log is incomplete, but it should be ok.
Please be sure to disable Defense+
========================================================
Some of the issues you describe at the beginning may still be there, i'd like to verify.
Please
click here
to download
Farbar Service Scanner (FSS)
to your desktop
Run
FSS
Tick all options ...
... and click on the "
Scan
" button.
Once done, it will create a log (FSS.txt) in the same directory the tool is run.
Close
Farbar Service Scanner
and attach the log.
========================================================
Run OTL
Under the
Custom Scans/Fixes
box at the bottom, paste in the following
Code:
:OTL
DRV - File not found [Kernel | System | Stopped] -- C:\Windows\system32\drivers\oowhvvfl.sys -- (oowhvvfl)
:Files
C:\Windows\system32\dds_log_trash.cmd
:Commands
[purity]
[emptytemp]
Then click the
Run Fix
button at the top
Let the program run unhindered, reboot when it is done
Then attach a new OTL log. (run OTL, click
Quick Scan
)
========================================================
Enable Defense+
Logged
pisellone
Newbie
Offline
Posts: 14
Re: HELP, rootkit.hiddenfolder, rootkit.hiddenfile
«
Reply #27 on:
June 29, 2012, 09:42:49 PM »
the surprise is:
after the last reboot, security center, windows firewall, and microsoft defender, are working !!!
if you are talking about this, i think the farbar is not necessary, true?
i think it's time to make a ghost backup of my pc
Logged
Grosbébé
Comodo Member
Offline
Posts: 48
Re: HELP, rootkit.hiddenfolder, rootkit.hiddenfile
«
Reply #28 on:
June 30, 2012, 03:25:30 AM »
Quote from: pisellone on June 29, 2012, 09:42:49 PM
after the last reboot, security center, windows firewall, and microsoft defender, are working !!!
if you are talking about this, i think the farbar is not necessary, true?
True
Quote
i think it's time to make a ghost backup of my pc
Not now, please wait, all the nasty files are still present on your system.
Logged
pisellone
Newbie
Offline
Posts: 14
Re: HELP, rootkit.hiddenfolder, rootkit.hiddenfile
«
Reply #29 on:
July 04, 2012, 08:54:27 AM »
what have i to do, before the ghost ?
Logged
Tags:
Pages:
1
[
2
]
3
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.051 seconds with 20 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com