Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
November 18, 2008, 05:23:56 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
212209
Posts
24527
Topics
57703
Members
Latest Member:
Striken7
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Virus/Malware Removal Assistance
Default How to fix severe virus problems?
« previous
next »
Pages:
[
1
]
Author
Topic: Default How to fix severe virus problems? (Read 1443 times)
Psychozd
Newbie
Offline
Posts: 2
Default How to fix severe virus problems?
«
on:
July 12, 2008, 10:45:22 AM »
Two days ago, I`ve noticed that my computer is slowing down. I`ve accesed the control managment (to be honest I don`t know how it is called on english, cause my XP is on croatian, but the keypad shortcut is AltGr + Ctrl + Del) and I saw that some installation process in going on. Before I was able to end it, the installation completed and my comp was infected.
It changed my wallpaper, deleted some icons, and locked me out of some key systems. I can`t access hard disk, control panel, control managment, or any system that could help me to realise what is wrong.
I`ve run a on - demand scanner with full system scan twice, and I couldn`t remove virus. First time it found 345 infected files, and cleaned 296, and second time it founded 52 infected files, and cleaned only three. One of the problems is that more than 2000 files, including some in /windows/system32/ are locked and cannot be accessed.
The "XP" is opening my internet broswers suggesting me to download some of the "antivirus programs" to clean it, but I didn`t fail on that. (the sites are "safewebnavigate.com", "antivirus-2008.pro.com"...)
What should I do, and how can I get rid of this virus?
And microsoft has sent me "microsoft windows malicious software removal tool" via automatic updates, but it has found only one infected file... Is that program any good?
Here are some screenshots of my problem, uploaded to imageshack...
http://img300.imageshack.us/img300/3372/virusxz4.png
http://img440.imageshack.us/img440/4...jamaterxz2.png
http://img292.imageshack.us/img292/4...ectionspn2.png
http://img172.imageshack.us/img172/2107/krajam7.png
http://img135.imageshack.us/img135/3...arddiscpq8.png
All those "antivirus, and anti****" icons you can see on my background are added by virus...
I`ve forgot...
NOD has found many different versions of win32/worm, trojan downloader, you name it...
And AMON has found NewHeur_PE virus.
This is file name...
Module Object Name Threat Action User Information
9.7.2008 18:07: VIRUS ALERT! IMON file -Virus Link Removed- unknown NewHeur_PE virus NT AUTHORITY\SYSTEM
Removed Virus Link- 3xist.
«
Last Edit: July 13, 2008, 03:23:00 AM by 3xist
»
Logged
3xist
Global Moderator
Comodo's Hero
Offline
Posts: 3328
Re: Default How to fix severe virus problems?
«
Reply #1 on:
July 12, 2008, 11:35:17 PM »
Quote from: Psychozd on July 12, 2008, 10:45:22 AM
Two days ago, I`ve noticed that my computer is slowing down. I`ve accesed the control managment (to be honest I don`t know how it is called on english, cause my XP is on croatian, but the keypad shortcut is AltGr + Ctrl + Del) and I saw that some installation process in going on. Before I was able to end it, the installation completed and my comp was infected.
It changed my wallpaper, deleted some icons, and locked me out of some key systems. I can`t access hard disk, control panel, control managment, or any system that could help me to realise what is wrong.
I`ve run a on - demand scanner with full system scan twice, and I couldn`t remove virus. First time it found 345 infected files, and cleaned 296, and second time it founded 52 infected files, and cleaned only three. One of the problems is that more than 2000 files, including some in /windows/system32/ are locked and cannot be accessed.
The "XP" is opening my internet broswers suggesting me to download some of the "antivirus programs" to clean it, but I didn`t fail on that. (the sites are "safewebnavigate.com", "antivirus-2008.pro.com"...)
What should I do, and how can I get rid of this virus?
And microsoft has sent me "microsoft windows malicious software removal tool" via automatic updates, but it has found only one infected file... Is that program any good?
