Antivirus Detection

Hello, I am using CIS on mine Laptop thats running on Vista 64 bits and i had a lot of crashes and some processes i couldn t place, i have running the antivirus and it found nothing at all.

Still i am wondering why the laptop was slow i thought maybe the last updates of Microsoft was the reason but no that would be the first time.

I have scanned the system with PCTools antivirus combined with their antispyware and it reports an total of 105 infections yes 105 infections detected was a couple of mail worms in mails still closed and it found an netsky variant. i was completely unable to send it to comodo for analysis eveything i was trying todo i get exceptions errors or an buffer overflow etc.

I have completely reinstalled windows vista and i have installed the CIS and it is fully updated i have also installed malwarebytes for extra safety against spyware.

I was wondering why the detection have failed and comodo claims that no spyware can harm the system so i am in doubt about the antivirus can someone explained what is happen with the detection why it failed.

here an update from flyingtux i have running now on this moment an critical scan and it found again 28 threaths so i am wondering what now is happening and what is detected or it is false or it is true ???

Comodo has done the scan and detected is an Rootkit.HiddenFile@0 and is removed to the quarantaine what should i do send it to Comodo or just delete.

Can you show the report of the scan? That makes it easier to analyse what is going on.

Hello thanks for your reply i have attached the logfile of CAV please see the detection info, after removing this it cost me 15 minutes to start Windows Vista again.

COMODO Internet Security Premium - Log Beheer Logs

Tabel

:

Antivirus regels

Datum aangemaakt

:

2011-04-15 19:10:14

Regels geteld

:

