Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 21, 2010, 06:34:59 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
373404
Posts
41421
Topics
94148
Members
Latest Member:
Sebo77
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Virus/Malware Removal Assistance
possible malware here?
« previous
next »
Pages:
1
[
2
]
Author
Topic: possible malware here? (Read 2545 times)
mr fett
Newbie
Offline
Posts: 21
Re: possible walware here?
«
Reply #15 on:
October 25, 2009, 02:26:14 PM »
Thanks- I appreciate you looking at it. What about that A2 log? Is that the normal appearance? I ask because this all prompted me to do a multi-scan of my desktop computer, and while Malwarebutes and SuperantiSpyware only found cookies, A2 is finding more cookies and some medium risk registry stuff that looks alarming along with some high risk stuff. I wanted to post the A2 log when it finishes to get your opinion, but I want to make sure I post a correct log file that can be read and makes sense. Is it standard protocol to just convert the db3 file to txt after it is saved, or should I be saving it as something different? I'm wondering if the trojan I had a few weeks ago that I thought I removed is still there.
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
Offline
Posts: 6891
Why not ? The choice is yours !
Re: possible walware here?
«
Reply #16 on:
October 25, 2009, 03:15:24 PM »
Quote from: mr fett on October 25, 2009, 02:26:14 PM
Thanks- I appreciate you looking at it. What about that A2 log? Is that the normal appearance? I ask because this all prompted me to do a multi-scan of my desktop computer, and while Malwarebutes and SuperantiSpyware only found cookies, A2 is finding more cookies and some medium risk registry stuff that looks alarming along with some high risk stuff. I wanted to post the A2 log when it finishes to get your opinion, but I want to make sure I post a correct log file that can be read and makes sense. Is it standard protocol to just convert the db3 file to txt after it is saved, or should I be saving it as something different? I'm wondering if the trojan I had a few weeks ago that I thought I removed is still there.
Hi,
well no, that's not really common to change it. But that allows me to take a look at it.
***looking at it***
***finds a corrupted file***
well, can't use it, sorry.
Could you do a scan and take a screenshot of the results (remember to expand all tabs so I can see where the files are !) ? (
How to take screenshots
)
eXPerience
Logged
mr fett
Newbie
Offline
Posts: 21
Re: possible walware here?
«
Reply #17 on:
October 25, 2009, 04:03:12 PM »
I think a part of my issue is in the fact that before closing down A2, I tried quarantining the 4 found objects. I wasn't allowed to, so I didn't get a typical list of threats like I've seen in Adaware, etc- which I assume is the log file you're after? The log file created by A2 that I found looks like it's just the actions it carried out, not the files I saw it find (if this makes any sense), sort of what a Search and Destroy logfile looks like to me. I've never used the program before, so I don't know how it works. If I posted the correct file, how do people upload it so that it can be read if it's saved as a db3 file by the program? i can't find any options on controlling the log file saves. Sorry, but this program seems to be more confusing than what it seems it should be. Maybe you and I are are talking about 2 different things, and I can't explain myself well enough? Sorry to be a PITA....
My desktop A2 scan is still running so when it's done I'll do a screenshot. Are you wanting a screenshot of the A2 scan interface where it lists the objects? If so, the full list all won't fit onto one screen shot, and the names of some are so long they need to be scrolled to see them entirely. Would I take a shot, then scroll then take another shot?
Quote from: eXPerience on October 25, 2009, 03:15:24 PM
Hi,
well no, that's not really common to change it. But that allows me to take a look at it.
***looking at it***
***finds a corrupted file***
well, can't use it, sorry.
Could you do a scan and take a screenshot of the results (remember to expand all tabs so I can see where the files are !) ? (
How to take screenshots
)
eXPerience
Logged
mr fett
Newbie
Offline
Posts: 21
Re: possible walware here?
«
Reply #18 on:
October 25, 2009, 05:22:04 PM »
I don't know how I messed up with the logfile/report from my laptop, but here's the report and screenshots for my desktop A2 scan. The last 2 on drive H are safe. It's the other ones I don't know about. The Ultra VNC is a program a buddy put on my computer who is much more savvy than I, so I assume they're ok too.
i happened to find a db3 file for this one too- looks like I mistook it before dor a log report that I never actually saved
I have no idea now why it looks so messed up....
Here also is the Hijack This log
«
Last Edit: October 25, 2009, 05:42:56 PM by mr fett
»
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
Offline
Posts: 6891
Why not ? The choice is yours !
Re: possible walware here?
«
Reply #19 on:
October 26, 2009, 03:41:38 AM »
Hi,
I sujest you quarentine :
- spywarebot
- the IE plugin
- HTML.infected
- Trojan.generic!IK
best regards,
eXPerience
Logged
mr fett
Newbie
Offline
Posts: 21
Re: possible walware here?
