Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

Spyware/Virus attack - downloaded from download.com

Jan 1, 2009 8:28PM PST

I've just picked up a spyware/virus through software downloaded via one of the sponsored links on download.com
I searched for rar/zip extractor and one of the sponsored links at the top of the page was to get WinRar 3.8 for free.

I'm always wary of these sponsored or external site links, but I visited the page, everything seemed OK, because the link was something like download.net.cn, so I downloaded the "software" and installed. Everything was fine for about 2 minutes then this pop-up started appearing every minute saying "comanglia comanglia comanglia!!!!" and when
I started up my browser it re-directed to a "Microsoft" page stating I have been attacked by a virus or spyware and that I need to follow a link to install anti-spyware software.

I have Super Anti-Spyware, Avast and Comodo installed. I ran the spyware and virus scanner but couldn't pick up anything. So I downloaded and installed SpyBot (from download.com) and ran that. It
picked up a few things that the others didn't and I had that removed.

Now, about 5 full scans and a couple of reboots later my internet connection is intermitent and I still get that "spyware" warning when I startup my browser. I use Firefox and Explorer, and both come up with the issue. O yes, and the "comanglia" pop-up seems to have dissapeared.

Any help would by highly appreciated.

Discussion is locked

- Collapse -
Thanks for letting us know......
Jan 2, 2009 12:22AM PST

I have forwarded your post.

In the meantime, could you pls.

Please download Malwarebytes Anti-Malwareand save it to your desktop.
alternate download link 1
alternate download link 2

* Make sure you are connected to the Internet.
* Double-click on mbam-setup.exe to install the application.
* When the installation begins, follow the prompts and do not make any changes to default settings.
* When installation has finished, make sure you leave both of these checked:
o Update Malwarebytes' Anti-Malware
o Launch Malwarebytes' Anti-Malware
* Then click Finish.

MBAM will automatically start and you will be asked to update the program before performing a scan.

* If an update is found, the program will automatically update itself.
* Press the OK button to close that box and continue.
* If you encounter any problems while downloading the updates,
manually download them from here
and just double-click on mbam-rules.exe to install.
Alternatively, you can update through MBAM's interface from a clean computer,
copy the definitions (rules.ref) located in
C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes'
Anti-Malware from that system to a usb stick or CD and then copy it to the infected machine.

On the Scanner tab:

* Make sure the "Perform Quick Scan" option is selected.
* Then click on the Scan button.
* If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
* The scan will begin and "Scan in progress" will show at the top.
It may take some time to complete so please be patient.
* When the scan is finished, a message box will say "The scan completed successfully.
Click 'Show Results' to display all objects found".
* Click OK to close the message box and continue with the removal process.

Back at the main Scanner screen:

* Click on the Show Results button to see a list of any malware that was found.
* Make sure that everything is checked, and click Remove Selected.
* When removal is completed, a log report will open in Notepad.
* The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
* Copy and paste the contents of that report in your next reply and exit MBAM.

Note:-- If MBAM encounters a file that is difficult to remove,
you may be asked to reboot your computer so it can proceed with the disinfection process.
Regardless if prompted to restart the computer or not, please do so immediately.
Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

- Collapse -
SAME THING!
Jan 2, 2009 7:51AM PST

i just downloaded winrar and i got teh same virus. i downloaded malwarebytes and ran it but it wont catch it.

- Collapse -
Give SuperantiSpyware a try......
Jan 2, 2009 8:13AM PST

Download and scan with SUPERAntiSpyware Free for Home Users

* Double-click SUPERAntiSpyware.exe and use the default settings for installation.
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
* Under "Configuration and Preferences", click the Preferences button.
* Click the Scanning Control tab.
* Under Scanner Options make sure the following are checked (leave all others unchecked):

Close browsers before scanning.
Scan for tracking cookies.
Terminate memory threats before quarantining.

* Click the "Close" button to leave the control center screen.
* Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
* On the left, make sure you check C:\Fixed Drive.
* On the right, under "Complete Scan", choose Perform Complete Scan.
* Click "Next" to start the scan. Please be patient while it scans your computer.
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
* Make sure everything has a checkmark next to it and click "Next".
* A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
* If asked if you want to reboot, click "Yes".

- Collapse -
AVG
Jan 2, 2009 8:20AM PST

i DL'ed AVG free and it caught it. its something that adds itself to explorer.exe so just let AVG do its thing and it will restart the comp since it has to turn off explorer. when i rebooted its gone.

- Collapse -
(NT) Thanks for the additional info with AVG !
Jan 2, 2009 8:26AM PST
- Collapse -
AVG version
Jan 2, 2009 8:59AM PST

Wich AVG version should I download. I also got the virus by downloading winrar. I have AVAST installed and it ran a complete scan. It seemed to have removed the pop-up about comanglia but I still have the miscrosoft malware message that pops-up once a while in internet exporer. thank you for your help

- Collapse -
still not all clear
Jan 2, 2009 9:05AM PST

i used AVG free.

i to still have yet to figure out the MS security center thing.

everytime i type google.com into the url bar on either firefox or ie. it goes to that page. like a redirect. and i know its a fake page. i think i am just going to format my computer again because this is just a pain in the butt.

