Welcome, Guest. Please login or register.
May 17, 2008, 08:10:16 AM

Login with username, password and session length

155273 Posts
19191 Topics
47335 Members

Latest Member: sabino59

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Anti-Viruspyware (CAVS)
| | |-+  Virus/Malware Removal Assistance
| | | |-+  malware alert [Resolved]
« previous next »
Pages: [1] Go Down Print
Author Topic: malware alert [Resolved]  (Read 662 times)
cjdbrm468
Newbie
*
Offline Offline

Posts: 4


« on: April 04, 2008, 09:51:38 AM »

I have Comodo pro running on my computer and got the following alert yesterday can you help please.. the alert is ..C:\ProgramFiles\CommonFiles\Motive\InstallHelper.exe,  also marked as unkown Malware(Dirty)(ID..
I pressed remove but it said it could not so it has isolated it.. what can I do Please..any help much appreciated
Cliff
« Last Edit: April 09, 2008, 11:26:02 AM by Ragwing » Logged
dw2108
Newbie
*
Offline Offline

Posts: 17


« Reply #1 on: April 04, 2008, 01:32:10 PM »

If you sent the file to quarantine, then only a few registry keys and junk files are left; however, if this is recurrent malware, it can regenerate itself on a reboot. But you need first to make sure that this is not a false positive by submitting it to Avira, Avast, Norton, etc., for evaluation.

If you want to restore it and to remove it, try downloading a-squared free and Ccleaner from majorgeeks.com or snapfiles.com/freeware and run some scans. Winpatrol from www.winpatrol.com and SpyBot are very good in displaying ActiveX and BHO malware installed on your PC, each having options to remove the malware.

First, do some googling to make sure that you are not seeing a false positive and scan with a-squared.

Hope this helps.

Dave

P.S. I've found that WinCleaner AS Free from www.wincleaneras.com and AnVir Task Manager Free work well with CAVS and BOClean, and you may want to try these out when you get this problem cleared up.
« Last Edit: April 04, 2008, 02:18:38 PM by dw2108 » Logged
Ragwing
Guardian of the Light Master of the Force Invincible Legend
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2211


The Computer Mage


« Reply #2 on: April 04, 2008, 03:23:33 PM »

Greetings!

Upload it to VirusTotal, to verify that it's not a false positive.

Cheers,
Ragwing
Logged

The Wheel of Time turns, and Ages come and pass, leaving memories that become legend. Legend fades to myth, and even myth is long forgotten when the Age that gave it birth comes again.
cjdbrm468
Newbie
*
Offline Offline

Posts: 4


« Reply #3 on: April 05, 2008, 04:29:11 AM »

Thanks to all for replies.. I am an OAP and have,t a clue how to do what you suggest, so I used a Unistall program  called your uninstall and it said it had removed it,  if it has not then am I safe leaving it in quarantine or should I take the computer to a specialist to remove it.... thanks
cliff
Logged
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 4667


Life may suck, but contemplate the alternative.


« Reply #4 on: April 05, 2008, 05:12:14 AM »

If it's in quarantine, then it is rendered inaccessible and is therefore safe. It can't get out and anything that wants to call it can't reach it.

I would upload it to virustotal. This is relatively easy to do. Firstly, restore the file from quarantine and note the folder that it is restored to. Then, in your browser, go to http://www.virustotal.com. Click the browse button and go to the folder that the file was restoered to and select the file. Click the "Send file" button and it will be uploaded and analysed at virus total, where you can view theresult.

Hope this helps,
Ewen :-)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
cjdbrm468
Newbie
*
Offline Offline

Posts: 4


« Reply #5 on: April 07, 2008, 11:18:55 AM »

Thanks everyone
I have solved the problem, I used a program called YOUR UNINSTALLER  and it worked  I re checked a scan with Comodo and it was there before I used the unistall I scanned again and it had gone, the uninstall showed it cleared things from the registry, so thanks once again
Regards
Cliff
Logged
Ragwing
Guardian of the Light Master of the Force Invincible Legend
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2211


The Computer Mage


« Reply #6 on: April 09, 2008, 11:25:49 AM »

No problem. I'll close this topic now. PM an online moderator with a link to this topic if you should need it opened again.

Cheers,
Ragwing
Logged

The Wheel of Time turns, and Ages come and pass, leaving memories that become legend. Legend fades to myth, and even myth is long forgotten when the Age that gave it birth comes again.
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.168 seconds with 19 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com