Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
November 18, 2008, 06:15:50 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
212227
Posts
24530
Topics
57713
Members
Latest Member:
desertrat2143
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Virus/Malware Removal Assistance
Need help with a virus
« previous
next »
Pages:
[
1
]
2
Author
Topic: Need help with a virus (Read 1844 times)
ericd
Newbie
Offline
Posts: 9
Need help with a virus
«
on:
September 04, 2008, 09:29:23 PM »
My computer has windows xp service pack 2 and I have the comodo firewall 3 and the comodo antivirus 2. A couple of days ago I got a lot of error messages saying I am infected and that I should download anti-spyware master to protect the computer. Well, when I tryed to download it the antivirus told me that it was a virus. By then though the program was already on the computer and it started to download x-rated stuff onto the desktop. I got that to finally stop but it is still trying to gain access to the internet again so it can start it all over again. When that happened a folder call pchealth popped up in the program files and windows folders. The program inside of it is not pchealth instead it is something else that I don't know, because I am on a friend's computer and can't look it up now. When I scanned the computer it did find seven virus and about 8000 suspicious files and when I try to submit them the firewall says that rundll.exe is trying to get shutdown privileges. When I hit deny, it shuts down the internet connection. Now the firewall pop ups don't have the writing on the tops on them anymore. Is there anything that I can do or is it a lost cause. Thinks for any help.
Logged
grayhair
Comodo Loves me
Offline
Posts: 184
Re: Need help with a virus
«
Reply #1 on:
September 04, 2008, 10:42:26 PM »
Yikes!! I don't know anything specifically about this "antispyware master." My first words of advice would be not to connect it to the internet right now, as you may have unintentionally installed some sort of downloader, and being connected could make things worse. Besides Comodo Firewall v.3 and Comodo antivirus 2, what other security programs do you have installed? There are things you can do--the worst being a reformat of your operating disc. Do you have backups of your documents, important files, installation programs, etc.? If not, don't try to back things up right now, as the malware could be scattered around your computer. Be patient, hopefully help will be on the way here.
Anyone know anything specific about this "Antispyware Master?"
Logged
grayhair
Comodo Loves me
Offline
Posts: 184
Re: Need help with a virus
«
Reply #2 on:
September 04, 2008, 10:55:06 PM »
I Googled a little bit about the AntiSpyware Master thing. It does appear to be nasty. I did see in one forum that someone had good results in getting rid of it by installing and running SuperAntiSpy (which is very legitimate!). Here is the link to SuperAntiSpy:
Edit: I hit the wrong key and sent this on its way incomplete. Now the finish:
http://www.superantispyware.com/
If your friend will let you, I would download SuperAntiSpy on your friends computer, save the install file on a CD, then install it on your computer from the CD. After installation it will want you to update it--maybe just do a COMPLETE scan first, and see what it picks up. Then maybe connect the computer to the internet, update the program, and do another complete scan.
Probably SuperAntiSpy won't be the only thing you will need to run, but it is a start.
Second edit: just download the free edition of SuperAntiSpy for now.
«
Last Edit: September 04, 2008, 11:03:02 PM by grayhair
»
Logged
gandalicious
Bad guy
Global Moderator
Comodo's Hero
Offline
Posts: 3496
kkeewwwwlll
Re: Need help with a virus
«
Reply #3 on:
September 04, 2008, 11:09:55 PM »
or... maybe you can try
DrWebCureIt
. it's portable, no installation needed. don't forget to scan your comp with it or superAntiSpyware on safe mode.
goodluck
Logged
ericd
Newbie
Offline
Posts: 9
Re: Need help with a virus
«
Reply #4 on:
September 04, 2008, 11:45:22 PM »
Quote from: grayhair on September 04, 2008, 10:42:26 PM
Besides Comodo Firewall v.3 and Comodo antivirus 2, what other security programs do you have installed?
I have ad-aware 2008 and spy sweeper. I don't if you count winpatrol as a security program but it did help close one part of the virus. Thinks for the suggestions I am going to try that and hope it gets rid of it, and I'll let you know the results of it.
Logged
3xist
Global Moderator
Comodo's Hero
Offline
Posts: 3328
Re: Need help with a virus
«
Reply #5 on:
September 05, 2008, 09:23:53 AM »
Recommendation:
Remove Ad-aware & Webroot Spy-Sweeper (If you paid for it then keep it).
Download, Install, Update & Scan with:
Malwarebytes' Anti-Malware
SUPERAntispyware
Josh
Logged
Comodo Moderator:
Maintains order at the forum and makes sure the
policy
is followed.
My System Details:
Windows XP 32bit SP3, CIS 3.5.
Specialty:
Malware Removal & Remote Helper.
Info-Sec
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 587
Re: Need help with a virus
«
Reply #6 on:
September 05, 2008, 09:49:25 AM »
Quote from: ericd on September 04, 2008, 11:45:22 PM
I have ad-aware 2008 and spy sweeper. I don't if you count winpatrol as a security program but it did help close one part of the virus. Thinks for the suggestions I am going to try that and hope it gets rid of it, and I'll let you know the results of it.
Use malwarebytes, it is the most effective ive found at removing rogue antispywares such as antispyware master.
Logged
*Vista *CFP V3 *Avira * Avast *Spyware Doctor
*XP *Zone Alarm PRO *NOD32 V2.7 *Spysweeper
LEWIS HAMILTON
Comodo's Hero
Offline
Posts: 202
2008 Formula 1 World Champion...
Re: Need help with a virus
«
Reply #7 on:
September 05, 2008, 10:06:06 AM »
Quote from: 3xist on September 05, 2008, 09:23:53 AM
Recommendation:
Remove Ad-aware & Webroot Spy-Sweeper (If you paid for it then keep it).
