Welcome, Guest. Please login or register.
November 15, 2009, 02:05:57 AM

Login with username, password and session length

334771 Posts
37021 Topics
83929 Members

Latest Member: zzxop

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Virus/Malware Removal Assistance
| | | |-+  What to do if you're infected - eXPerience Rev.3
« previous next »
Pages: [1] 2 3 Go Down Print
Author Topic: What to do if you're infected - eXPerience Rev.3  (Read 6754 times)
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6410


Why not ? The choice is yours !


« on: June 17, 2009, 02:33:23 PM »

This guide will help you removing malware from your system. Note : This is only a guide and cannot be held responsible for any damage to your system!

(optional : Comodo Back-up)
Superantispyware
Malwarebytes Antimalware
A-squared Free
Hijackthis




1) Back-up all your files and folders using a Comodo Back-up

2) Check for definition Updates (Important!).


3) Allow each program to scan. Scan one at a time.


4) Let the programs clean the infections.

Do not fix anything with A-squared directly, this program is known for it's false positives and might do damage to your system if use wrongly

5) Reboot and see if you find any remains of the virus

6) Download and run Hijackthis. Afterwards, do a system scan and save a log file. A text file will open in notepad, save this one and later upload it together with your post. DO NOT FIX ANYTHING YET !!! .




7) Open a new topic. In that topic, please include :
- The hijackthis log
- the A-squared log
- it might be usefull to report the malware names also

It's important that you make a new topic, this way we can verify that the infection is indeed gone !

Xan
« Last Edit: September 24, 2009, 10:29:44 AM by eXPerience » Logged

OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1367


The only thing i ask for are eggs.


WWW
« Reply #1 on: June 17, 2009, 06:17:51 PM »

Since you made a new Post

I will post what i posted on the other one here:

Is this a new what to do if your infected board? i would say change A-Squared to COMODO since the Family signs are comming with in the next 2 to 3 weeks!

If COMODO adds 5000 Family signatures look at how much it can catch!

# of FS      Max for 1 Sig   Total
5000    *   23542      = 117,710,000     
4000    *   23542      = 94,168,000     
3000    *   23542      = 70,626,000     
2000    *   23542      = 47,084,000   
1000    *   23542      = 23,542,000   
Logged

What you see isn’t what you always get!
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6410


Why not ? The choice is yours !


« Reply #2 on: June 18, 2009, 01:54:13 AM »

I'm expecting the users to have Comodo on their computer Wink. The help with cleaning board is a childboard of CIS so I don't find it usefull adding CIS also Wink

Xan
Logged

OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1367


The only thing i ask for are eggs.


WWW
« Reply #3 on: June 18, 2009, 12:36:07 PM »

Oh ok i get you now! Why not switch A2 for Avira, or is A2 that good?
Logged

What you see isn’t what you always get!
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6410


Why not ? The choice is yours !


« Reply #4 on: June 18, 2009, 02:29:51 PM »

A squared is a great on demand scanner. Avira is good in detecting the installers, but I got my doubts on the cleanup. It also gives adds, and it installs a realtime scanner. (Which was also the reason that I used Bitdefender in the past)

Xan
Logged

OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1367


The only thing i ask for are eggs.


WWW
« Reply #5 on: June 18, 2009, 04:21:42 PM »

What about Avast (i know it has realtime), you may also want to include a svhost identifier so that you can see if any Malware is using it, i dont think hijackthis works for that!
« Last Edit: June 19, 2009, 12:00:41 AM by OmeletGuy » Logged

What you see isn’t what you always get!
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6410


Why not ? The choice is yours !


« Reply #6 on: June 19, 2009, 02:45:41 AM »

Any idea about a userfriendly svhost analyzer that makes some report that I can understand ?
Perhaps that's an overkill ? We should keep this as userfriendly as possible, we can always ask for that svhost files later ?

Xan
Logged

OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1367


The only thing i ask for are eggs.


WWW
« Reply #7 on: June 19, 2009, 11:19:37 AM »

Any idea about a userfriendly svhost analyzer that makes some report that I can understand ?
Perhaps that's an overkill ? We should keep this as userfriendly as possible, we can always ask for that svhost files later ?

Xan

Your right a svhost identifier would be over kill, and i dont know one that is user friendly.

But one thing you should say is set CIS to Proactive Security.
Logged

What you see isn’t what you always get!
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6410


Why not ? The choice is yours !


« Reply #8 on: June 19, 2009, 11:22:40 AM »

Is that part of the cleaning up ?  Roll Eyes

Xan
Logged

OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1367


The only thing i ask for are eggs.


WWW
« Reply #9 on: June 19, 2009, 11:28:28 AM »

No but i should help to detect keyloggers and other spy malware, that the other AV and maybe CAV's missed

Then again Hijackthis should pick it up right?
Logged

What you see isn’t what you always get!
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6410


Why not ? The choice is yours !


« Reply #10 on: June 19, 2009, 11:29:18 AM »

I was thinking the same Wink. So it's ready to go public ?

Xan
Logged

pnowak
Newbie
*
Offline Offline

Posts: 1


« Reply #11 on: July 06, 2009, 04:56:52 PM »

Xan, I miss one important info:
"6) Reboot into normal mode ..."   - does it mean the previous steps should be done in safe mode Huh
Logged
adric
"Start every day with a smile and get it over with."
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 639


"I am not young enough to know everything. "


« Reply #12 on: July 10, 2009, 04:31:14 AM »

Any idea about a userfriendly svhost analyzer that makes some report that I can understand ?
Perhaps that's an overkill ? We should keep this as userfriendly as possible, we can always ask for that svhost files later ?

Xan

http://www.codeplex.com/svchostviewer

Al
Logged
Jose_Lisbon
Comodo's Hero
*****
Offline Offline

Posts: 425



« Reply #13 on: July 16, 2009, 10:10:18 AM »

It is always a good idea to use GMER after all the other scans.
It makes sure that you have/have not rootkits.
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6410


Why not ? The choice is yours !


« Reply #14 on: July 27, 2009, 08:43:51 AM »

Xan, I miss one important info:
"6) Reboot into normal mode ..."   - does it mean the previous steps should be done in safe mode Huh
Oh yeah, that was part of the oldest version of it... Doesn't matter, I deleted it now, thanks for the info ! Wink

Using GMER after all these scanners and hijackthis ? isn't that a bit an overkill ?

Xan
Logged

Tags:
Pages: [1] 2 3 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.039 seconds with 19 queries.
Powered by SMF 1.1.10 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com