- Collapse -
MS security center thing
Jan 2, 2009 10:09AM PST

Do you have MalwareBytesAntiMalware ? If yes, update it and run it.

- Collapse -
system crash.
Jan 2, 2009 10:23AM PST

my system crashed. i had to format it to get it back.... i lost over a 1000 hours of research. i just dont know what to do. i am just lost....all my docs from the last 5 years.... i cant believe this.

- Collapse -
(NT) ... you did not make back-ups from your research?
Jan 2, 2009 10:28AM PST
- Collapse -
do but they are gone
Jan 2, 2009 10:34AM PST

i had them on the extra drive. i had done a format this morning to install vista 64bit. i moved them back over instead of copied. so they are gone now. pretty much i am screwed.

- Collapse -
Ouch......
Jan 2, 2009 10:51AM PST

THAT hurts Sad

Are you sure, you MOVED everything and did NOT copy??

- Collapse -
manual job with HiJackThis should do it
Jan 2, 2009 8:08PM PST

hi,
thanks for everyone's replies and help! really appreciate it.

I seem to have removed the virus out of explorer.exe with Malwarebyte's, but had to remove the webpage/explorer issue with Trend's HiJackThis and it worked. Everything seems ok now.

Below is a part of the log HiJackThis generated of the files I removed, so lookout for something similar or just look at items which look out of place. BE CAREFUL THOUGH and TAKE YOUR TIME by going through the list and ask the software to analyze on what you have selected; it helps a great deal.

Here's the log(the top ones are the sites where my explorer kept on trying to re-direct me to) :

O1 - Hosts: 61.157.217.210 www.antispy.com
O1 - Hosts: 61.157.217.210 www.antispyware.com
O1 - Hosts: 61.157.217.210 antispyware.com
O1 - Hosts: 61.157.217.210 antispy.com
O1 - Hosts: 123.251.143.110 www.asdfasdfd.com
O1 - Hosts: 123.251.143.110 www.gg.com
O1 - Hosts: 123.251.143.110 www.ghfhj.com
O1 - Hosts: 123.251.143.110 www.cvnbcvnb.com
O1 - Hosts: 123.251.143.110 www.1.com
O1 - Hosts: 123.251.143.110 www.3.com
O1 - Hosts: 123.251.143.110 www.asdf4asdfd.com
O1 - Hosts: 123.251.143.110 www.asdfawsdfd.com
O1 - Hosts: 123.251.143.110 www.asdfatsdfd.com
O1 - Hosts: 123.251.143.110 www.asdfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfadsdfd.com
O1 - Hosts: 123.251.143.110 www.asdfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfafsdfd.com
O1 - Hosts: 123.251.143.110 www.asdfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfagsdfd.com
O1 - Hosts: 123.251.143.110 www.asdfasgdfd.com
O1 - Hosts: 123.251.143.110 www.asdfasdhfd.com
O1 - Hosts: 123.251.143.110 www.asdfasdfjd.com
O1 - Hosts: 123.251.143.110 www.asdfasdfkd.com
O1 - Hosts: 123.251.143.110 www.asdfasdfld.com
O1 - Hosts: 123.251.143.110 www.asdfasdf,d.com
O1 - Hosts: 123.251.143.110 www.asxdfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdzfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdcfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfvasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfabsdfd.com
O1 - Hosts: 123.251.143.110 www.asdfasndfd.com
O1 - Hosts: 123.251.143.110 www.asdfasdmfd.com
O1 - Hosts: 123.251.143.110 www.asdfasdfd.com
O1 - Hosts: 123.251.143.110 www.11asdfasdfd.com
O1 - Hosts: 123.251.143.110 www.as222dfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfa33sdfd.com
O1 - Hosts: 123.251.143.110 www.asdfasd44fd.com
O1 - Hosts: 123.251.143.110 www.asdfasdfd5.com
O1 - Hosts: 123.251.143.110 www.as66dfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdf77asdfd.com
O1 - Hosts: 123.251.143.110 www.asdf8asdfd.com
O1 - Hosts: 123.251.143.110 www.asdf9asdfd.com
O1 - Hosts: 123.251.143.110 www.asdf0asdfd.com
O1 - Hosts: 123.251.143.110 www.asdf-asdfd.com
O1 - Hosts: 123.251.143.110 www.aqqsdfasdfd.com
O1 - Hosts: 123.251.143.110 www.aswwdfasdfd.com
O1 - Hosts: 123.16.197.121 www.asdhhfasdfdyy.com
O1 - Hosts: 123.251.143.110 www.asdwwwfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfeasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfrrasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfttasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfyyasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfuuuasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfaiisdfd.com
O1 - Hosts: 123.251.143.110 www.asdfaoosdfd.com
O1 - Hosts: 123.251.143.110 www.asdfappsdfd.com
O1 - Hosts: 123.251.143.110 www.asdfasssdfd.com
O1 - Hosts: 123.251.143.110 www.aswwdfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdeefasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfffasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfavvvsdfd.com
O1 - Hosts: 123.251.143.110 www.asnnndfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdmmmfasdfd.com
O1 - Hosts: 123.251.143.110 www.asdfaffsdfd.com
O1 - Hosts: 123.251.143.110 www.asdhhfasdfd.com

Hope this helps Happy