56
Datum Locatie Malware Naam Actie Status
2011-04-15 16:43:26 c:\Users\Jeroen\AppData\Local\Temp{AFF43DD9-1ACE-4F76-9A67-F5926D46E41F}{AFF43DD9-1ACE-4F76-9A67-F5926D46E41F}-2.eula Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:26 c:\Users\Jeroen\AppData\Local\Temp{AFF43DD9-1ACE-4F76-9A67-F5926D46E41F}{AB9D0312-0C96-4f03-AA6F-5C303D61C2CF}.rtf Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:26 c:\Users\Jeroen\AppData\Local\Temp{AFF43DD9-1ACE-4F76-9A67-F5926D46E41F}{AB9D0312-0C96-4f03-AA6F-5C303D61C2CF}.ico Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:27 c:\Users\Jeroen\AppData\Local\Temp{AFF43DD9-1ACE-4F76-9A67-F5926D46E41F}{D5271C82-7195-46cc-9746-21799EE5CDED}.rtf Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:27 c:\Users\Jeroen\AppData\Local\Temp{AFF43DD9-1ACE-4F76-9A67-F5926D46E41F}{D5271C82-7195-46cc-9746-21799EE5CDED}.ico Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:27 c:\Users\Jeroen\AppData\Local\Temp{AFF43DD9-1ACE-4F76-9A67-F5926D46E41F}{AFF43DD9-1ACE-4F76-9A67-F5926D46E41F}-2.install Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:28 c:\Users\Jeroen\AppData\Local\Temp{C3D6F8BC-0B1F-4ED6-BC1B-3F411B1CE48C}{C3D6F8BC-0B1F-4ED6-BC1B-3F411B1CE48C}-2.install Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:28 c:\Users\Jeroen\AppData\Local\Temp{C3D6F8BC-0B1F-4ED6-BC1B-3F411B1CE48C}{AB9D0312-0C96-4f03-AA6F-5C303D61C2CF}.rtf Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:28 c:\Users\Jeroen\AppData\Local\Temp{C3D6F8BC-0B1F-4ED6-BC1B-3F411B1CE48C}{AB9D0312-0C96-4f03-AA6F-5C303D61C2CF}.ico Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:29 c:\Users\Jeroen\AppData\Local\Temp{C3D6F8BC-0B1F-4ED6-BC1B-3F411B1CE48C}{C3D6F8BC-0B1F-4ED6-BC1B-3F411B1CE48C}-2.eula Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:29 c:\Users\Jeroen\AppData\Local\Temp{C3D6F8BC-0B1F-4ED6-BC1B-3F411B1CE48C}{D5271C82-7195-46cc-9746-21799EE5CDED}.rtf Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:29 c:\Users\Jeroen\AppData\Local\Temp{C3D6F8BC-0B1F-4ED6-BC1B-3F411B1CE48C}{D5271C82-7195-46cc-9746-21799EE5CDED}.ico Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:29 c:\Users\Jeroen\AppData\Local\Temp{C3D6F8BC-0B1F-4ED6-BC1B-3F411B1CE48C}{F5C6357E-5498-45ce-A170-3404485AB064}.rtf Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:29 c:\Users\Jeroen\AppData\Local\Temp{C3D6F8BC-0B1F-4ED6-BC1B-3F411B1CE48C}{F5C6357E-5498-45ce-A170-3404485AB064}.ico Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:31 c:\Users\Jeroen\AppData\Local\Temp{CB39F05D-99CE-49AD-8937-F60D8A18603B}{CB39F05D-99CE-49AD-8937-F60D8A18603B}-2.install Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:31 c:\Users\Jeroen\AppData\Local\Temp{CB39F05D-99CE-49AD-8937-F60D8A18603B}{D5271C82-7195-46cc-9746-21799EE5CDED}.rtf Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:31 c:\Users\Jeroen\AppData\Local\Temp{CB39F05D-99CE-49AD-8937-F60D8A18603B}{D5271C82-7195-46cc-9746-21799EE5CDED}.ico Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:31 c:\Users\Jeroen\AppData\Local\Temp{CB39F05D-99CE-49AD-8937-F60D8A18603B}{F5C6357E-5498-45ce-A170-3404485AB064}.rtf Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:32 c:\Users\Jeroen\AppData\Local\Temp{CB39F05D-99CE-49AD-8937-F60D8A18603B}{F5C6357E-5498-45ce-A170-3404485AB064}.ico Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:32 c:\Users\Jeroen\AppData\Local\Temp{CB39F05D-99CE-49AD-8937-F60D8A18603B}{CB39F05D-99CE-49AD-8937-F60D8A18603B}-2.eula Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:34 c:\Users\Jeroen\AppData\Local\Temp{8470032E-6F3D-4B71-982A-799D0459FCF3}{AB9D0312-0C96-4f03-AA6F-5C303D61C2CF}.rtf Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:34 