Welcome, Guest. Please login or register.
November 18, 2008, 05:15:41 PM

Login with username, password and session length

212209 Posts
24527 Topics
57703 Members

Latest Member: Striken7

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Virus/Malware Removal Assistance
| | | |-+  am i infected ?
« previous next »
Pages: [1] 2 3 Go Down Print
Author Topic: am i infected ?  (Read 4083 times)
gandalicious
Bad guy
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3496


kkeewwwwlll


« on: November 03, 2007, 12:35:36 AM »

hi Wave

just downloaded drwebcureit,
i attached the result. all the infections are on C\system volume information.
what should i do about the infected items? may i just remove/delete them since i can't cure them.
been using Avira (CAVS before), Spyware Terminator, spyware blaster, CFP,CMG,CBO, and these nasties still managed to enter?
man! i'm scared!

p.s. i don't notice anything weird happens to my computer. 


ganda
Logged
~cat~
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 964


CBO "...there is nothing better."


« Reply #1 on: November 03, 2007, 02:11:30 AM »

Looks like it's picking up on old copies in your system restore.
You can clear them out by turning it off, then back on.
Logged

Parched dry and thirsty, knee deep in the river of life.
gandalicious
Bad guy
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3496


kkeewwwwlll


« Reply #2 on: November 03, 2007, 04:47:52 AM »

thx for the reply Cat,
forgive my ignorance,
do you mean i should turn off system restore (let the restore point to be removed) & turn it on right away? or should i do something between those turn off/on? i've RENAMED the infected file, is this the right step?

i can't believe my antimalwares can't detect them. i update all my antimalwares daily & set the heuristic to the highest level, and i just scanned my comp with PrevXFree scanner yesterday.no single nasty found, and now i found them. Angry

and what is this "system volume information" thing? should i be worry? i don't see anything strange on my comp.


Ganda
« Last Edit: November 03, 2007, 05:06:53 AM by ganda » Logged
Ragwing
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3199


« Reply #3 on: November 03, 2007, 05:23:26 AM »

do you mean i should turn off system restore (let the restore point to be removed) & turn it on right away? or should i do something between those turn off/on? i've RENAMED the infected file, is this the right step?

It's Windows, so you'll need to reboot after you've disabled it Cheesy
Then after reboot you need to enable it, and guess what? Reboot! Tongue
If you don't reboot, the files for System Restore won't be deleted.

and what is this "system volume information" thing? should i be worry? i don't see anything strange on my comp.

System Volume Information is where all files for System Restore is stored, it's usually hidden, and you can't access it, tho there's an easy way to do it if you're interested Wink

Cheers,
Ragwing

Logged

Forum Policy
FAQ's

If you should need help or have a question, feel free to PM me.
gandalicious
Bad guy
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3496


kkeewwwwlll


« Reply #4 on: November 03, 2007, 06:37:41 AM »

i get it now. now i'm clean like a baby  Grin
System Volume Information is where all files for System Restore is stored, it's usually hidden, and you can't access it, tho there's an easy way to do it if you're interested Wink
oh yeah, i forgot to ask about this. tried to open C/system volume information and i got
"access denied".
but i think i've managed to open it once a long time ago on my other computer (the one infected by rontokbro), Norman Virus control detected the virus on this system volume info.and i simply open it Huh
well, teach me to do it pls Tongue .

and thx for the quick reply to you both.  Cheers Cheers <=== milk.

ganda
Logged
Ragwing
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3199


« Reply #5 on: November 03, 2007, 06:46:22 AM »

well, teach me to do it pls Tongue

NOTE: I use Swedish version of XP Pro, so my English translation might not be correct.

1. Open the Control panel.

2. Click 'Folder options'.

3. Click the 'View'-tab.

4. Uncheck 'Use simplified file sharing(recommend)'.

5. Under 'Hidden files and folders' choose' Show hidden files and folders'.

6. Uncheck 'Hide protected operating files(recommend)'.

7. Open up my computer, and click your HDD(usually Local Disk (C:) ).

8. Right-click 'System Volume Information' and choose 'Properties'.

9. Click the 'Security'-tab.

10. Click your account and allow it full access.

11. Click 'OK'.

12. Now you're able to go into the mysterious 'System Volume Information'-folder!

Cheers,
Ragwing
Logged

Forum Policy
FAQ's

If you should need help or have a question, feel free to PM me.
gandalicious
Bad guy
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3496


kkeewwwwlll


« Reply #6 on: November 03, 2007, 06:54:21 AM »