«
Reply #20 on:
October 26, 2009, 07:48:56 PM »
Thanks.
The program cannot quarantine the spywarebot (2 traces). I get an error message for them, saying they cannot be deleted, and to consult the experts at the A2 forum. This is the same message I got when I tried quarantining the 4 objects on my laptop. What do you suggest now?
This may sound like a dumb question, but why am I only quarantining these objects, and not deleting them? What do I do with them now that they are quarantined? Once I delete eventually them do I do a system clean on that drive, delete all restore points and re-scan?
Should I be deleting all the other things (tracking cookies, etc) so they don't sit there and pop up again on future scans? Is there a way in A2 to ignore the files I know are false positives so they don't pop up again? I can't seem to find an ignore option.
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
Offline
Posts: 6891
Why not ? The choice is yours !
Re: possible walware here?
«
Reply #21 on:
October 27, 2009, 03:41:16 AM »
Quote
Should I be deleting all the other things (tracking cookies, etc) so they don't sit there and pop up again on future scans? Is there a way in A2 to ignore the files I know are false positives so they don't pop up again? I can't seem to find an ignore option.
I think rightclicking and adding to the whitelist should do if I remember right?
Quote
The program cannot quarantine the spywarebot (2 traces). I get an error message for them, saying they cannot be deleted, and to consult the experts at the A2 forum. This is the same message I got when I tried quarantining the 4 objects on my laptop. What do you suggest now?
I'm a bit puzzled, because I don't know if it's actually cleaned now or not....... Hijackthis looks clean....
Well, if you really feel you need to I sujest you scan with Superantispyware. if that doesn't help, you will need to look for more expert cleaning : Comodo LivePcSupport
Quote
This may sound like a dumb question, but why am I only quarantining these objects, and not deleting them? What do I do with them now that they are quarantined? Once I delete eventually them do I do a system clean on that drive, delete all restore points and re-scan?
It's safer, imagine that you actually need those files for an application or so, well, you can still repair it then. If you delete it, it's lost forever.
eXPerience
Logged
Kyle
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 3370
Re: possible walware here?
«
Reply #22 on:
October 27, 2009, 05:59:46 AM »
Can a Mod please correct the spelling of the topic? I know I'm being fussy.. It just tickles me every time I see it.. lol
Logged
Windows XP
E5200 2.5ghz [at] 3.33ghz, POV 9800gt 512mb, 2gb DDR2 RAM. 500gb. HDD
Ubuntu
P4 [at] 3ghz, Radeon x300 128mb
1gb DDR2 Ram 80GB HDD
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
Offline
Posts: 6891
Why not ? The choice is yours !
Re: possible walware here?
«
Reply #23 on:
October 27, 2009, 10:52:10 AM »
Quote from: Kyle on October 27, 2009, 05:59:46 AM
Can a Mod please correct the spelling of the topic? I know I'm being fussy.. It just tickles me every time I see it.. lol
I find it funny, that's why I kept it there in the first place
ok, I only changed the OP
eXPerience
Logged
mr fett
Newbie
Offline
Posts: 21
Re: possible walware here?
«
Reply #24 on:
October 27, 2009, 02:24:00 PM »
Quote from: Kyle on October 27, 2009, 05:59:46 AM
Can a Mod please correct the spelling of the topic? I know I'm being fussy.. It just tickles me every time I see it.. lol
yeah, I noticed that a while ago, but didn't know how to fix it. At least I could find my post easily
oops
Logged
mr fett
Newbie
Offline
Posts: 21
Re: possible walware here?
«
Reply #25 on:
October 27, 2009, 02:26:24 PM »
Quote from: eXPerience on October 27, 2009, 03:41:16 AM
I think rightclicking and adding to the whitelist should do if I remember right?
I'm a bit puzzled, because I don't know if it's actually cleaned now or not....... Hijackthis looks clean....
Well, if you really feel you need to I sujest you scan with Superantispyware. if that doesn't help, you will need to look for more expert cleaning : Comodo LivePcSupport
It's safer, imagine that you actually need those files for an application or so, well, you can still repair it then. If you delete it, it's lost forever.
eXPerience
OK- I'll try this when I get home from work tonight. From what I remember thoguh, Superantispyware didn't find those objects in the first place....
I'll re-run everything and see what I find.
Thanks.
Logged
mr fett
Newbie
Offline
Posts: 21
Re: possible malware here?
«
Reply #26 on:
October 28, 2009, 08:01:20 PM »
A2 and Hijack This logs from follow up scan. The "undeletable" files didn't show up for some reason but the 2 other objects did. Spybot, Malwarebytes, SuperAntispaware, and Adaware all missed them. So I cleaned all drives and deleted restore points, restarted and scanned again with A2- nothing found. I'll have to see if they pop up again in a couple days....
Logged
Tags:
Pages:
1
[
2
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 0.097 seconds with 19 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com