c:\Users\Jeroen\AppData\Local\Temp{8470032E-6F3D-4B71-982A-799D0459FCF3}{AB9D0312-0C96-4f03-AA6F-5C303D61C2CF}.ico Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:34 c:\Users\Jeroen\AppData\Local\Temp{8470032E-6F3D-4B71-982A-799D0459FCF3}{D5271C82-7195-46cc-9746-21799EE5CDED}.rtf Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:34 c:\Users\Jeroen\AppData\Local\Temp{8470032E-6F3D-4B71-982A-799D0459FCF3}{D5271C82-7195-46cc-9746-21799EE5CDED}.ico Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:34 c:\Users\Jeroen\AppData\Local\Temp{8470032E-6F3D-4B71-982A-799D0459FCF3}{8470032E-6F3D-4B71-982A-799D0459FCF3}-2.install Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:35 c:\Users\Jeroen\AppData\Local\Temp{8470032E-6F3D-4B71-982A-799D0459FCF3}{8470032E-6F3D-4B71-982A-799D0459FCF3}-2.eula Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:35 c:\Users\Jeroen\AppData\Local\Temp{8470032E-6F3D-4B71-982A-799D0459FCF3}{F5C6357E-5498-45ce-A170-3404485AB064}.rtf Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 16:43:35 c:\Users\Jeroen\AppData\Local\Temp{8470032E-6F3D-4B71-982A-799D0459FCF3}{F5C6357E-5498-45ce-A170-3404485AB064}.ico Rootkit.HiddenFile@0 Detecteer Succes
2011-04-15 17:10:59 c:\Users\Jeroen\AppData\Local\Temp{AFF43DD9-1ACE-4F76-9A67-F5926D46E41F}{AFF43DD9-1ACE-4F76-9A67-F5926D46E41F}-2.eula Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:00 c:\Users\Jeroen\AppData\Local\Temp{AFF43DD9-1ACE-4F76-9A67-F5926D46E41F}{AB9D0312-0C96-4f03-AA6F-5C303D61C2CF}.rtf Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:00 c:\Users\Jeroen\AppData\Local\Temp{AFF43DD9-1ACE-4F76-9A67-F5926D46E41F}{AB9D0312-0C96-4f03-AA6F-5C303D61C2CF}.ico Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:00 c:\Users\Jeroen\AppData\Local\Temp{AFF43DD9-1ACE-4F76-9A67-F5926D46E41F}{AFF43DD9-1ACE-4F76-9A67-F5926D46E41F}-2.install Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:01 c:\Users\Jeroen\AppData\Local\Temp{C3D6F8BC-0B1F-4ED6-BC1B-3F411B1CE48C}{AB9D0312-0C96-4f03-AA6F-5C303D61C2CF}.ico Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:01 c:\Users\Jeroen\AppData\Local\Temp{C3D6F8BC-0B1F-4ED6-BC1B-3F411B1CE48C}{D5271C82-7195-46cc-9746-21799EE5CDED}.ico Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:02 c:\Users\Jeroen\AppData\Local\Temp{C3D6F8BC-0B1F-4ED6-BC1B-3F411B1CE48C}{C3D6F8BC-0B1F-4ED6-BC1B-3F411B1CE48C}-2.eula Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:02 c:\Users\Jeroen\AppData\Local\Temp{C3D6F8BC-0B1F-4ED6-BC1B-3F411B1CE48C}{D5271C82-7195-46cc-9746-21799EE5CDED}.rtf Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:02 c:\Users\Jeroen\AppData\Local\Temp{C3D6F8BC-0B1F-4ED6-BC1B-3F411B1CE48C}{F5C6357E-5498-45ce-A170-3404485AB064}.ico Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:02 c:\Users\Jeroen\AppData\Local\Temp{C3D6F8BC-0B1F-4ED6-BC1B-3F411B1CE48C}{C3D6F8BC-0B1F-4ED6-BC1B-3F411B1CE48C}-2.install Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:02 c:\Users\Jeroen\AppData\Local\Temp{C3D6F8BC-0B1F-4ED6-BC1B-3F411B1CE48C}{F5C6357E-5498-45ce-A170-3404485AB064}.rtf Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:03 c:\Users\Jeroen\AppData\Local\Temp{CB39F05D-99CE-49AD-8937-F60D8A18603B}{D5271C82-7195-46cc-9746-21799EE5CDED}.rtf Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:03 c:\Users\Jeroen\AppData\Local\Temp{AFF43DD9-1ACE-4F76-9A67-F5926D46E41F}{D5271C82-7195-46cc-9746-21799EE5CDED}.ico Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:03 c:\Users\Jeroen\AppData\Local\Temp{CB39F05D-99CE-49AD-8937-F60D8A18603B}{CB39F05D-99CE-49AD-8937-F60D8A18603B}-2.install Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:03 