Win32.Brontok removal/database on COMODO (using CIS)

Hi guys!
I’ve got infected with particular one, as opera crashes, windows update is not going through (says need to activate- it is!), windows defense keep coming up with infection warning…FF (default browser) comes up with warning of unsafe browsing. Run anti brotok by BitDefender- detects, removes one handle, but still coming back
is there COMODO way to get rid of the ■■■■■■?
thanks!

uh yah its trying to go to http://www.perfectd-review.com/?a=112&b=53544F524D2D5641554C546CF9B0CC&so=01
page! some rouge ar$e of "defense application "
thanks

I would recomend you follow this guide:

Also submit the file that keeps comming back to these 2 links:
http://camas.comodo.com/ and post a link after the analysis has finished.
And submit it hear also:
Comodo Firewall | Get Best Personal Firewall Software for $29.99 A Year

in a bit (running couple of other scans)

Can i ask what other AV/scanner are you using?

Thanks

run few (supreantispyware, spysweeper… latest malware bytes
http://img36.picoodle.com/img/img36/2/6/26/atasas/f_brontokm_f896073.jpg

here’s the warning
http://img36.picoodle.com/img/img36/2/6/26/atasas/f_Securim_036bdf0.jpg

regards submitting… it would become one big file to submit?.. ??? as you can see

Submitted all but shell.dll (server error)

Thx for submition.

I would also recomend you switch CIS to Proactive Security and Set D+ and Firewall to safe mode if you have not done already.

What file keeps comming back?

Oh and that security alert is fake as far as i can tell.

http://camas.comodo.com/cgi-bin/submit?file=51f958bdf8dd03df02fae303e9a9432194cc276178a165363f5ba4e1656d1246
http://camas.comodo.com/cgi-bin/submit?file=0d33a5278f31f427a29d25ae73ad03262b33fd69e31b785545f7e6e648f8bb37
http://camas.comodo.com/cgi-bin/submit?file=7f57dcdcef946d400b923beecac6b9fae58ead8f2f75c8a2d36f8ce1531a202a

yes!
done! (removed with malware bytes)
thanks!
will post after reboot

You could use My blocked Files under D+, select Add, select Browse, and go to the files all the other scanners show and add them to the blocked list, do a restart and that should kill them, but i would recommend that you still follow the guide on what to do if your infected and remove the malware that way.

Done! (gone)
However I believe would be handy to be able to not to get the fake one with COMODO in the future…
thanks for your help!

thanks for the tip!
however detection in a first place…

Indeed it is. Also did you download anything that the security alert told you to?

hmmm most likely… fixes/patches- my everyday life O0

Hmm A security alert should not tell you to download stuff, and some research into this Malware says that its a fake Security alert, and if you click on it, It will give you page to download a fake AV, Personal Anti Virus 2009.

Just wondering if you have downloaded it?

http://img.bleepingcomputer.com/swr-guides/p/perfect-defender-2009/perfect-defender-2009.jpg

ha ha! I didn’t!..
nice one!
I believe some of the new/untested(unheard name/reputation) fixes for PS4 was the guilty one!
Thanks for the help!

Most likely and your lucky you did not download that rouge.

You could upload files you think are malware to this website.

http://virscan.org/ it will scan against 38 anti viruses, i think. This does not mean its a clean file but its a better way to check if there is a virus.

yeah! bit late for that as I’ve remobed it already + the location of the ■■■■■■ wasn’t clear…