Here are some screenshots of my problem, uploaded to imageshack...
http://img300.imageshack.us/img300/3372/virusxz4.png
http://img440.imageshack.us/img440/4...jamaterxz2.png
http://img292.imageshack.us/img292/4...ectionspn2.png
http://img172.imageshack.us/img172/2107/krajam7.png
http://img135.imageshack.us/img135/3...arddiscpq8.png
All those "antivirus, and anti****" icons you can see on my background are added by virus...
I`ve forgot...
NOD has found many different versions of win32/worm, trojan downloader, you name it...
And AMON has found NewHeur_PE virus.
This is file name...
Module Object Name Threat Action User Information
9.7.2008 18:07: VIRUS ALERT! IMON file -snip- probably unknown NewHeur_PE virus NT AUTHORITY\SYSTEM
Hey Psychozd. Welcome to the Forums!
First Download & install the following:
SUPERAntispyware Free
Malware Bytes' Anti-Malware
Clamwin
Those links will automatically begin downloading. Once you installed all 3 apps, Download all necessary definition updates for all of the products.
Now reboot, & when your computer starts up, Keep pressing "F8" until you get to the option to choose
Safe Mode
(Safe Mode is a special diagnostic mode) and click on it without networking. Finally, Scan & Remove all the infections found with MalwareBytes, SUPERAntispyware, NOD32, & ClamWin. (Make sure you do
full system scans
&
ONE
at a time). Now Reboot a 2nd time normally, & re-run the scans again.
Post back after you completed those steps, Tell me how your system is
Goodluck!
«
Last Edit: July 13, 2008, 03:33:39 AM by 3xist
»
Logged
Comodo Moderator:
Maintains order at the forum and makes sure the
policy
is followed.
My System Details:
Windows XP 32bit SP3, CIS 3.5.
Specialty:
Malware Removal & Remote Helper.
Goose18
Comodo's Hero
Online
Posts: 1150
Re: Default How to fix severe virus problems?
«
Reply #2 on:
July 13, 2008, 12:57:07 AM »
Mods please remove the link it is a virus. Avast detected it as Win32:Agent-ZRK [trj]
edit: since Avast 4.8 Home detected it try downloading avast and using it's Boot Time scanner which detects viruses and malware and even spyware before windows starts up.
www.avast.com
«
Last Edit: July 13, 2008, 03:32:23 AM by 3xist
»
Logged
Avast! 4.8, BOClean, CFP3 and did i mention Avast! 4.8
OH guess what!!! Avast! 4.8
System Specs: Pentium 4 with HT 3.06 Ghz, 1.5GB RAM, 160 GB WDC HD, Nvidia Geforce 7600GT 256MB
3xist
Global Moderator
Comodo's Hero
Offline
Posts: 3328
Re: Default How to fix severe virus problems?
«
Reply #3 on:
July 13, 2008, 03:21:44 AM »
Quote from: Goose18 on July 13, 2008, 12:57:07 AM
Mods please remove the link it is a virus. Avast detected it as Win32:Agent-ZRK [trj]
Thanks it's been removed.
Logged
Comodo Moderator:
Maintains order at the forum and makes sure the
policy
is followed.
My System Details:
Windows XP 32bit SP3, CIS 3.5.
Specialty:
Malware Removal & Remote Helper.
UncleDoug
Comodo's Hero
Offline
Posts: 261
Re: Default How to fix severe virus problems?
«
Reply #4 on:
July 13, 2008, 08:08:02 AM »
One of the things you should do on a weekly basis is to manually check and update all your security programs. I have several that I have turned of in services.msc but bring them back online if I want more
options
in scanning.
The last infection I had caused the screen to constantly reload, I was able to stop it by booting to safe mode and then ran malwarebytes which slopped that problem and allowed me to scan in regular mode. If you think you are infected always scan in both modes.
My disappointment is that while scanning with over a dozen different programs, that many will find something different, a few times they will find the same file but not all, No one program finds them all not even 70% (maybe 60%)
when I have gotten infected
.
