Welcome, Guest. Please login or register.
January 04, 2010, 02:24:24 AM

Login with username, password and session length

347320 Posts
38418 Topics
87307 Members

Latest Member: Kerby

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Virus/Malware Removal Assistance
| | | |-+  possible malware here?
« previous next »
Pages: 1 [2] Go Down Print
Author Topic: possible malware here?  (Read 1811 times)
mr fett
Newbie
*
Offline Offline

Posts: 21


« Reply #15 on: October 25, 2009, 02:26:14 PM »

Thanks- I appreciate you looking at it. What about that A2 log? Is that the normal appearance? I ask because this all prompted me to do a multi-scan of my desktop computer, and while Malwarebutes and SuperantiSpyware only found cookies, A2 is finding more cookies and some medium risk registry stuff that looks alarming along with some high risk stuff. I wanted to post the A2 log when it finishes to get your opinion, but I want to make sure I post a correct log file that can be read and makes sense. Is it standard protocol to just convert the db3 file to txt after it is saved, or should I be saving it as something different? I'm wondering if the trojan I had a few weeks ago that I thought I removed is still there.
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6629


Why not ? The choice is yours !


« Reply #16 on: October 25, 2009, 03:15:24 PM »

Thanks- I appreciate you looking at it. What about that A2 log? Is that the normal appearance? I ask because this all prompted me to do a multi-scan of my desktop computer, and while Malwarebutes and SuperantiSpyware only found cookies, A2 is finding more cookies and some medium risk registry stuff that looks alarming along with some high risk stuff. I wanted to post the A2 log when it finishes to get your opinion, but I want to make sure I post a correct log file that can be read and makes sense. Is it standard protocol to just convert the db3 file to txt after it is saved, or should I be saving it as something different? I'm wondering if the trojan I had a few weeks ago that I thought I removed is still there.
Hi,

well no, that's not really common to change it. But that allows me to take a look at it.

***looking at it***
***finds a corrupted file***

well, can't use it, sorry.

Could you do a scan and take a screenshot of the results (remember to expand all tabs so I can see where the files are !) ? (How to take screenshots)

eXPerience
Logged

mr fett
Newbie
*
Offline Offline

Posts: 21


« Reply #17 on: October 25, 2009, 04:03:12 PM »

I think a part of my issue is in the fact that before closing down A2, I tried quarantining the 4 found objects. I wasn't allowed to, so I didn't get a typical list of threats like I've seen in Adaware, etc- which I assume is the log file you're after? The log file created by A2 that I found looks like it's just the actions it carried out, not the files I saw it find (if this makes any sense), sort of what a Search and Destroy logfile looks like to me. I've never used the program before, so I don't know how it works. If I posted the correct file, how do people upload it so that it can be read if it's saved as a db3 file by the program? i can't find any options on controlling the log file saves. Sorry, but this program seems to be more confusing than what it seems it should be. Maybe you and I are are talking about 2 different things, and I can't explain myself well enough?  Sorry to be a PITA....

My desktop A2 scan is still running so when it's done I'll do a screenshot. Are you wanting a screenshot of the A2 scan interface where it lists the objects? If so, the full list all won't fit onto one screen shot, and the names of some are so long they need to be scrolled to see them entirely. Would I take a shot, then scroll then take another shot?

Hi,

well no, that's not really common to change it. But that allows me to take a look at it.

***looking at it***
***finds a corrupted file***

well, can't use it, sorry.

Could you do a scan and take a screenshot of the results (remember to expand all tabs so I can see where the files are !) ? (How to take screenshots)

eXPerience
Logged
mr fett
Newbie
*
Offline Offline

Posts: 21


« Reply #18 on: October 25, 2009, 05:22:04 PM »

I don't know how I messed up with the logfile/report from my laptop, but here's the report and screenshots for my desktop A2 scan. The last 2 on drive H are safe. It's the other ones I don't know about. The Ultra VNC is a program a buddy put on my computer who is much more savvy than I, so I assume they're ok too.

 i happened to find a db3 file for this one too- looks like I mistook it before dor a log report that I never actually saved  Embarrassed I have no idea now why it looks so messed up....

Here also is the Hijack This log
« Last Edit: October 25, 2009, 05:42:56 PM by mr fett » Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6629


Why not ? The choice is yours !


« Reply #19 on: October 26, 2009, 03:41:38 AM »

Hi,

I sujest you quarentine :

- spywarebot
- the IE plugin
- HTML.infected
- Trojan.generic!IK

best regards,
eXPerience
Logged

mr fett
Newbie
*
Offline Offline

Posts: 21


« Reply #20 on: October 26, 2009, 07:48:56 PM »

Thanks.

