Welcome, Guest. Please login or register.
Did you miss your activation email?
May 23, 2013, 10:13:37 PM

Login with username, password and session length

663848 Posts
70594 Topics
145226 Members

Latest Member: ashok_weird

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Virus/Malware Removal Assistance
| | |-+  Virus in DSL Modem
« previous next »
Pages: [1] Go Down Print
Author Topic: Virus in DSL Modem  (Read 6561 times)
chappy846
Newbie
*
Offline Offline

Posts: 7


« on: January 23, 2012, 05:46:48 AM »

I think I have a virus ,trojan  controlling my PC  Dell OS Vista Home Premium SP2Dual Core 2.40Ghz each 283 HHD lots of memory . my computer has remained infected  after clean installs .No spyware ever caught a clue , re; the bot ,virus ,Etc,. searched the web for possibility of infections in BIOS, and DSL modems . The modems made more sense than a BIOS . There are worms trojans that target modems . Any help on this ? Chappy846
« Last Edit: January 23, 2012, 05:53:09 AM by Ronny » Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 13182


Volunteer Moderator


« Reply #1 on: January 23, 2012, 05:52:33 AM »

Hi chappy846,

Can you first explain what the problem is and why you think it's a virus?
It's a bit hard to understand what's going on on your system(s)...
Logged

Volunteer Moderator
Any concerns? Please send me a PM or review the Forum Policy -  update Jan 3rd 2013!
chappy846
Newbie
*
Offline Offline

Posts: 7


« Reply #2 on: January 23, 2012, 08:52:02 AM »

Early on when i first found out I had a virus,bug of some kind , I did a clean install and , the virus , bug seemed to have been taken care of .Things went along and I began to notice that wierd things happened , one was as I clicked on the spyware button to load it , a momentary flash of the command screen would appear. It was so fast that if I blinked ,I may not have seen it. The cursor would tremble as I clicked on some files and not on others .

I ran several High Jack this scans as welll as others , I bgan  to see iyems that had been deleted were back on the next scan .

I just purchased another pc , this one .  Purchased at a good discount but still boxed ,no dust inside .when I got all the needed stuff done , plugged into DSL modem ,went on the net .when the first connection was made ,familliar things happened ,the same kind of things happened with the old PC.

 I  thought at the time thats weird . I went on with doing the web thing setting up browsers reinstalling programs used before.  I did not transfer anything from thr old computer at that time .

Then the same old things began to occur as  with the old PC . I knew it should not be possible for thiis to be . . On the web i searched for and found items related to problem . I am beginning to repest my self

Would you if possible ask me direct questions ,it would be easier  for me to reply . I am alittle old and slowiing down in thought processes.  Any thing you or others could do to lead me out of this pickle would help a lot . Chappy846
 Embarrassed
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 13182


Volunteer Moderator


« Reply #3 on: January 23, 2012, 09:18:23 AM »

We can ask direct questions but therefor we needed a little background information.
Based on your story I think there are two options.

One a rootkit on the system or two your Modem/Routers DNS servers are changed and you might not be browsing to what seems legit.
For rootkit detections can you please run the following tools to see if they detect anything?

TDSS Killer
http://support.kaspersky.com/downloads/utils/tdsskiller.exe

HitmanPro
http://www.surfright.nl/en/downloads/

Both free.
for your DNS settings, can you open a command-box (Start -> Run -> cmd  (Press ENTER)).
And then type

ipconfig /all

Please send me a PM with the output, it might contain information not to be exposed in the public here.
Logged

Volunteer Moderator
Any concerns? Please send me a PM or review the Forum Policy -  update Jan 3rd 2013!
chappy846
Newbie
*
Offline Offline

Posts: 7


« Reply #4 on: January 23, 2012, 10:54:08 AM »

sorry to be so obtuse , how do i message you ?
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 13182


Volunteer Moderator


« Reply #5 on: January 23, 2012, 11:08:25 AM »

sorry to be so obtuse , how do i message you ?

