Welcome, Guest. Please login or register.
Did you miss your activation email?
May 25, 2013, 12:16:07 AM

Login with username, password and session length

664016 Posts
70627 Topics
145259 Members

Latest Member: treablefelp

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Virus/Malware Removal Assistance
| | |-+  Infection Found? What Do I Do Next?
« previous next »
Pages: [1] Go Down Print
Author Topic: Infection Found? What Do I Do Next?  (Read 5635 times)
Fastflys
Newbie
*
Offline Offline

Posts: 16


« on: September 30, 2011, 09:04:38 AM »

Hi

Just run a manual scan and 01 infection was found.

Threat Name: Rootkit.HiddenValue[at]0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\OE

I just use a computer so am a complete novice when it comes to something like this.  I believe that the above is a Registry key?  If so why is Comodo flagging it up as a possible infection?  I know that it's not good to mess around with Registry entries so what do I do next?  I'm tempted to hit the "Ignore" button as my computer appears to be running just fine.

If any of you are kind enough to offer help, can you please treat me as you would a child and give me simple instructions as I really don't understand the jargon at all.

Thanks in advance
FF
Logged
malwarekiller
Comodo Loves me
****
Offline Offline

Posts: 143



« Reply #1 on: October 04, 2011, 12:29:29 AM »

Please quarintine the file with comodo and send it to comodo from the quarintine area... Smiley

Now,to crosscheck your computer is clean.....perform a scan with AVP tool and delete if disinfections is not possible. Cheesy

http://www.kaspersky.com/antivirus-removal-tool-register

Just fill in a short form and your download will start....update and scan... Cool
Logged
Fastflys
Newbie
*
Offline Offline

Posts: 16


« Reply #2 on: October 04, 2011, 01:33:31 AM »

Thanks for your response.

1st - Comodo cannot quarantine this registry key? file
2nd - Could this key/file be a key/file hidden by Windows OS? as it appears to relate to the running of Outlook Express and cannot be quarantined?
3rd - How do I forward this key/file to Comodo if I can't quarantine it?
Logged
SiberLynx
Comodo's Hero
*****
Offline Offline

Posts: 2159



« Reply #3 on: October 05, 2011, 06:11:43 AM »

Please quarintine the file with comodo and send it to comodo from the quarintine area...
etc.
"quarIntine"  File?!  Huh

Do you know what are you talking about?
Sure you have no idea … as usual... & you are reported again to the moderators

=======

Hi  Fastflys,

Please do not follow any advice given by malwarekiller
Read this thread & this message

I don't see the attention by mods yet & it's sad & dangerous
There were several similar “advices”.  It has to be stopped!

...Threat Name: Rootkit.HiddenValue[at]0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\OE
This detection is most likely False Positive

Please rather wait for the response from  Comodo's support staff

Meanwhile supply more info about your system:
OS & Service Pack; platform (x64 or 32 bit)
Version of Comodo installed & current DB of AV
Version of OE that you are running;
etc. ...more info – better

As for the detection – you rather send precise (copied, but not just typed)  message from the log and/or  attach an image

My regards
« Last Edit: October 06, 2011, 05:09:57 AM by SiberLynx » Logged

admin; XP Pro, SP3 (32bit); CIS 3.14.130099.587 (firewall only; Proactive with Defense+)- that is the only Comodo's thing I need; Emsisoft - Mamutu Behavioural Blocker or Full EAM
Win 7 x64: Comodo Firewall 3.14; Emsisoft Anti-Malware
clockwork
Comodo's Hero
*****
Offline Offline

Posts: 1919


Oxygen requires Chuck Norris to live


« Reply #4 on: October 05, 2011, 09:37:32 PM »

Just get another free scanner without an own guard feature, for a second opinion.

