Welcome, Guest. Please login or register.
November 18, 2008, 06:12:06 PM

Login with username, password and session length

212227 Posts
24530 Topics
57713 Members

Latest Member: desertrat2143

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Virus/Malware Removal Assistance
| | | |-+  Need help with a virus
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: Need help with a virus  (Read 1837 times)
ericd
Newbie
*
Offline Offline

Posts: 9


« on: September 04, 2008, 09:29:23 PM »

My computer has windows xp service pack 2 and I have the comodo firewall 3 and the comodo antivirus 2.  A couple of days ago I got a lot of error messages saying I am infected and that I should download anti-spyware master to protect the computer.  Well, when I tryed to download it the antivirus told me that it was a virus.  By then though the program was already on the computer and it started to download x-rated stuff onto the desktop.  I got that to finally stop but it is still trying to gain access to the internet again so it can start it all over again.  When that happened a folder call pchealth popped up in the program files and windows folders. The program inside of it is not pchealth instead it is something else that I don't know, because I am on a friend's computer and can't look it up now.  When I scanned the computer it did find seven virus and about 8000 suspicious files and when I try to submit them the firewall says that rundll.exe is trying to get shutdown privileges.  When I hit deny, it shuts down the internet connection. Now the firewall pop ups don't have the writing on the tops on them anymore.  Is there anything that I can do or is it a lost cause.  Thinks for any help.
Logged
grayhair
Comodo Loves me
****
Offline Offline

Posts: 184


« Reply #1 on: September 04, 2008, 10:42:26 PM »

   Yikes!!  I don't know anything specifically about this "antispyware master."  My first words of advice would be not to connect it to the internet right now, as you may have unintentionally installed some sort of downloader, and being connected could make things worse.  Besides Comodo Firewall v.3 and Comodo antivirus 2, what other security programs do you have installed?  There are things you can do--the worst being a reformat of your operating disc.  Do you have backups of your documents, important files, installation programs, etc.?  If not, don't try to back things up right now, as the malware could be scattered around your computer.  Be patient, hopefully help will be on the way here.
   Anyone know anything specific about this "Antispyware Master?"
Logged
grayhair
Comodo Loves me
****
Offline Offline

Posts: 184


« Reply #2 on: September 04, 2008, 10:55:06 PM »

   I Googled a little bit about the AntiSpyware Master thing.  It does appear to be nasty.  I did see in one forum that someone had good results in getting rid of it by installing and running SuperAntiSpy (which is very legitimate!).  Here is the link to SuperAntiSpy:

Edit: I hit the wrong key and sent this on its way incomplete.  Now the finish:

   http://www.superantispyware.com/

   If your friend will let you, I would download SuperAntiSpy on your friends computer, save the install file on a CD, then install it on your computer from the CD.  After installation it will want you to update it--maybe just do a COMPLETE scan first, and see what it picks up.  Then maybe connect the computer to the internet, update the program, and do another complete scan.
   Probably SuperAntiSpy won't be the only thing you will need to run, but it is a start.

   Second edit:  just download the free edition of SuperAntiSpy for now.
« Last Edit: September 04, 2008, 11:03:02 PM by grayhair » Logged
gandalicious
Bad guy
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3496


kkeewwwwlll


« Reply #3 on: September 04, 2008, 11:09:55 PM »

or... maybe you can try DrWebCureIt . it's portable, no installation needed. don't forget to scan your comp with it or superAntiSpyware on safe mode.  Thumb Up goodluck  Wave
Logged
ericd
Newbie
*
Offline Offline

Posts: 9


« Reply #4 on: September 04, 2008, 11:45:22 PM »

Besides Comodo Firewall v.3 and Comodo antivirus 2, what other security programs do you have installed?
I have ad-aware 2008 and spy sweeper.  I don't if you count winpatrol as a security program but it did help close one part of the virus.  Thinks for the suggestions I am going to try that and hope it gets rid of it, and I'll let you know the results of it.
Logged
3xist
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3328



« Reply #5 on: September 05, 2008, 09:23:53 AM »

Recommendation:

Remove Ad-aware & Webroot Spy-Sweeper (If you paid for it then keep it).

Download, Install, Update & Scan with:
Malwarebytes' Anti-Malware
SUPERAntispyware

Josh
Logged

Comodo Moderator: Maintains order at the forum and makes sure the policy is followed.
My System Details: Windows XP 32bit SP3, CIS 3.5.
Specialty: Malware Removal & Remote Helper.
Info-Sec
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 587



« Reply #6 on: September 05, 2008, 09:49:25 AM »

I have ad-aware 2008 and spy sweeper.  I don't if you count winpatrol as a security program but it did help close one part of the virus.  Thinks for the suggestions I am going to try that and hope it gets rid of it, and I'll let you know the results of it.

Use malwarebytes, it is the most effective ive found at removing rogue antispywares such as antispyware master.
Logged

*Vista *CFP V3 *Avira * Avast *Spyware Doctor
*XP *Zone Alarm PRO *NOD32 V2.7 *Spysweeper
LEWIS HAMILTON
Comodo's Hero
*****
Offline Offline

Posts: 202


2008 Formula 1 World Champion...


« Reply #7 on: September 05, 2008, 10:06:06 AM »

Recommendation:

Remove Ad-aware & Webroot Spy-Sweeper (If you paid for it then keep it).