If you click on my name there is an option on the left below Actions "Send Personal Message".
Logged

Volunteer Moderator
Any concerns? Please send me a PM or review the Forum Policy -  update Jan 3rd 2013!
chappy846
Newbie
*
Offline Offline

Posts: 7


« Reply #6 on: January 23, 2012, 04:10:48 PM »

here is attachments as per request . the Kaspersky report was too big to sent this is a synopsys in stead


============================================================
07:57:21.0299 3764   Detected object count: 0
07:57:21.0299 3764   Actual detected object count: 0

no hitman attacment? I will do i it again TU Chappy846
Logged
Chiron
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 5582



« Reply #7 on: January 23, 2012, 10:51:43 PM »

If you like you can also follow the advice I give in How to Know If Your Computer Is Infected.

It's a little more work, but I think it's worth it.
Logged

chappy846
Newbie
*
Offline Offline

Posts: 7


« Reply #8 on: January 24, 2012, 01:25:22 AM »

I did all that . Killswitch gave everything a safe designation the other two were the same , no malware on pC.I think the bug is in the DSL modem .no scans of any type find nothing but tracking cookies on the PC

That left the BIOS , too much for my knowledge to try .

I web searched virus on DSL modems and got hits .About 4 years ago a new type of virus was hacking modems . It had to be a certain type of software on the modem to allow virus to take over . I went to my service provider and talked to them r; subject . They were kind enough to check operation of the modem .when all was over , the said thay are sending me a new modem ,and please return the old one .
No reasons given just replace modem . So I don't know for  sure if it was infected or not

I am hoping that without the support of the control in the modem , the virus on the PC can be deleted. ..

Thamks for the heads up  chappy5718
Logged
Chiron
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 5582



« Reply #9 on: January 24, 2012, 01:32:57 AM »

So just to be clear, there were not even any unknown files on the computer after following the methods I describe in my article?
Logged

chappy846
Newbie
*
Offline Offline

Posts: 7


« Reply #10 on: January 24, 2012, 07:17:49 AM »

When the new modem is installed I will have to scan, with CISPRO, PC..I don't think the virus,bug will go away on its own. Thanks again                   
Logged
5718Dewey
Comodo Member
**
Offline Offline

Posts: 32


« Reply #11 on: January 24, 2012, 02:37:11 PM »

I still dont have new modem as yet . BUT! with the new settings on old modem I was able to run cce . There were 15 threats that were taken care of . The system , Comodo works as long as it has proper acess to computer . I thank all of you for putting up with me .
I don't trust the download that came with tdsskiller , it came with malware . I will scan with cis pro later just to see whathappens there Thanks again 5718Dewey
Logged
Chiron
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 5582



« Reply #12 on: January 24, 2012, 09:58:58 PM »

I don't trust the download that came with tdsskiller , it came with malware .
What do you mean? What makes you think that there was malware with the download? Huh
Logged

chappy846
Newbie
*
Offline Offline

Posts: 7


« Reply #13 on: January 25, 2012, 09:25:04 PM »

It showed up on the cce scan as crried a virus .Google the tdsskiller and you will see some posts re; same. By the way you may mark my part in this as solved. I rcvd a new modem snd bought a new computer . Thanks for all your help.

Chappy846
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 13182


Volunteer Moderator


« Reply #14 on: January 26, 2012, 05:21:30 AM »

It showed up on the cce scan as crried a virus .Google the tdsskiller and you will see some posts re; same. By the way you may mark my part in this as solved. I rcvd a new modem snd bought a new computer . Thanks for all your help.

Chappy846
Well I'm willing to bet that was a so called False Positive, Comodo Flags TDSSKiller every new release because of the behaviors it has.
I keep reporting them as FP... unless you downloaded it from somewhere else I wouldn't be to afraid about that.
Probably rescanning now will no longer flag it.
Logged

Volunteer Moderator
Any concerns? Please send me a PM or review the Forum Policy -  update Jan 3rd 2013!
Tags: trojan proxy keepface 
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.049 seconds with 21 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com