Download, Install, Update & Scan with:
Malwarebytes' Anti-Malware
SUPERAntispyware
Josh
He!!o ericd. . .
Take 3xist advice! and replace your CAVS2.0 with AVIRA Free. you can download it here:
http://www.download.com/Avira-AntiVir-Personal-Free-Antivirus/3000-2239_4-10322935.html?part=dl-10322935&subj=dl&tag=button&cdlPid=10877501
«
Last Edit: September 05, 2008, 10:10:30 AM by LEWIS HAMILTON
»
Logged
"...IF YOU TRUST ME, I TRUST YOU MORE. IF YOU DON'T TRUST ME, I DON'T TRUST YOU MORE..."
ericd
Newbie
Offline
Posts: 9
Re: Need help with a virus
«
Reply #8 on:
September 05, 2008, 05:04:09 PM »
I tried running dr web cureit and it found like 20 different virus and Now i am running super anti-spyware and it has already found like 20 more viruses. Now I am going to try the mal-ware bytes thing. I will let you all know the results of the scans. Thanks for all the help that you all have given me.
Logged
CGPMaster
Global Moderator
Comodo's Hero
Offline
Posts: 797
"Honor, Courage, Commitment" - USMC
Re: Need help with a virus
«
Reply #9 on:
September 05, 2008, 05:05:32 PM »
You are most welcome,
Superantispyware works better while in safe mode
CG
Logged
Comodo Moderator:
Maintains order at the forum and makes sure the
policy
is followed.
My System Details:
32bit Windows XP, CIS, SAS
Specialty:
Infection Removal & Remote Support
grayhair
Comodo Loves me
Offline
Posts: 184
Re: Need help with a virus
«
Reply #10 on:
September 05, 2008, 05:40:26 PM »
Quote from: ericd on September 05, 2008, 05:04:09 PM
I tried running dr web cureit and it found like 20 different virus and Now i am running super anti-spyware and it has already found like 20 more viruses. Now I am going to try the mal-ware bytes thing. I will let you all know the results of the scans. Thanks for all the help that you all have given me.
Some good news! And just in time for the weekend LOL.
Don't be afraid to run these various scans several times. I have found that in a very infected machine sometimes it takes the first scan (sometimes two) to "make the bunnies run." Have you installed Avira Free yet? I would do that, and again make sure it has the latest updates, and run the thing several times. Avira would be a better AV than Comodo ver.2 right now. Comodo ver. 3 should be out soon, and promises to be much better. Let us know how this thing all turns out.
Good luck.
Logged
Info-Sec
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 587
Re: Need help with a virus
«
Reply #11 on:
September 06, 2008, 01:13:47 AM »
Quote from: ericd on September 05, 2008, 05:04:09 PM
I tried running dr web cureit and it found like 20 different virus and Now i am running super anti-spyware and it has already found like 20 more viruses. Now I am going to try the mal-ware bytes thing. I will let you all know the results of the scans. Thanks for all the help that you all have given me.
While your running scans run a spybot search and destroy scan, it isnt as good as it used to be, but generally if it dosnt detect anything then your system should run fine.
Logged
*Vista *CFP V3 *Avira * Avast *Spyware Doctor
*XP *Zone Alarm PRO *NOD32 V2.7 *Spysweeper
3xist
Global Moderator
Comodo's Hero
Offline
Posts: 3328
Re: Need help with a virus
«
Reply #12 on:
September 06, 2008, 01:18:16 AM »
Quote from: ericd on September 05, 2008, 05:04:09 PM
I tried running dr web cureit and it found like 20 different virus and Now i am running super anti-spyware and it has already found like 20 more viruses. Now I am going to try the mal-ware bytes thing. I will let you all know the results of the scans. Thanks for all the help that you all have given me.
Thanks.
Try that for now and let us know how things go.
Josh
Logged
Comodo Moderator:
Maintains order at the forum and makes sure the
policy
is followed.
My System Details:
Windows XP 32bit SP3, CIS 3.5.
Specialty:
Malware Removal & Remote Helper.
ericd
Newbie
Offline
Posts: 9
Re: Need help with a virus
«
Reply #13 on:
September 07, 2008, 01:14:43 AM »
Super Anti-Spyware finished running and it found like 400 different objects, and I downloaded and installed Avira Antivirus and it found about 10 Trojans and a couple of viruses. I ran the Malware bytes thing and it found like 10-15 infected registry keys. I have been running the scans and it has been finding nothing. However the pchealth folder that has the virus or whatever in it, sometimes come back after I delete the folder, so maybe there is something that the scans are missing. Is there something wrong or am I just paranoid? Thanks for any help.
Logged
3xist
Global Moderator
Comodo's Hero
Offline
Posts: 3328
Re: Need help with a virus
«
Reply #14 on:
September 07, 2008, 02:09:36 AM »
Quote from: ericd on September 07, 2008, 01:14:43 AM
Super Anti-Spyware finished running and it found like 400 different objects, and I downloaded and installed Avira Antivirus and it found about 10 Trojans and a couple of viruses. I ran the Malware bytes thing and it found like 10-15 infected registry keys. I have been running the scans and it has been finding nothing. However the pchealth folder that has the virus or whatever in it, sometimes come back after I delete the folder, so maybe there is something that the scans are missing. Is there something wrong or am I just paranoid? Thanks for any help.
Is your PC Running OK?
Are the scans removing threats found?
Josh
Logged
Comodo Moderator:
Maintains order at the forum and makes sure the
policy
is followed.
My System Details:
Windows XP 32bit SP3, CIS 3.5.
Specialty:
Malware Removal & Remote Helper.
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.452 seconds with 19 queries.
Powered by SMF 1.1.7
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com