Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
July 06, 2008, 10:16:27 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
170882
Posts
20398
Topics
49738
Members
Latest Member:
vano.agosto
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Anti-Viruspyware (CAVS)
Virus/Malware Removal Assistance
help needed! PC slow & infected
« previous
next »
Pages:
1
[
2
]
Author
Topic: help needed! PC slow & infected (Read 4392 times)
Rotty
Global Moderator
Comodo's Hero
Offline
Posts: 793
http://www.venganza.org/ - Noodly Appendage
Re: help needed!
«
Reply #15 on:
October 27, 2007, 07:14:49 PM »
As a side note:
The "C:\WINDOWS\system32\SSVICHOSST.exe" line was under the processes list, that means the there were two instances of the executable running at once. This cannot be fixed in hijackthis, although you could end the process..
The idea is to remove the entry that launched the process at startup: "O4 - HKCU\..\Run: [Yahoo Messengger] C:\WINDOWS\system32\SSVICHOSST.exe" which was removed.
Anything that starts with "O4" (Run registry entry) or "O23" (Registered service) means that it launches a process at startup. Hijackthis covers a few sections of the registry as "O4" but all have the same effect of starting a process at startup.
Logged
The opinions expressed in my posts are my own.
They do NOT necessarily represent or reflect the views of my employer.
moysong
Newbie
Offline
Posts: 4
Re: help needed!
«
Reply #16 on:
November 08, 2007, 06:36:07 AM »
HEY GUYS! CAN YOU PLEASE TELL ABOUT THIS COZ I HAVE ALSO SAME PROBLEM I CANT OPEN TASK MANAGER...PLEASE HELP ME THANK YOU,..
Moderator Edit: Please do NOT post HJT logs; they are simply too long. Instead, upload them as an attachment. Also please do not capitalize posts as on the internet it implies shouting/yelling.
«
Last Edit: November 13, 2007, 05:13:57 PM by Soyabeaner
»
Logged
moysong
Newbie
Offline
Posts: 4
Re: help needed!
«
Reply #17 on:
November 08, 2007, 06:43:48 AM »
PLEASE TELL WHAT ARE THOSE IN RED COLOR...?
Logged
N.T.T.W.
Global Moderator
Comodo's Hero
Offline
Posts: 1121
A minute of your time can help many.
Re: help needed!
«
Reply #18 on:
November 08, 2007, 08:11:49 AM »
Looks like you have bearshare on your pc as well as askpbar. There may be other things as well.
Do you have spybot S & D? If not I would recommend you download it and run it.
http://www.safer-networking.org/en/download/index.html
Logged
Post proelia praemia.
Die dulci fruere.
grue155
Global Moderator
Comodo's Hero
Offline
Posts: 612
Re: help needed!
«
Reply #19 on:
November 09, 2007, 02:47:19 PM »
moysong:
This log entry
O4 - HKCU\..\Run: [Tok-Cirrhatus-3939] "C:\Documents and Settings\ramil.bungque\Local Settings\Application Data\br8901on.exe"
matches a description
http://www.prevx1.com/polywaredetail.asp?SQ=HCCI445255
for a polyware virus going by the name RAKYATKELAPARAN.EXE
A google search on RAKYATKELAPARAN.EXE turns this reference
http://www.bleepingcomputer.com/startups/RakyatKelaparan.exe-13875.html
described as "Added by the W32/Brontok-I worm."
Your log also has this item
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
meaning that your ability to edit the registry has been disabled. That's a common thing for malware to do these days, it in effort to make cleanup more difficult.
For details on W32/Brontok-I, details at
http://www.sophos.com/virusinfo/analyses/w32brontoki.html
From what I've seen in various malware cleanup forums elsewhere, Brontok is not an easy cleanup.
And that's about the limit of my skills. I can follow logs for the most part, but doing the cleanup isn't my field.
Edit: Doing some more checking, this description
http://www.microsoft.com/security/encyclopedia/details.aspx?name=Win32%2fBrontok
confirms several additional details in your log as matching that of the Brontok virus. Microsoft rates removal of this malware as "difficult".
There seem to be few tools dealing directly with Brontok removal. Several that I've found listed are for previous versions of the malware, and are incomplete or ineffective at removal of Brontok-I.
The Microsoft Malicious Software Removal Tool is listed as a removal tool. The MSRT can be downloaded at
http://www.microsoft.com/security/malwareremove/default.mspx
«
Last Edit: November 09, 2007, 04:00:17 PM by grue155
»
Logged
moysong
Newbie
Offline
Posts: 4
Re: help needed!
