Welcome, Guest. Please login or register.
November 18, 2008, 06:29:58 PM

Login with username, password and session length

212232 Posts
24531 Topics
57714 Members

Latest Member: wilhoit

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Virus/Malware Removal Assistance
| | | |-+  Unknown exe(s)
« previous next »
Pages: [1] Go Down Print
Author Topic: Unknown exe(s)  (Read 1814 times)
efsane
Newbie
*
Offline Offline

Posts: 5



« on: January 23, 2008, 04:18:47 AM »

Hello all

I have realized this alert on EVERY system startup. The icon is same. But name of exe "changes".







Comodo shows full path of folder. I go there, nothing appears about this exe.

After i block itS internet connection, it can't connect to internet.




Anyone has idea about this?
Logged

- C O M O D O -
aXes
Comodo Loves me
****
Offline Offline

Posts: 110


aXes for praxes!


« Reply #1 on: January 23, 2008, 05:45:57 AM »

Hi efsane and welcome to the forum!

I think you have metamorphic virus(es). But the interesting one is you have Avast AV.

Did you scan all of your computer? If so, there is a fact that Melih was announced: Era of detection is dead!

I suggest you try another AV scanners. Fortunately you have CFP and at least you can stop viruses.

aXes
« Last Edit: January 23, 2008, 05:47:34 AM by aXes » Logged

Don't be afraid your life will end; be afraid that it will never begin!
N.T.T.W.
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1124


A minute of your time can help many.


« Reply #2 on: January 23, 2008, 07:34:39 AM »

Might be worth setting Avast to do a boot time scan.

Also might be worth setting a global rule preventing traffic to or from 85.197.99.143.


 Smiler
« Last Edit: January 23, 2008, 07:36:37 AM by N.T.T.W. » Logged

Post proelia praemia.
Die dulci fruere.
Ragwing
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3199


« Reply #3 on: January 23, 2008, 10:58:06 AM »

This sounds like something really bad. Try doing a boot-time scan, as suggested by N.T.T.W. If it doesn't work, try some other AV's.
If it's still there, return with your results here.

Cheers,
Ragwing
Logged

Forum Policy
FAQ's

If you should need help or have a question, feel free to PM me.
AnotherOne
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 666


« Reply #4 on: January 28, 2008, 01:57:37 AM »

Two points.  First, the fact that you can't find the file by checking the path shown means either the file is stealthed (suggesting a rootkit) or it is extracted to RAM and the path is only a virtual path.  Try a rootkit scan if nothing shows up with AV scans.  I believe that Avira's Antivir had one of the best detection rates of the free AV scanners.

Second, you can try tracking down the source of the file by right-clicking it on the Active Processes window.  There is an option to Terminate and Quarantine the file.  This may cause another file to reveal itself when it tries to check up on the quarantined file.  I've never tried this, but I assume that an alert will pop up when a quarantined file access is attempted.  On that pop-up, you will also have the option to quarantine the new file.  You may have to do this for a few files.  This may not work if the first file is virtual.  It depends on how the presence of the first file is checked up on.
Logged

What do you mean, my shoes are on the wrong feet???  These are the only feet I've got!
Yuriy
Russian board
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1041


WWW
« Reply #5 on: January 28, 2008, 03:00:49 AM »

You may also download DrWeb CureIT scanner, switch off internet connection (best thing is to unplug your modem).
Then boot in safe mode and run CureIT. It is a single executable wich doesn't need to be installed, but it is almost equal to standard DrWeb package capability.
« Last Edit: January 28, 2008, 03:04:06 AM by goodbrazer » Logged

Ubuntu 8.10 (intrepid) x32
Ragwing
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3199


« Reply #6 on: January 28, 2008, 10:44:34 AM »

If it's a rootkit, then RootkitRevealer or IceSword should be good enough.
Logged

Forum Policy
FAQ's

If you should need help or have a question, feel free to PM me.
AnotherOne
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 666


« Reply #7 on: January 28, 2008, 07:06:21 PM »

Rootkit Revealer does not have any removal tools and I am not sure that Ice Sword does either (couldn't get it to work on my system for some reason).  Another highly regarded rootkit tool is Panda Antirootkit:
http://research.pandasecurity.com/archive/New-Panda-Anti_2D00_Rootkit-_2D00_-Version-1.07.aspx
Download from the above page.  It has removal tools and is supposed to be easy to use.  Another simple test for rootkit presence is System Virginity Verifier at www.invisiblethings.org
Logged

What do you mean, my shoes are on the wrong feet???  These are the only feet I've got!
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.263 seconds with 20 queries.
Powered by SMF 1.1.7 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com