c:\Users\Jeroen\AppData\Local\Temp{C3D6F8BC-0B1F-4ED6-BC1B-3F411B1CE48C}{AB9D0312-0C96-4f03-AA6F-5C303D61C2CF}.rtf Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:03 c:\Users\Jeroen\AppData\Local\Temp{CB39F05D-99CE-49AD-8937-F60D8A18603B}{CB39F05D-99CE-49AD-8937-F60D8A18603B}-2.eula Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:04 c:\Users\Jeroen\AppData\Local\Temp{8470032E-6F3D-4B71-982A-799D0459FCF3}{AB9D0312-0C96-4f03-AA6F-5C303D61C2CF}.rtf Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:04 c:\Users\Jeroen\AppData\Local\Temp{8470032E-6F3D-4B71-982A-799D0459FCF3}{D5271C82-7195-46cc-9746-21799EE5CDED}.rtf Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:04 c:\Users\Jeroen\AppData\Local\Temp{CB39F05D-99CE-49AD-8937-F60D8A18603B}{D5271C82-7195-46cc-9746-21799EE5CDED}.ico Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:04 c:\Users\Jeroen\AppData\Local\Temp{CB39F05D-99CE-49AD-8937-F60D8A18603B}{F5C6357E-5498-45ce-A170-3404485AB064}.rtf Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:04 c:\Users\Jeroen\AppData\Local\Temp{CB39F05D-99CE-49AD-8937-F60D8A18603B}{F5C6357E-5498-45ce-A170-3404485AB064}.ico Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:05 c:\Users\Jeroen\AppData\Local\Temp{8470032E-6F3D-4B71-982A-799D0459FCF3}{AB9D0312-0C96-4f03-AA6F-5C303D61C2CF}.ico Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:05 c:\Users\Jeroen\AppData\Local\Temp{8470032E-6F3D-4B71-982A-799D0459FCF3}{F5C6357E-5498-45ce-A170-3404485AB064}.rtf Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:06 c:\Users\Jeroen\AppData\Local\Temp{8470032E-6F3D-4B71-982A-799D0459FCF3}{F5C6357E-5498-45ce-A170-3404485AB064}.ico Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:06 c:\Users\Jeroen\AppData\Local\Temp{AFF43DD9-1ACE-4F76-9A67-F5926D46E41F}{D5271C82-7195-46cc-9746-21799EE5CDED}.rtf Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:06 c:\Users\Jeroen\AppData\Local\Temp{8470032E-6F3D-4B71-982A-799D0459FCF3}{8470032E-6F3D-4B71-982A-799D0459FCF3}-2.eula Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:06 c:\Users\Jeroen\AppData\Local\Temp{8470032E-6F3D-4B71-982A-799D0459FCF3}{8470032E-6F3D-4B71-982A-799D0459FCF3}-2.install Rootkit.HiddenFile@0 Quarantaine Succes
2011-04-15 17:11:06 c:\Users\Jeroen\AppData\Local\Temp{8470032E-6F3D-4B71-982A-799D0459FCF3}{D5271C82-7195-46cc-9746-21799EE5CDED}.ico Rootkit.HiddenFile@0 Quarantaine Succes
Einde rapport

[attachment deleted by admin]

easy to get rid of them. download CCleaner and go to settings ant uncheck the 24 hour temp file. run a cleaning scan. and all of them is gone. ;D

The log says the files were quarantined. Did they get quarantined while the computer was booting or during the regular Windows session?

When you reboot the computer does it still 15 minutes to boot?

!ot! Welkom op de Comodo Forums mede Nederlander.

Thanks for your help, i have done an full system scan and comodo have everything removed to quarantaine the files are also send to comdo by the antiivirus an good action.

After removing the garbage yes it tooks 14 minutes that the computer was rebooted and booted i must waiting at least 12 inutes before the welcome screen was gone, i have done an new system scan and comodo told me everything is clear.

I have also running comodo cleaner and ccleaner and have unmarked the option you told me so i hope comodo do the rest have you any idea how to block icmp and igmp with comodo. Problem has been resolved. :-TU

Please make a separate topic in the Firewall Help board with your questions about blocking ICMP and IGMP messages. That way your question is more visible for other users and may help others.