Its easy as that Smiley

Why should a false positive make work?
Logged

"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
SiberLynx
Comodo's Hero
*****
Offline Offline

Posts: 2159



« Reply #5 on: October 06, 2011, 05:28:26 AM »

Hi clockwork,

Sure getting second opinion by another scanner (or many) is much better approach compare to insanity posted by malwarekiller,
at the same time please remember what the OP said - he is a novice
So even installation of an additional security  (without real-time residents) can be problematic & even lead to more confusion/& possible conflicts at this stage (you know that)

Can you please clarify for me your statement
...Why should a false positive make work?
I don't dig it. What that suppose to mean? Honestly ... no offense intended   Smiley

Cheers!
Logged

admin; XP Pro, SP3 (32bit); CIS 3.14.130099.587 (firewall only; Proactive with Defense+)- that is the only Comodo's thing I need; Emsisoft - Mamutu Behavioural Blocker or Full EAM
Win 7 x64: Comodo Firewall 3.14; Emsisoft Anti-Malware
clockwork
Comodo's Hero
*****
Offline Offline

Posts: 1919


Oxygen requires Chuck Norris to live


« Reply #6 on: October 06, 2011, 08:17:55 AM »

A second opinion of another free antivirus, without an own guard itself (to avoid incompatibillities), is the easiest suggestion in this case, and the smartest way to act.
And most likely it will come out to be a false positive, so anything else would be too much work (sending files to comodo [confusion], quarantine [maybe bad effects on system if the file is legit], logging, system specifications writing, ect....)


To make it very easy to find a good second opinion antivirus:
Try emsisoft antimalware free version (old name was a-squared free). Its easier to install a product, than to follow any other suggestions.

Logged

"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
georgef
Newbie
*
Offline Offline

Posts: 5


« Reply #7 on: October 08, 2011, 03:16:09 PM »

The best way to deal with this is to delete the root key go to run > regedit > HKEY_CURRENT_USER > Software > Microsoft > Windows >CurrentVersion > Run > OE  this will take out the root virus (note if your on windows vista or 7 your run is also your search bar in the start menu.)
Logged
SiberLynx
Comodo's Hero
*****
Offline Offline

Posts: 2159



« Reply #8 on: October 08, 2011, 10:02:46 PM »

The best way to deal with this is to delete the root key go to run > regedit > HKEY_CURRENT_USER > Software > Microsoft > Windows >CurrentVersion > Run > OE  this will take out the root virus (note if your on windows vista or 7 your run is also your search bar in the start menu.)
Hi georgef ,

Why would you say so Huh
Did you read the posts above?

What can you say about the system of the OP?
What do you know about "how he is running OE"?
What do you know whether he is an Admin or running under Limited User Account?
....etc....
Have noticed that OE .... and most importantly - the System is working fine ?

So why in Hell one have to delete the reg entry? considering the fact  that Comodo's AV  still has high rate of FPs

My regards
« Last Edit: October 08, 2011, 10:04:21 PM by SiberLynx » Logged

admin; XP Pro, SP3 (32bit); CIS 3.14.130099.587 (firewall only; Proactive with Defense+)- that is the only Comodo's thing I need; Emsisoft - Mamutu Behavioural Blocker or Full EAM
Win 7 x64: Comodo Firewall 3.14; Emsisoft Anti-Malware
clockwork
Comodo's Hero
*****
Offline Offline

Posts: 1919


Oxygen requires Chuck Norris to live


« Reply #9 on: October 09, 2011, 07:36:35 AM »

The best way to deal with this is to delete the root key go to run > regedit > HKEY_CURRENT_USER > Software > Microsoft > Windows >CurrentVersion > Run > OE  this will take out the root virus (note if your on windows vista or 7 your run is also your search bar in the start menu.)
Lets say, IF this registry entry has been made by a virus, why should removing this registry entry solve anything?
Most likely you get in trouble if you erase things without verifying their kind.

False positives can happen. So you should not just read the file adress to remove the file/entry.

More worse than no answer is a wrong answer.
« Last Edit: October 09, 2011, 07:38:42 AM by clockwork » Logged

"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
Chiron
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5588



« Reply #10 on: October 09, 2011, 09:31:43 PM »

This detection is most likely False Positive
I would tend to agree with this. Currently the rootkit scanner in CIS finds many false positives if enabled. Mine shows 3 for my computer, and I can guarantee you that each is a FP.

That said, you can't be sure whether it is a FP or not. If you like you can read a few reviews about some other rootkit scanners and check your computer with some of them. Of course, with rootkit scanners, I always advise not removing anything until you get the advice of experts.

Please let us know what they find. Thanks.
Logged

Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.06 seconds with 21 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com