Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
January 06, 2010, 09:19:35 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
348119
Posts
38500
Topics
87525
Members
Latest Member:
markusr
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Virus/Malware Removal Assistance
A 'morphing' virus, BLOCKED MY NET!
« previous
next »
Pages:
[
1
]
2
Author
Topic: A 'morphing' virus, BLOCKED MY NET! (Read 2079 times)
Nikwan3
Malware Research Group
Newbie
Offline
Posts: 15
A 'morphing' virus, BLOCKED MY NET!
«
on:
September 16, 2009, 12:54:31 PM »
Hi..
I recently discovered presence of two 'system' attribute files on my drives..
They spread through USB drives..
Also, since the time, my net is blocked, I can connect, but can not surf/download anything...! so NO AV UPDATES as well!!
One of the files is a autorun.ini and the other some*.pif..
I tried to change their attribute using some tools, succeeded with the *.pif file but it fails for autorun.ini..
Also, tried to delete them, but autorun.ini can not be...
also, if I unlock that file then two new files are created, new autorun.ini and *.pif, This time with a different (*.pif) name......!!!! Also this new autorun.ini points to this new *.pif file....!!
Awesome it is, some may think, BUT I need to remove them!!!!
I have yesterday's (15th Sep,09) virus definitions and COMODO FAILS TO DETECT THEM, not even warnings.... Those files are not excluded from scan and I DO NOT have ANY OTHER security software....
Any help from anyone....
Logged
Kevin D.
Newbie
Offline
Posts: 20
Re: A 'morphing' virus, BLOCKED MY NET!
«
Reply #1 on:
September 16, 2009, 01:05:15 PM »
Hello,
I think you could try to scan with SUPERAntiSpyware and Malwarebytes Anti-Malware.
Download these programs on another computer and burn them or put them on an USB stick. Then install it on your infected computer and run a complete scan.
Big chance these programs will find the virus and remove it.
Good luck,
Logged
Nikwan3
Malware Research Group
Newbie
Offline
Posts: 15
Re: A 'morphing' virus, BLOCKED MY NET!
«
Reply #2 on:
September 16, 2009, 01:11:55 PM »
Thanks for your reply..
Already working on it..
Logged
clockwork
Comodo Loves me
Offline
Posts: 187
Re: A 'morphing' virus, BLOCKED MY NET!
«
Reply #3 on:
September 16, 2009, 01:28:52 PM »
why wasnt it blocked by comodos defense+?
if you cant erase the autorun ini, because its active, maybe try one of the (free) boot antivirus programs. i think avira has one, for example.
a good secondary (free) antivirus for on demand tests is "a squared" (free version has no guard anyway). i can suggest to use one other antivirus for scanning, if you use comodo av as the guard. main reason: exclusion list grows of false positives, and sometimes its important to know when you have a virus on a drive. maybe not for yourself (you have the default deny, mostly), but for those who get files from you. they dont have a default deny, mostly.
i returned after a test of comodos av to my "proved for years av". there are very good free ones out there
Logged
Kevin D.
Newbie
Offline
Posts: 20
Re: A 'morphing' virus, BLOCKED MY NET!
«
Reply #4 on:
September 16, 2009, 02:10:59 PM »
Indeed, strange it hasn't been blocked by Defense+. Is Defense+ activated and switched to safe mode or paranoid mode?
Avira's Antivir scanner is a good one, and free too! Good to use as active virusscanner, next to the Comodo Firewall and Defense+. This combination works very well and I can recommend it.
Besides that I use SUPERAntiSpyware and MalwareBytes AntiMalware for a manual scan once in a while, and ofcourse on infected systems to remove something. But with above config the chance you will get a virus is very small. Even if Antivir (or Comodo AV or another one) fails to detect the virus, big chance Defense++ will block it/let you block it.
«
Last Edit: September 16, 2009, 02:23:50 PM by Kevin D.
»
Logged
Nikwan3
Malware Research Group
Newbie
Offline
Posts: 15
Re: A 'morphing' virus, BLOCKED MY NET!
«
Reply #5 on:
September 16, 2009, 02:21:43 PM »
Yes, Defence+ is active and is in Paranoid mode actually...
But its not only me who uses this computer, its sort of a Family computer!!!
I hope you get me!!
Logged
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 4467
Re: A 'morphing' virus, BLOCKED MY NET!
«
Reply #6 on:
September 16, 2009, 05:22:39 PM »
Put the hard drive of your computer in another computer and delete the two files from there. Does this help?
Logged
Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , Always the latest CIS or CIS Beta (too lazy to update my sig) Athlon XP 2600 1 GB RAM. Opera Browser always using the latest snapshots; Opera 10.10 as of now
Kevin D.
Newbie
Offline
Posts: 20
Re: A 'morphing' virus, BLOCKED MY NET!
«
Reply #7 on:
September 16, 2009, 05:58:04 PM »
And you could try to boot in Safe mode, maybe you can delete the files then. Or boot with a linux live CD like Knoppix or Ubuntu and delete the files.
