Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
January 05, 2010, 06:08:25 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
347658
Posts
38466
Topics
87429
Members
Latest Member:
mariner8381
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Virus/Malware Removal Assistance
possible malware here?
« previous
next »
Pages:
1
[
2
]
Author
Topic: possible malware here? (Read 1841 times)
mr fett
Newbie
Offline
Posts: 21
Re: possible walware here?
«
Reply #15 on:
October 25, 2009, 02:26:14 PM »
Thanks- I appreciate you looking at it. What about that A2 log? Is that the normal appearance? I ask because this all prompted me to do a multi-scan of my desktop computer, and while Malwarebutes and SuperantiSpyware only found cookies, A2 is finding more cookies and some medium risk registry stuff that looks alarming along with some high risk stuff. I wanted to post the A2 log when it finishes to get your opinion, but I want to make sure I post a correct log file that can be read and makes sense. Is it standard protocol to just convert the db3 file to txt after it is saved, or should I be saving it as something different? I'm wondering if the trojan I had a few weeks ago that I thought I removed is still there.
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
Offline
Posts: 6633
Why not ? The choice is yours !
Re: possible walware here?
«
Reply #16 on:
October 25, 2009, 03:15:24 PM »
Quote from: mr fett on October 25, 2009, 02:26:14 PM
Thanks- I appreciate you looking at it. What about that A2 log? Is that the normal appearance? I ask because this all prompted me to do a multi-scan of my desktop computer, and while Malwarebutes and SuperantiSpyware only found cookies, A2 is finding more cookies and some medium risk registry stuff that looks alarming along with some high risk stuff. I wanted to post the A2 log when it finishes to get your opinion, but I want to make sure I post a correct log file that can be read and makes sense. Is it standard protocol to just convert the db3 file to txt after it is saved, or should I be saving it as something different? I'm wondering if the trojan I had a few weeks ago that I thought I removed is still there.
Hi,
well no, that's not really common to change it. But that allows me to take a look at it.
***looking at it***
***finds a corrupted file***
well, can't use it, sorry.
Could you do a scan and take a screenshot of the results (remember to expand all tabs so I can see where the files are !) ? (
How to take screenshots
)
eXPerience
Logged
mr fett
Newbie
Offline
Posts: 21
Re: possible walware here?
«
Reply #17 on:
October 25, 2009, 04:03:12 PM »
I think a part of my issue is in the fact that before closing down A2, I tried quarantining the 4 found objects. I wasn't allowed to, so I didn't get a typical list of threats like I've seen in Adaware, etc- which I assume is the log file you're after? The log file created by A2 that I found looks like it's just the actions it carried out, not the files I saw it find (if this makes any sense), sort of what a Search and Destroy logfile looks like to me. I've never used the program before, so I don't know how it works. If I posted the correct file, how do people upload it so that it can be read if it's saved as a db3 file by the program? i can't find any options on controlling the log file saves. Sorry, but this program seems to be more confusing than what it seems it should be. Maybe you and I are are talking about 2 different things, and I can't explain myself well enough? Sorry to be a PITA....
My desktop A2 scan is still running so when it's done I'll do a screenshot. Are you wanting a screenshot of the A2 scan interface where it lists the objects? If so, the full list all won't fit onto one screen shot, and the names of some are so long they need to be scrolled to see them entirely. Would I take a shot, then scroll then take another shot?
Quote from: eXPerience on October 25, 2009, 03:15:24 PM
Hi,
well no, that's not really common to change it. But that allows me to take a look at it.
***looking at it***
***finds a corrupted file***
well, can't use it, sorry.
Could you do a scan and take a screenshot of the results (remember to expand all tabs so I can see where the files are !) ? (
How to take screenshots
)
eXPerience
Logged
mr fett
Newbie
Offline
Posts: 21
Re: possible walware here?
«
Reply #18 on:
October 25, 2009, 05:22:04 PM »
I don't know how I messed up with the logfile/report from my laptop, but here's the report and screenshots for my desktop A2 scan. The last 2 on drive H are safe. It's the other ones I don't know about. The Ultra VNC is a program a buddy put on my computer who is much more savvy than I, so I assume they're ok too.
i happened to find a db3 file for this one too- looks like I mistook it before dor a log report that I never actually saved
I have no idea now why it looks so messed up....
Here also is the Hijack This log
«
Last Edit: October 25, 2009, 05:42:56 PM by mr fett
»
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
Offline
Posts: 6633
Why not ? The choice is yours !
Re: possible walware here?
«
Reply #19 on:
October 26, 2009, 03:41:38 AM »
Hi,
I sujest you quarentine :
- spywarebot
- the IE plugin
- HTML.infected
- Trojan.generic!IK
best regards,
eXPerience
Logged
mr fett
Newbie
Offline
Posts: 21
Re: possible walware here?
«
Reply #20 on:
October 26, 2009, 07:48:56 PM »
Thanks.
The program cannot quarantine the spywarebot (2 traces). I get an error message for them, saying they cannot be deleted, and to consult the experts at the A2 forum. This is the same message I got when I tried quarantining the 4 objects on my laptop. What do you suggest now?
