ComputerForum.com ComputerForum.com  

Go Back   Computer Forum > Computer Software > Computer Security

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
Old 10-26-2009, 12:52 PM   #1 (permalink)
Diamond Member
 
patrickv's Avatar
 
Join Date: Jul 2006
Location: I wonder !!!
Posts: 6,299
Angry Coodoosoft

As per the title guys. I really need some help on this.
is there a definite way to remove this crap ?
Even though I disable it at startup and I would also remove its entry, it would appear again. However there's no process called herss.exe like google said.
The only way for me to know the thing is running i have to go to the user's temp directory and looks for cvas0.dll or similar or i'll end up with this



This is what happens when printing back to back on the printer. It crashes when the virus is active. I can go to temp, delete herss.exe and remove the dll, try printing and it will work.

Are there any good ways to permanently remove it ?

many thanks
__________________
My Blog

My FlickR
patrickv is offline   Reply With Quote


Old 10-26-2009, 12:54 PM   #2 (permalink)
Diamond Member
 
patrickv's Avatar
 
Join Date: Jul 2006
Location: I wonder !!!
Posts: 6,299
Default

ah sorry it's Cdoosoft !! lol
__________________
My Blog

My FlickR
patrickv is offline   Reply With Quote
Old 10-26-2009, 01:36 PM   #3 (permalink)
Diamond Member
 
linkin93's Avatar
 
Join Date: Jun 2009
Location: NSW, Australia
Age: 16
Posts: 2,330
Default

get malwarebytes and hijack this... run them both in safemode after updating (best way is to go safemode with networking)

could you give a list of your processes when the virus is active?
__________________
System
CM Storm Scout - Asus P5N-E SLI - Core 2 Duo E4500 @ 3.02Ghz - 2x1GB Corsair XMS2 @ 900mhz - Sapphire HD 3870 - WD 250GB Caviar SE16 - SHAW 860W - Windows 7 Ultimate x64

Perhiprials
Logitech G5 Mouse - Logitech R-10 Speakers - Targus Keyboard - HP L1470 17" 1280x1024 Monitor
linkin93 is offline   Reply With Quote
Old 10-26-2009, 01:50 PM   #4 (permalink)
Diamond Member
 
patrickv's Avatar
 
Join Date: Jul 2006
Location: I wonder !!!
Posts: 6,299
Default

Quote:
Originally Posted by linkin93 View Post
get malwarebytes and hijack this... run them both in safemode after updating (best way is to go safemode with networking)

could you give a list of your processes when the virus is active?
Malwarebytes doesn't help in this case, tried and tested. I even updated it.Not even hijack this.
I downloaded Spybot S&D and so far it has removed the infection, I have also rebooted a couple of times. So far so good. Will see how long this last
__________________
My Blog

My FlickR
patrickv is offline   Reply With Quote
Old 10-26-2009, 02:22 PM   #5 (permalink)
Diamond Member
 
linkin93's Avatar
 
Join Date: Jun 2009
Location: NSW, Australia
Age: 16
Posts: 2,330
Default

perhaps try googling for the specific infection and then removal... usually works... some people are kind enough to create guides to remove a specific infection.
__________________
System
CM Storm Scout - Asus P5N-E SLI - Core 2 Duo E4500 @ 3.02Ghz - 2x1GB Corsair XMS2 @ 900mhz - Sapphire HD 3870 - WD 250GB Caviar SE16 - SHAW 860W - Windows 7 Ultimate x64

Perhiprials
Logitech G5 Mouse - Logitech R-10 Speakers - Targus Keyboard - HP L1470 17" 1280x1024 Monitor
linkin93 is offline   Reply With Quote


Old 10-26-2009, 04:55 PM   #6 (permalink)
Diamond Member
 
patrickv's Avatar
 
Join Date: Jul 2006
Location: I wonder !!!
Posts: 6,299
Thumbs up

Quote:
Originally Posted by linkin93 View Post
perhaps try googling for the specific infection and then removal... usually works... some people are kind enough to create guides to remove a specific infection.
Yup, Thanks.
I once was on a blog somewhere and it lead me to StopZilla. I downloaded the program and I have to admit.. It sucks major
__________________
My Blog

My FlickR
patrickv is offline   Reply With Quote
Old 10-26-2009, 09:37 PM   #7 (permalink)
Diamond Member
 
Respital's Avatar
 
Join Date: Aug 2007
Location: Canada
Age: 15
Posts: 2,646
Default

Hello:

Download and Run ComboFix
If you already have Combofix, please delete this copy and download it again as it's being updated regularly.Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply i will need:
  • The ComboFix log
  • A fresh HiJackThis log
  • An update on how your computer is running
__________________
Winner of Photo Tourney: Twilight
/My Rig:/
/Case :/ Antec Sonata III
/Power Supply :/ Antec Earthquake 500W
/Motherboard :/ Gigabyte P35-DSR3
/Processor :/ Intel E6850@3.4Ghz
/Ram :/ Consair 2x 1 Gb 800mhz
/Video Card :/ Zotac 8800 GT
/Monitor:/Samsung T220 w 20 000 : 1 Contrast and 2ms response time
/3DMark06 Score :/ 11730
Respital is offline   Reply With Quote
Reply

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 11:22 PM.


Powered by: vBulletin Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0 ©2009, Crawlability, Inc.