Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 19, 2010, 05:28:03 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
372987
Posts
41369
Topics
94036
Members
Latest Member:
schematicfanatic
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Virus/Malware Removal Assistance
Unknown exe(s)
« previous
next »
Pages:
[
1
]
Author
Topic: Unknown exe(s) (Read 2714 times)
efsane
Newbie
Offline
Posts: 5
Unknown exe(s)
«
on:
January 23, 2008, 04:18:47 AM »
Hello all
I have realized this alert on EVERY system startup. The icon is same. But name of exe "changes".
Comodo shows full path of folder. I go there, nothing appears about this exe.
After i block itS internet connection, it can't connect to internet.
Anyone has idea about this?
Logged
- C O M O D O -
aXes
Comodo Loves me
Offline
Posts: 110
aXes for praxes!
Re: Unknown exe(s)
«
Reply #1 on:
January 23, 2008, 05:45:57 AM »
Hi efsane and welcome to the forum!
I think you have metamorphic virus(es). But the interesting one is you have
Avast
AV.
Did you scan all of your computer? If so, there is a fact that Melih was announced: Era of detection is dead!
I suggest you try another AV scanners. Fortunately you have CFP and at least you can stop viruses.
aXes
«
Last Edit: January 23, 2008, 05:47:34 AM by aXes
»
Logged
Don't be afraid your life will end; be afraid that it will
never
begin!
N.T.T.W.
Global Moderator
Comodo's Hero
Offline
Posts: 1124
A minute of your time can help many.
Re: Unknown exe(s)
«
Reply #2 on:
January 23, 2008, 07:34:39 AM »
Might be worth setting Avast to do a boot time scan.
Also might be worth setting a global rule preventing traffic to or from 85.197.99.143.
«
Last Edit: January 23, 2008, 07:36:37 AM by N.T.T.W.
»
Logged
Post proelia praemia.
Die dulci fruere.
Ragwing
Global Moderator
Comodo's Hero
Offline
Posts: 3454
Re: Unknown exe(s)
«
Reply #3 on:
January 23, 2008, 10:58:06 AM »
This sounds like something really bad. Try doing a boot-time scan, as suggested by N.T.T.W. If it doesn't work, try some other AV's.
If it's still there, return with your results here.
Cheers,
Ragwing
Logged
Forum Policy
FAQs
AnotherOne
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 712
Re: Unknown exe(s)
«
Reply #4 on:
January 28, 2008, 01:57:37 AM »
Two points. First, the fact that you can't find the file by checking the path shown means either the file is stealthed (suggesting a rootkit) or it is extracted to RAM and the path is only a virtual path. Try a rootkit scan if nothing shows up with AV scans. I believe that Avira's Antivir had one of the best detection rates of the free AV scanners.
Second, you can try tracking down the source of the file by right-clicking it on the Active Processes window. There is an option to Terminate and Quarantine the file. This may cause another file to reveal itself when it tries to check up on the quarantined file. I've never tried this, but I assume that an alert will pop up when a quarantined file access is attempted. On that pop-up, you will also have the option to quarantine the new file. You may have to do this for a few files. This may not work if the first file is virtual. It depends on how the presence of the first file is checked up on.
Logged
What do you mean, my shoes are on the wrong feet??? These are the only feet I've got!
SS26
Comodo's Hero
Offline
Posts: 1666
Re: Unknown exe(s)
«
Reply #5 on:
January 28, 2008, 03:00:49 AM »
You may also download
DrWeb CureIT scanner
, switch off internet connection (best thing is to unplug your modem).
Then boot in safe mode and run CureIT. It is a single executable wich doesn't need to be installed, but it is almost equal to standard DrWeb package capability.
«
Last Edit: January 28, 2008, 03:04:06 AM by goodbrazer
»
Logged
Ragwing
Global Moderator
Comodo's Hero
Offline
Posts: 3454
Re: Unknown exe(s)
«
Reply #6 on:
January 28, 2008, 10:44:34 AM »
If it's a rootkit, then
RootkitRevealer
or
IceSword
should be good enough.
Logged
Forum Policy
FAQs
AnotherOne
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 712
Re: Unknown exe(s)
«
Reply #7 on:
January 28, 2008, 07:06:21 PM »
Rootkit Revealer does not have any removal tools and I am not sure that Ice Sword does either (couldn't get it to work on my system for some reason). Another highly regarded rootkit tool is Panda Antirootkit:
http://research.pandasecurity.com/archive/New-Panda-Anti_2D00_Rootkit-_2D00_-Version-1.07.aspx
Download from the above page. It has removal tools and is supposed to be easy to use. Another simple test for rootkit presence is System Virginity Verifier at
www.invisiblethings.org
Logged
What do you mean, my shoes are on the wrong feet??? These are the only feet I've got!
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 0.054 seconds with 16 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com