Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
November 18, 2008, 05:15:41 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
212209
Posts
24527
Topics
57703
Members
Latest Member:
Striken7
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Virus/Malware Removal Assistance
am i infected ?
« previous
next »
Pages:
[
1
]
2
3
Author
Topic: am i infected ? (Read 4083 times)
gandalicious
Bad guy
Global Moderator
Comodo's Hero
Offline
Posts: 3496
kkeewwwwlll
am i infected ?
«
on:
November 03, 2007, 12:35:36 AM »
hi
just downloaded drwebcureit,
i attached the result. all the infections are on C\system volume information.
what should i do about the infected items? may i just remove/delete them since i can't cure them.
been using Avira (CAVS before), Spyware Terminator, spyware blaster, CFP,CMG,CBO, and these nasties still managed to enter?
man! i'm scared!
p.s. i don't notice anything weird happens to my computer.
ganda
Logged
~cat~
Global Moderator
Comodo's Hero
Offline
Posts: 964
CBO "...there is nothing better."
Re: am i infected ?
«
Reply #1 on:
November 03, 2007, 02:11:30 AM »
Looks like it's picking up on old copies in your system restore.
You can clear them out by turning it off, then back on.
Logged
Parched dry and thirsty, knee deep in the river of life.
gandalicious
Bad guy
Global Moderator
Comodo's Hero
Offline
Posts: 3496
kkeewwwwlll
Re: am i infected ?
«
Reply #2 on:
November 03, 2007, 04:47:52 AM »
thx for the reply Cat,
forgive my ignorance,
do you mean i should turn off system restore (let the restore point to be removed) & turn it on right away? or should i do something between those turn off/on? i've RENAMED the infected file, is this the right step?
i can't believe my antimalwares can't detect them. i update all my antimalwares daily & set the heuristic to the highest level, and i just scanned my comp with PrevXFree scanner yesterday.no single nasty found, and now i found them.
and what is this "system volume information" thing? should i be worry? i don't see anything strange on my comp.
Ganda
«
Last Edit: November 03, 2007, 05:06:53 AM by ganda
»
Logged
Ragwing
Global Moderator
Comodo's Hero
Offline
Posts: 3199
Re: am i infected ?
«
Reply #3 on:
November 03, 2007, 05:23:26 AM »
Quote from: ganda on November 03, 2007, 04:47:52 AM
do you mean i should turn off system restore (let the restore point to be removed) & turn it on right away? or should i do something between those turn off/on? i've RENAMED the infected file, is this the right step?
It's Windows, so you'll need to reboot after you've disabled it
Then after reboot you need to enable it, and guess what? Reboot!
If you don't reboot, the files for System Restore won't be deleted.
Quote from: ganda on November 03, 2007, 04:47:52 AM
and what is this "system volume information" thing? should i be worry? i don't see anything strange on my comp.
System Volume Information is where all files for System Restore is stored, it's usually hidden, and you can't access it, tho there's an easy way to do it if you're interested
Cheers,
Ragwing
Logged
Forum Policy
FAQ's
If you should need help or have a question, feel free to
PM
me.
gandalicious
Bad guy
Global Moderator
Comodo's Hero
Offline
Posts: 3496
kkeewwwwlll
Re: am i infected ?
«
Reply #4 on:
November 03, 2007, 06:37:41 AM »
i get it now. now i'm clean like a baby
Quote from: Ragwing on November 03, 2007, 05:23:26 AM
System Volume Information is where all files for System Restore is stored, it's usually hidden, and you can't access it, tho there's an easy way to do it if you're interested
oh yeah, i forgot to ask about this. tried to open C/system volume information and i got
"access denied".
but i think i've managed to open it once a long time ago on my other computer (the one infected by rontokbro), Norman Virus control detected the virus on this system volume info.and i simply open it
well, teach me to do it pls
.
and thx for the quick reply to you both.
<=== milk.
ganda
Logged
Ragwing
Global Moderator
Comodo's Hero
Offline
Posts: 3199
Re: am i infected ?
«
Reply #5 on:
November 03, 2007, 06:46:22 AM »
Quote from: ganda on November 03, 2007, 06:37:41 AM
well, teach me to do it pls
NOTE: I use Swedish version of XP Pro, so my English translation might not be correct.
1. Open the Control panel.
2. Click 'Folder options'.
3. Click the 'View'-tab.
4. Uncheck 'Use simplified file sharing(recommend)'.
5. Under 'Hidden files and folders' choose' Show hidden files and folders'.
6. Uncheck 'Hide protected operating files(recommend)'.
7. Open up my computer, and click your HDD(usually Local Disk (C:) ).
8. Right-click 'System Volume Information' and choose 'Properties'.
9. Click the 'Security'-tab.
10. Click your account and allow it full access.
11. Click 'OK'.
12. Now you're able to go into the mysterious 'System Volume Information'-folder!
Cheers,
Ragwing
Logged
Forum Policy
FAQ's
If you should need help or have a question, feel free to
PM
me.
gandalicious
Bad guy
Global Moderator
Comodo's Hero
Offline
Posts: 3496
kkeewwwwlll
Re: am i infected ?