This may sound like a dumb question, but why am I only quarantining these objects, and not deleting them? What do I do with them now that they are quarantined? Once I delete eventually them do I do a system clean on that drive, delete all restore points and re-scan?
Should I be deleting all the other things (tracking cookies, etc) so they don't sit there and pop up again on future scans? Is there a way in A2 to ignore the files I know are false positives so they don't pop up again? I can't seem to find an ignore option.
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
Offline
Posts: 6633
Why not ? The choice is yours !
Re: possible walware here?
«
Reply #21 on:
October 27, 2009, 03:41:16 AM »
Quote
Should I be deleting all the other things (tracking cookies, etc) so they don't sit there and pop up again on future scans? Is there a way in A2 to ignore the files I know are false positives so they don't pop up again? I can't seem to find an ignore option.
I think rightclicking and adding to the whitelist should do if I remember right?
Quote
The program cannot quarantine the spywarebot (2 traces). I get an error message for them, saying they cannot be deleted, and to consult the experts at the A2 forum. This is the same message I got when I tried quarantining the 4 objects on my laptop. What do you suggest now?
I'm a bit puzzled, because I don't know if it's actually cleaned now or not....... Hijackthis looks clean....
Well, if you really feel you need to I sujest you scan with Superantispyware. if that doesn't help, you will need to look for more expert cleaning : Comodo LivePcSupport
Quote
This may sound like a dumb question, but why am I only quarantining these objects, and not deleting them? What do I do with them now that they are quarantined? Once I delete eventually them do I do a system clean on that drive, delete all restore points and re-scan?
It's safer, imagine that you actually need those files for an application or so, well, you can still repair it then. If you delete it, it's lost forever.
eXPerience
Logged
Kyle
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 3286
Re: possible walware here?
«
Reply #22 on:
October 27, 2009, 05:59:46 AM »
Can a Mod please correct the spelling of the topic? I know I'm being fussy.. It just tickles me every time I see it.. lol
Logged
E5200 2.5ghz [at] 3.33ghz, POV 9800gt 512mb, 2gb DDR2 RAM. 500gb. HDD
~~~
Trying to see if I can completely switch to linux
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
Offline
Posts: 6633
Why not ? The choice is yours !
Re: possible walware here?
«
Reply #23 on:
October 27, 2009, 10:52:10 AM »
Quote from: Kyle on October 27, 2009, 05:59:46 AM
Can a Mod please correct the spelling of the topic? I know I'm being fussy.. It just tickles me every time I see it.. lol
I find it funny, that's why I kept it there in the first place
ok, I only changed the OP
eXPerience
Logged
mr fett
Newbie
Offline
Posts: 21
Re: possible walware here?
«
Reply #24 on:
October 27, 2009, 02:24:00 PM »
Quote from: Kyle on October 27, 2009, 05:59:46 AM
Can a Mod please correct the spelling of the topic? I know I'm being fussy.. It just tickles me every time I see it.. lol
yeah, I noticed that a while ago, but didn't know how to fix it. At least I could find my post easily
oops
Logged
mr fett
Newbie
Offline
Posts: 21
Re: possible walware here?
«
Reply #25 on:
October 27, 2009, 02:26:24 PM »
Quote from: eXPerience on October 27, 2009, 03:41:16 AM
I think rightclicking and adding to the whitelist should do if I remember right?
I'm a bit puzzled, because I don't know if it's actually cleaned now or not....... Hijackthis looks clean....
Well, if you really feel you need to I sujest you scan with Superantispyware. if that doesn't help, you will need to look for more expert cleaning : Comodo LivePcSupport
It's safer, imagine that you actually need those files for an application or so, well, you can still repair it then. If you delete it, it's lost forever.
eXPerience
OK- I'll try this when I get home from work tonight. From what I remember thoguh, Superantispyware didn't find those objects in the first place....
I'll re-run everything and see what I find.
Thanks.
Logged
mr fett
Newbie
Offline
Posts: 21
Re: possible malware here?
«
Reply #26 on:
October 28, 2009, 08:01:20 PM »
A2 and Hijack This logs from follow up scan. The "undeletable" files didn't show up for some reason but the 2 other objects did. Spybot, Malwarebytes, SuperAntispaware, and Adaware all missed them. So I cleaned all drives and deleted restore points, restarted and scanned again with A2- nothing found. I'll have to see if they pop up again in a couple days....
Logged
Tags:
Pages:
1
[
2
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to Help Comodo?
-----------------------------
=> Help Spread the Word - Banners and Logos
=> How Can I Help Comodo? (Please We Need You!)
===> Help Spread the Word! (Please Read and Help)
===> Report Comodo Forum / Web Site Issues
=> Please Tell Us Your Views and Vote Here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> AntiVirus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> AntiVirus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> AntiVirus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> AntiVirus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> Graphical User Interface (GUI) Wishlist
===> Bug Report - CIS
=====> AntiVirus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> GUI / Miscellaneous / Other Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless World!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to You)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Other Security Products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
=> Other Firewalls
=> Host Intrusion Prevention Systems (HIPS)
=> AntiPhishing Solutions
Page created in 0.045 seconds with 17 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com