The program cannot quarantine the spywarebot (2 traces). I get an error message for them, saying they cannot be deleted, and to consult the experts at the A2 forum. This is the same message I got when I tried quarantining the 4 objects on my laptop. What do you suggest now?

This may sound like a dumb question, but why am I only quarantining these objects, and not deleting them? What do I do with them now that they are quarantined? Once I delete eventually them do I do a system clean on that drive, delete all restore points and re-scan?

Should I be deleting all the other things (tracking cookies, etc) so they don't sit there and pop up again on future scans? Is there a way in A2 to ignore the files I know are false positives so they don't pop up again? I can't seem to find an ignore option.
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6629


Why not ? The choice is yours !


« Reply #21 on: October 27, 2009, 03:41:16 AM »

Quote
Should I be deleting all the other things (tracking cookies, etc) so they don't sit there and pop up again on future scans? Is there a way in A2 to ignore the files I know are false positives so they don't pop up again? I can't seem to find an ignore option.
I think rightclicking and adding to the whitelist should do if I remember right?

Quote
The program cannot quarantine the spywarebot (2 traces). I get an error message for them, saying they cannot be deleted, and to consult the experts at the A2 forum. This is the same message I got when I tried quarantining the 4 objects on my laptop. What do you suggest now?
I'm a bit puzzled, because I don't know if it's actually cleaned now or not....... Hijackthis looks clean....
Well, if you really feel you need to I sujest you scan with Superantispyware. if that doesn't help, you will need to look for more expert cleaning : Comodo LivePcSupport

Quote
This may sound like a dumb question, but why am I only quarantining these objects, and not deleting them? What do I do with them now that they are quarantined? Once I delete eventually them do I do a system clean on that drive, delete all restore points and re-scan?
It's safer, imagine that you actually need those files for an application or so, well, you can still repair it then. If you delete it, it's lost forever.

eXPerience
Logged

Kyle
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 3285



WWW
« Reply #22 on: October 27, 2009, 05:59:46 AM »

 Off-Topic! Can a Mod please correct the spelling of the topic? I know I'm being fussy.. It just tickles me every time I see it.. lol
Logged

E5200 2.5ghz [at] 3.33ghz, POV 9800gt 512mb, 2gb DDR2 RAM.  500gb. HDD


~~~
Trying to see if I can completely switch to linux Cheesy
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6629


Why not ? The choice is yours !


« Reply #23 on: October 27, 2009, 10:52:10 AM »

Off-Topic! Can a Mod please correct the spelling of the topic? I know I'm being fussy.. It just tickles me every time I see it.. lol
I find it funny, that's why I kept it there in the first place  Wink

ok, I only changed the OP Smiley

eXPerience
Logged

mr fett
Newbie
*
Offline Offline

Posts: 21


« Reply #24 on: October 27, 2009, 02:24:00 PM »

Off-Topic! Can a Mod please correct the spelling of the topic? I know I'm being fussy.. It just tickles me every time I see it.. lol

 Embarrassed

yeah, I noticed that a while ago, but didn't know how to fix it. At least I could find my post easily  Grin oops
Logged
mr fett
Newbie
*
Offline Offline

Posts: 21


« Reply #25 on: October 27, 2009, 02:26:24 PM »

I think rightclicking and adding to the whitelist should do if I remember right?
I'm a bit puzzled, because I don't know if it's actually cleaned now or not....... Hijackthis looks clean....
Well, if you really feel you need to I sujest you scan with Superantispyware. if that doesn't help, you will need to look for more expert cleaning : Comodo LivePcSupport
It's safer, imagine that you actually need those files for an application or so, well, you can still repair it then. If you delete it, it's lost forever.

eXPerience

OK- I'll try this when I get home from work tonight. From what I remember thoguh, Superantispyware didn't find those objects in the first place.... Huh

I'll re-run everything and see what I find.
Thanks.
Logged
mr fett
Newbie
*
Offline Offline

Posts: 21


« Reply #26 on: October 28, 2009, 08:01:20 PM »

A2 and Hijack This logs from follow up scan. The "undeletable" files didn't show up for some reason but the 2 other objects did. Spybot, Malwarebytes, SuperAntispaware, and Adaware all missed them. So I cleaned all drives and deleted restore points, restarted and scanned again with A2- nothing found. I'll have to see if they pop up again in a couple days....
Logged
Tags:
Pages: 1 [2] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.043 seconds with 17 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com