«
Reply #6 on:
November 03, 2007, 06:54:21 AM »
saved the page
Logged
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 7455
Re: am i infected ?
«
Reply #7 on:
November 03, 2007, 07:00:24 AM »
So those were FP's? The only file in my
System Volume Information
directory is one file that has nothing in it (i've edited it a long time ago): MountPointManagerRemoteDatabase
Logged
gandalicious
Bad guy
Global Moderator
Comodo's Hero
Offline
Posts: 3496
kkeewwwwlll
Re: am i infected ?
«
Reply #8 on:
November 03, 2007, 07:07:08 AM »
Quote from: ู้ส Soya ร้ on November 03, 2007, 07:00:24 AM
So those were FP's?
are you asking me?
i don't know. after turning off system restore & rebooting, i lost all of my restore points. or maybe you don't use system restore at all?
i create restore points a lot & set the "disk space to use" bar to maximum.
«
Last Edit: November 03, 2007, 07:08:56 AM by ganda
»
Logged
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 7455
Re: am i infected ?
«
Reply #9 on:
November 03, 2007, 07:07:47 AM »
Apparently no.
, but based on cat's first response they appear to be infected restore points. If so then Dr. Web is better than others you've used
«
Last Edit: November 03, 2007, 07:09:46 AM by ู้ส Soya ร้
»
Logged
andyman35
Global Moderator
Comodo's Hero
Offline
Posts: 734
Re: am i infected ?
«
Reply #10 on:
November 06, 2007, 04:28:54 AM »
Quote from: ganda on November 03, 2007, 07:07:08 AM
are you asking me?
i don't know. after turning off system restore & rebooting, i lost all of my restore points. or maybe you don't use system restore at all?
i create restore points a lot & set the "disk space to use" bar to maximum.
That's a question I get asked a lot,whether system restore is more harm than good.My answer is that on the whole it's better than nothing,but there are free alternatives available.Personally I use Drive ImageXML which creates a complete copy of your system drive,of course make sure it's clean of any malware first.This image can be saved to another drive or partition or can be burned to Dvd or CDR.
The advantage over system restore is that it copies everything rather than a limited number of settings,so a restored image will be exactly as it was when the image was created.
Logged
Japo
Autonomous Human
Global Moderator
Comodo's Hero
Offline
Posts: 1204
Life starts everyday anew. Prospects not so good.
Re: am i infected ?
«
Reply #11 on:
November 06, 2007, 12:00:55 PM »
To delete your system restore points, I think it's enough to get at the hard drive's properties, click on "free disc space" (or something like that), select restore points and then OK.
Logged
Please abide by the
forum policy
, thanks! ~ Moderators don't speak on Comodo's behalf unless so stated
XP users
check this
to secure your PCs
gandalicious
Bad guy
Global Moderator
Comodo's Hero
Offline
Posts: 3496
kkeewwwwlll
Re: am i infected ?
«
Reply #12 on:
November 06, 2007, 07:31:25 PM »
funny, i click
Show new replies to your posts.
, but this topic's not listed.
Quote from: ู้ส Soya ร้ on November 03, 2007, 07:07:47 AM
Apparently no.
, but based on cat's first response they appear to be infected restore points. If so then Dr. Web is better than others you've used
that's a big problem
about the "probably batch.script virus", i remember that i have 1 suspicious .exe file (it's a corrupted local virus, i guess).
Program.AVTest, (i think it's trojan simulator)
Adware.Gdown;;
Modification of BackDoor.Generic.1219
Adware.Msearch.origin;;
but these three is fishy.
i think system restore is just "restoring system", and do nothing to the files, am i right? then why system volume information can have these trojan simulator & my suspicious .exe file? i blocked trojan simulator when i was trying it (CBO,ST's Clam AV warned me) & i'm too paranoid to test a suspicious .exe ( i tried it on another comp, and it did nothing).
Logged
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 7455
Re: am i infected ?
«
Reply #13 on:
November 06, 2007, 07:34:59 PM »
So far no one in this thread has answered directly whether these SR points are viruses or not...
If you still have them, why not upload to Comodo or whatever vendor for confirmation?
Logged
gandalicious
Bad guy
Global Moderator
Comodo's Hero
Offline
Posts: 3496
kkeewwwwlll
Re: am i infected ?
«
Reply #14 on:
November 06, 2007, 07:49:12 PM »
Quote from: ู้ส Soya ร้ on November 06, 2007, 07:34:59 PM
So far no one in this thread has answered directly whether these SR points are viruses or not...
If you still have them, why not upload to Comodo or whatever vendor for confirmation?
i was too panic to do that
and now i have erase them. about the suspicious file, i attached it in this forum. the guy who's infected by this virus said that the virus came from flash disk and there are 2 .exe. but he only send me 1 of it.
http://forums.comodo.com/help_for_comodo_antivirus/how_long_the_submitted_file_can_be_added_into_virus_database-t13501.0.html
Logged
Tags:
Pages:
[
1
]
2
3
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.226 seconds with 19 queries.
Powered by SMF 1.1.7
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com