 Clapping saved the page
Logged
Soyabeaner
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7455



« Reply #7 on: November 03, 2007, 07:00:24 AM »

So those were FP's?  The only file in my System Volume Information directory is one file that has nothing in it (i've edited it a long time ago): MountPointManagerRemoteDatabase
Logged
gandalicious
Bad guy
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3496


kkeewwwwlll


« Reply #8 on: November 03, 2007, 07:07:08 AM »

So those were FP's?
are you asking me?
i don't know. after turning off system restore & rebooting, i lost all of my restore points. or maybe you don't use system restore at all?
i create restore points a lot & set the "disk space to use" bar to maximum.
« Last Edit: November 03, 2007, 07:08:56 AM by ganda » Logged
Soyabeaner
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7455



« Reply #9 on: November 03, 2007, 07:07:47 AM »

Apparently no. Cheesy, but based on cat's first response they appear to be infected restore points.  If so then Dr. Web is better than others you've used Huh
« Last Edit: November 03, 2007, 07:09:46 AM by ู้ส Soya ร้ » Logged
andyman35
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 734


« Reply #10 on: November 06, 2007, 04:28:54 AM »

are you asking me?
i don't know. after turning off system restore & rebooting, i lost all of my restore points. or maybe you don't use system restore at all?
i create restore points a lot & set the "disk space to use" bar to maximum.

That's a question I get asked a lot,whether system restore is more harm than good.My answer is that on the whole it's better than nothing,but there are free alternatives available.Personally I use Drive ImageXML which creates a complete copy of your system drive,of course make sure it's clean of any malware first.This image can be saved to another drive or partition or can be burned to Dvd or CDR.

The advantage over system restore is that it copies everything rather than a limited number of settings,so a restored image will be exactly as it was when the image was created.
Logged
Japo
Autonomous Human
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1204


Life starts everyday anew. Prospects not so good.


« Reply #11 on: November 06, 2007, 12:00:55 PM »

To delete your system restore points, I think it's enough to get at the hard drive's properties, click on "free disc space" (or something like that), select restore points and then OK.
Logged

Please abide by the forum policy, thanks! ~ Moderators don't speak on Comodo's behalf unless so stated


XP users check this to secure your PCs
gandalicious
Bad guy
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3496


kkeewwwwlll


« Reply #12 on: November 06, 2007, 07:31:25 PM »

Huh funny, i click Show new replies to your posts. , but this topic's not listed.
Apparently no. Cheesy, but based on cat's first response they appear to be infected restore points.  If so then Dr. Web is better than others you've used Huh
that's a big problem  Shocked
about the "probably batch.script virus", i remember that i have 1 suspicious .exe file (it's a corrupted local virus, i guess).
Program.AVTest, (i think it's trojan simulator)
Adware.Gdown;;
Modification of BackDoor.Generic.1219
Adware.Msearch.origin;;


but these three is fishy.
i think system restore is just "restoring system", and do nothing to the files, am i right? then why system volume information can have these trojan simulator & my suspicious .exe file? i blocked trojan simulator when i was trying it (CBO,ST's Clam AV warned me) & i'm too paranoid to test a suspicious .exe ( i tried it on another comp, and it did nothing).

Logged
Soyabeaner
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7455



« Reply #13 on: November 06, 2007, 07:34:59 PM »

So far no one in this thread has answered directly whether these SR points are viruses or not... Thinking

If you still have them, why not upload to Comodo or whatever vendor for confirmation?
Logged
gandalicious
Bad guy
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3496


kkeewwwwlll


« Reply #14 on: November 06, 2007, 07:49:12 PM »

So far no one in this thread has answered directly whether these SR points are viruses or not... Thinking

If you still have them, why not upload to Comodo or whatever vendor for confirmation?
i was too panic to do that Grin and now i have erase them. about the suspicious file, i attached it in this forum. the guy who's infected by this virus said that the virus came from flash disk and there are 2 .exe. but he only send me 1 of it.
http://forums.comodo.com/help_for_comodo_antivirus/how_long_the_submitted_file_can_be_added_into_virus_database-t13501.0.html
Logged
Tags:
Pages: [1] 2 3 Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.226 seconds with 19 queries.
Powered by SMF 1.1.7 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com