More than just a few of the scanning tools you use, will have false positives (but scan individually that program with other anti malware programs to be safe.
Let one of the Experts in anti malware removal assist you, sometimes they will recommend a removal program that is directed
towards
your infection
. And at one point they will recommend clearing / turning OFF Windows Restore.
I mentionded earlier about insuring you update regularly, another item many do not
pay attention to
is the
scan settings
on each scanner. I found on almost all by default are set for Quick / Smart Scan. When you have an infection make sure you set the scan for Deep / Full scan (also inside archives).
The time usually takes 2-3 times longer, so be patient.
The quick scan setting also goes for Microsofts Malicious Removal Tool and Windows Defender. The difference is that Windows Defendere works like CAVS to scan for malware and the Malicious Removal Tool scans for malware that is already active like BoClean BUT you have to start the scan, while BoClean automatically reacts.
Windows Defender even though
how low it is thought of
, once found an infection that the others had missed ! The Malicious removal tool is normally uninstalled on the next reboot, after the monthly Windows patch updates.
Update Update Update
, have
several programs available
(not necessarily running), and
work with an Expert in malware scanning and removal.
UncleDoug
«
Last Edit: July 13, 2008, 08:15:10 AM by UncleDoug
»
Logged
Ronny
Comodo's Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 985
Re: Default How to fix severe virus problems?
«
Reply #5 on:
July 13, 2008, 08:37:58 AM »
Also be aware that most AV's only remove the "Active" components of your infection.
And take care it won't startup again with your computer.
A lot of virus/worm/trojan suff also changes things in your registry and on file level/security.
So if i would get infected this way i think i'd go for the backup of may important data and do a clean install from the bottom up. And as UncleDoug stated, update, update, update. Run Secunia's PSI or Comodo's Vulnerability analyzer to see what application's you run that need to be updated.
Run a realtime virusscanner a firewall and do some manual scanning with others every 2 weeks or so, save the logfiles so you can go back in time later to see if some "infection" was already there, or as most of them have false positives, compare them, or look them op on google to see if it's real.
Also i'd prefer using Firefox in combination with NoScript to disable most javascript drivebydownloads.
Logged
Now playing:
You rise, you fall, your down, then you rise again What don't kill you make you more strong
Psychozd
Newbie
Offline
Posts: 2
Re: Default How to fix severe virus problems?
«
Reply #6 on:
July 17, 2008, 08:31:52 PM »
Looks like that the main problem is
trojan-ace-x.
Adaware and spysweeper detected they but couldn`t remove it.
Is there any program that can remove this malware, virus, whatever?
Logged
3xist
Global Moderator
Comodo's Hero
Offline
Posts: 3328
Re: Default How to fix severe virus problems?
«
Reply #7 on:
July 17, 2008, 11:05:04 PM »
Quote from: 3xist on July 12, 2008, 11:35:17 PM
Hey Psychozd. Welcome to the Forums!
First Download & install the following:
SUPERAntispyware Free
Malware Bytes' Anti-Malware
Clamwin
Those links will automatically begin downloading. Once you installed all 3 apps, Download all necessary definition updates for all of the products.
Now reboot, & when your computer starts up, Keep pressing "F8" until you get to the option to choose
Safe Mode
(Safe Mode is a special diagnostic mode) and click on it without networking. Finally, Scan & Remove all the infections found with MalwareBytes, SUPERAntispyware, NOD32, & ClamWin. (Make sure you do
full system scans
&
ONE
at a time). Now Reboot a 2nd time normally, & re-run the scans again.
Post back after you completed those steps, Tell me how your system is
Goodluck!
Tried this?
Logged
Comodo Moderator:
Maintains order at the forum and makes sure the
policy
is followed.
My System Details:
Windows XP 32bit SP3, CIS 3.5.
Specialty:
Malware Removal & Remote Helper.
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.142 seconds with 20 queries.
Powered by SMF 1.1.7
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com