Download, Install, Update & Scan with:
Malwarebytes' Anti-Malware

SUPERAntispyware

Josh

He!!o ericd. . .   Wave

Take 3xist advice! and replace your CAVS2.0 with AVIRA Free. you can download it here: http://www.download.com/Avira-AntiVir-Personal-Free-Antivirus/3000-2239_4-10322935.html?part=dl-10322935&subj=dl&tag=button&cdlPid=10877501

 Cheers  Cheers  Cheers
           Cheers  Cheers  Cheers
                     Cheers  Cheers  Cheers
« Last Edit: September 05, 2008, 10:10:30 AM by LEWIS HAMILTON » Logged

"...IF YOU TRUST ME, I TRUST YOU MORE. IF YOU DON'T TRUST ME, I DON'T TRUST YOU MORE..."
ericd
Newbie
*
Offline Offline

Posts: 9


« Reply #8 on: September 05, 2008, 05:04:09 PM »

I tried running dr web cureit and it found like 20 different virus and Now i am running super anti-spyware and it has already found like 20 more viruses. Now I am going to try the mal-ware bytes thing.  I will let you all know the results of the scans. Thanks for all the help that you all have given me.
Logged
CGPMaster
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 797


"Honor, Courage, Commitment" - USMC


« Reply #9 on: September 05, 2008, 05:05:32 PM »

You are most welcome,

Superantispyware works better while in safe mode

CG

Logged

Comodo Moderator: Maintains order at the forum and makes sure the policy is followed.
My System Details: 32bit Windows XP, CIS, SAS
Specialty: Infection Removal & Remote Support
grayhair
Comodo Loves me
****
Offline Offline

Posts: 184


« Reply #10 on: September 05, 2008, 05:40:26 PM »

I tried running dr web cureit and it found like 20 different virus and Now i am running super anti-spyware and it has already found like 20 more viruses. Now I am going to try the mal-ware bytes thing.  I will let you all know the results of the scans. Thanks for all the help that you all have given me.


   Some good news! And just in time for the weekend LOL.   Cheers

   Don't be afraid to run these various scans several times.  I have found that in a very infected machine sometimes it takes the first scan (sometimes two) to "make the bunnies run."  Have you installed Avira Free yet?  I would do that, and again make sure it has the latest updates, and run the thing several times.  Avira would be a better AV than Comodo ver.2 right now.  Comodo ver. 3 should be out soon, and promises to be much better.  Let us know how this thing all turns out.

   Good luck.
Logged
Info-Sec
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 587



« Reply #11 on: September 06, 2008, 01:13:47 AM »

I tried running dr web cureit and it found like 20 different virus and Now i am running super anti-spyware and it has already found like 20 more viruses. Now I am going to try the mal-ware bytes thing.  I will let you all know the results of the scans. Thanks for all the help that you all have given me.

While your running scans run a spybot search and destroy scan, it isnt as good as it used to be, but generally if it dosnt detect anything then your system should run fine.
Logged

*Vista *CFP V3 *Avira * Avast *Spyware Doctor
*XP *Zone Alarm PRO *NOD32 V2.7 *Spysweeper
3xist
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3328



« Reply #12 on: September 06, 2008, 01:18:16 AM »

I tried running dr web cureit and it found like 20 different virus and Now i am running super anti-spyware and it has already found like 20 more viruses. Now I am going to try the mal-ware bytes thing.  I will let you all know the results of the scans. Thanks for all the help that you all have given me.

Thanks.

Try that for now and let us know how things go.

Josh
Logged

Comodo Moderator: Maintains order at the forum and makes sure the policy is followed.
My System Details: Windows XP 32bit SP3, CIS 3.5.
Specialty: Malware Removal & Remote Helper.
ericd
Newbie
*
Offline Offline

Posts: 9


« Reply #13 on: September 07, 2008, 01:14:43 AM »

Super Anti-Spyware finished running and it found like 400 different objects, and I downloaded and installed Avira Antivirus and it found about 10 Trojans and a couple of viruses. I ran the Malware bytes thing and it found like 10-15 infected registry keys.  I have been running the scans and it has been finding nothing.  However the pchealth folder that has the virus or whatever in it, sometimes come back after I delete the folder, so maybe there is something that the scans are missing.  Is there something wrong or am I just paranoid?  Thanks for any help.
Logged
3xist
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3328



« Reply #14 on: September 07, 2008, 02:09:36 AM »

Super Anti-Spyware finished running and it found like 400 different objects, and I downloaded and installed Avira Antivirus and it found about 10 Trojans and a couple of viruses. I ran the Malware bytes thing and it found like 10-15 infected registry keys.  I have been running the scans and it has been finding nothing.  However the pchealth folder that has the virus or whatever in it, sometimes come back after I delete the folder, so maybe there is something that the scans are missing.  Is there something wrong or am I just paranoid?  Thanks for any help.

Is your PC Running OK?

Are the scans removing threats found?

Josh
Logged

Comodo Moderator: Maintains order at the forum and makes sure the policy is followed.
My System Details: Windows XP 32bit SP3, CIS 3.5.
Specialty: Malware Removal & Remote Helper.
Tags:
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.375 seconds with 19 queries.
Powered by SMF 1.1.7 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com