Logged
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
Offline
Posts: 1722
The only thing i ask for are eggs.
Re: A 'morphing' virus, BLOCKED MY NET!
«
Reply #8 on:
September 16, 2009, 06:03:34 PM »
From the CIMA report of the malware you uploaded to it..
http://camas.comodo.com/cgi-bin/submit?file=c6842d2bbb41fafae60dc4d12f7e5b312b7fa055b697865d1674a7509371d621
• Families
Possible Families Detected
Virus.Win32..Sality.Gen
• Description
Suspicious Actions Detected
Disables windows firewall
Injects code into other processes
If it is Sality, then its hard to remove. It infects other programs... CIS maybe infected already.... BUT what ever you do, dont remove CIS. you are going to need something that can cure files. A normal AV wont do it.
Logged
Happy New Year and Holidays
Please follow forum policy. Thank you.
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 4467
Re: A 'morphing' virus, BLOCKED MY NET!
«
Reply #9 on:
September 16, 2009, 07:30:59 PM »
Dr Web's
Live CD
is known to be able to successfully clean these type of infections.
Download the image from the link in the above on a clean computer and burn the ISO image to a CD. Boot from the CD in the other computer and let the virus scanner update and run.
Watch this video from Remove-malware by Matt for reference:
http://www.youtube.com/watch?v=FGDl-IMOt1g
. It shows the process of using Dr Web Live CD to tackle this infecting type of viruses.
Logged
Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , Always the latest CIS or CIS Beta (too lazy to update my sig) Athlon XP 2600 1 GB RAM. Opera Browser always using the latest snapshots; Opera 10.10 as of now
Nikwan3
Malware Research Group
Newbie
Offline
Posts: 15
Re: A 'morphing' virus, BLOCKED MY NET!
«
Reply #10 on:
September 17, 2009, 01:46:07 PM »
[at] EricJH and Kevin D.
I run Ubuntu as my second OS. Tried deleting those diles already..
But no use...!!
Also, those two files are not there on my local hard drives but get CREATED on every USB drive I cannect!!!
Irrespective of how many tries I have made at deleting them from there....!
[at] Kevin D.
Tried ur suggestion for using SUPERAntiSpywar, dint help... It did not detect anything...
[at]OmeletGuy
Do you also mean something like the Dr. Web's Live CD, that can cure infections?
[at]EricJH
Will try that LiveCD and reply back..!
Thanks all!
Logged
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 4467
Re: A 'morphing' virus, BLOCKED MY NET!
«
Reply #11 on:
September 17, 2009, 06:05:55 PM »
Good luck and keep us posted.
Logged
Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , Always the latest CIS or CIS Beta (too lazy to update my sig) Athlon XP 2600 1 GB RAM. Opera Browser always using the latest snapshots; Opera 10.10 as of now
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
Offline
Posts: 1722
The only thing i ask for are eggs.
Re: A 'morphing' virus, BLOCKED MY NET!
«
Reply #12 on:
September 17, 2009, 06:47:40 PM »
Quote from: Nikwan3 on September 17, 2009, 01:46:07 PM
[at]OmeletGuy
Do you also mean something like the Dr. Web's Live CD, that can cure infections?
Yes this is what i meant.
Good luck.
Logged
Happy New Year and Holidays
Please follow forum policy. Thank you.
Guillermo391
Comodo Member
Offline
Posts: 38
Re: A 'morphing' virus, BLOCKED MY NET!
«
Reply #13 on:
September 18, 2009, 09:20:45 AM »
Does anyone know if CIS v4 will be able to cure files like Dr Web?
Logged
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
Offline
Posts: 1722
The only thing i ask for are eggs.
Re: A 'morphing' virus, BLOCKED MY NET!
«
Reply #14 on:
September 18, 2009, 12:07:04 PM »
Quote from: Guillermo391 on September 18, 2009, 09:20:45 AM
Does anyone know if CIS v4 will be able to cure files like Dr Web?
Yes it will be able to cure infection... but it may have to use CTM, Comodo Time Machine.
Logged
Happy New Year and Holidays
Please follow forum policy. Thank you.
Tags:
virus
usb
autorun.ini
Block
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to Help Comodo?
-----------------------------
=> Help Spread the Word - Banners and Logos
=> How Can I Help Comodo? (Please We Need You!)
===> Help Spread the Word! (Please Read and Help)
===> Report Comodo Forum / Web Site Issues
=> Please Tell Us Your Views and Vote Here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Help - CIS
=====> AntiVirus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> AntiVirus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> AntiVirus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> AntiVirus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> Graphical User Interface (GUI) Wishlist
===> Bug Report - CIS
=====> AntiVirus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> GUI / Miscellaneous / Other Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
===> Help - CTM
===> Feedback/Comments/Announcements/News - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless World!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to You)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Other Security Products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
=> Other Firewalls
=> Host Intrusion Prevention Systems (HIPS)
=> AntiPhishing Solutions
Page created in 0.046 seconds with 19 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com