«
Reply #20 on:
November 13, 2007, 06:38:05 AM »
guys! please tell me excactly what can i do to get out of this malware to healed or to remove because my PC is running slowly
Moderator Edit: Please do NOT post HJT logs; they are simply too long. Instead, upload them as an attachment.
«
Last Edit: November 13, 2007, 05:15:37 PM by Soyabeaner
»
Logged
Goose18
Comodo's Hero
Offline
Posts: 878
Yes... I hate apple.
Re: help needed! PC slow & infected
«
Reply #21 on:
November 13, 2007, 09:14:17 AM »
Best way for a 100% Clean PC.... *Reformat* I know reformatting sucks but from time to time it will need done...
Logged
Avast! 4.8, BOClean, CFP3 and did i mention Avast! 4.8
OH guess what!!! Avast! 4.8
grue155
Global Moderator
Comodo's Hero
Offline
Posts: 612
Re: help needed! PC slow & infected
«
Reply #22 on:
November 13, 2007, 03:04:31 PM »
Your HiJackThis log still show signs of Brontok-I. Specifically these two lines:
Quote
O4 - HKCU\..\Run: [Tok-Cirrhatus-3939] "C:\Documents and Settings\ramil.bungque\Local Settings\Application Data\br8901on.exe"
O4 - HKCU\..\Run: [Tok-Cirrhatus] "C:\Documents and Settings\ramil.bungque\Local Settings\Application Data\smss.exe"
From what I can tell, the forum here can provide basic help, but what you have isn't a basic kind of problem.
You've got these alternatives, in this order:
Download and run the Microsoft Malicious Software Removal Tool, which does list itself as removing Brontok malware.
A web search turns up removal instructions at trendmicro.com, at their web page
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FBRONTOK%2EI&VSect=Sn
The Trendmicro web page also lists their on-line scanner Housecall as being able to remove Brontok.
If those methods don't work, then I'm going to point you to another malware removal forum for assistance to walk you thru the malware cleanup. I'll suggest castlecops.com, bleepingcomputer.com, spywareinfo.com, techsupportform.com. Any of the forums listed at the ASAP page
http://asap.maddoktor2.com/
can do the job.
At worst, goose17 is right, then you zero wipe your disk, format, and reinstall.
Wish I could be more help, but this is outside my skill range.
Logged
Ragwing
Guardian of the Light Master of the Force Invincible Legend
Global Moderator
Comodo's Hero
Offline
Posts: 2545
The chosen hero of the Keyblade
Re: help needed!
«
Reply #23 on:
November 13, 2007, 03:22:07 PM »
Quote from: moysong on November 13, 2007, 06:38:05 AM
C:\WINDOWS\SSVICHOSST.exe
Seems like this one has returned.
For info about it:
http://spywarefiles.prevx.com/RRDDGD036916051/SSVICHOSST.EXE.html
You can try downloading the tool there and see if it's able to fix the problem.
If you're able to, install CFP3 with HIPS, or another HIPS. This way you can prevent it from running.
Tho the best thing you can do is to backup all important data to a second HDD/external HDD/USB-drive or CD/DVD and then format.
Cheers,
Ragwing
Logged
"The closer you get to the light, the greater your shadow becomes"
grue155
Global Moderator
Comodo's Hero
Offline
Posts: 612
Re: help needed! PC slow & infected
«
Reply #24 on:
November 13, 2007, 03:50:35 PM »
Quote
C:\WINDOWS\SSVICHOSST.exe
And that, thru prevx, becomes W32/Sohana-R, Details
http://www.sophos.com/security/analyses/w32sohanar.html
Note this from the Sophos description:
Quote
W32/Sohana-R includes functionality to
- access the internet and communicate with a remote server via HTTP.
- download, install and run new software.
With both Brontok and Sohana, I'd say the machine is fully compromised. While you might be able to get it cleaned thru one of the ASAP malware removal forums, I don't believe that the machine can be trusted again. At this stage of infection, I'd expect there to be a rootkit fully installed.
It's a judgment call, but I'd suggest what goose17 suggested: make what backups you can, and can verify are _not_ infected, then zero wipe the disk, and reinstall.
Logged
moysong
Newbie
Offline
Posts: 4
Re: help needed! PC slow & infected
«
Reply #25 on:
November 14, 2007, 03:59:14 AM »
Thank you guys! i think i need to do the best way...
sorry for the bold letters thing & the Hjt logs...
thank you again guys for all your suggestion...i'll be back when my pc is reformat ok..cheers
Logged
Tags:
problem in my pc
Pages:
1
[
2
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Remote Management
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.103 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com