Register
Pointless Waste of Time
Search forums | Inbox | Profile | Signature
+  Cracked.com Forums - Pointless Waste of Time
|-+  Gamers' Quarantine
| |-+  Computer Help
| | |-+  Comanglia Virus Problems
0 Members and 1 Guest are viewing this topic.
Pages: [1] 2 Print
Author Topic: Comanglia Virus Problems  (Read 5593 times)
camilikins
Purveyor of Dick Jokes

Karma: 42
Offline Offline



View Profile
« on: December 27, 2008, 10:47 PM »

Yesterday my boyfriend was downloading WinRAR to open some zip files and discovered that the version he downloaded had something called Comanglia Virus attached. Basically a popup saying 'Comanglia' kept popping up in a pop-up box which kept reappearing when you hit OK. Popup. We have two computers, so it's not too big of an issue, but I need to get rid of it.

I've since discovered that it's a Trojan. Unfortunately the computer often turns itself off spontaneously after 15-20 minutes (unrealted issues, I'm fairly sure) so Norton and AVG can't run long enough to clear it. Does anyone know a definitive way (even if it takes longer than 20 mins) to clean up this virus?

Cheers in advance.
Logged

Heck is for people who don't believe in Gosh.
Remington
PWoT Moderator

Karma: 1483
Offline Offline


Big Jerk

TERRIBLE!
View Profile
« Reply #1 on: December 28, 2008, 02:23 PM »

Press CTRL-SHIFT-ESC to bring up the task manager.  Click on Processes and end any process that says "explore.exe" (NOT explorer.exe).

Start -> Search -> "explore.exe" (again NOT explorer.exe)

Delete any copies of explore.exe found on your computer. (If you searched without quotations you might find copies of iexplore.exe alongside explore.exe--either search with the quotation marks or be sure not to delete the iexplore.exe files)

After you've deleted the files...

Start -> Run -> C:\WINDOWS\system32\drivers\etc  (or navigate that file path through My Computer)

Right click on the "Hosts" file and Open With -> Notepad.  You may need to just click open and select notepad from the list.

You should see a line that says

127.0.0.1  localhost

If there is anything below that line, remove it and save (CTRL-S) the file.

If this doesn't solve the problem, let me know and I'll do a little more research.
Logged

It's the Great PWOT Superhero Rumble!
The Hollywood Treatment, where I give movies the Hollywood endings they deserve.  Updated 11/07!
camilikins
Purveyor of Dick Jokes

Karma: 42
Offline Offline



View Profile
« Reply #2 on: December 29, 2008, 02:18 AM »

Awesome, thanks so much! Karma coming your way.

As far as I can tell it's been removed. I've also uninstalled WinRAR so hopefully no more problems will ensue. Thanks again for your trouble!
Logged

Heck is for people who don't believe in Gosh.
Remington
PWoT Moderator

Karma: 1483
Offline Offline


Big Jerk

TERRIBLE!
View Profile
« Reply #3 on: December 29, 2008, 04:20 AM »

No problem.  If you're looking for a good alternative to WinZip/RAR, I recommend 7-Zip.
Logged

It's the Great PWOT Superhero Rumble!
The Hollywood Treatment, where I give movies the Hollywood endings they deserve.  Updated 11/07!
mattg2
Relatively new

Karma: 0
Offline Offline



View Profile
« Reply #4 on: December 29, 2008, 04:51 PM »

I've just had the same problem with this but this isn't solving it I'm afraid.

explore.exe isn't in processes, thankfully. The messages have stopped now too but everything still isn't right.

In my hosts file there is only 1 line:

123.251.143.110   www.asdfasdf,d.com

When I try and delete it or replace it with the localshosts line it won't let me do that

I now also have CoolWWWSearch.smartsearch hijacker software showing up in Spybot and I can't delete it.

I can't even open avast to run a scan either.

Man, this is annoying!
Logged
Remington
PWoT Moderator

Karma: 1483
Offline Offline


Big Jerk

TERRIBLE!
View Profile
« Reply #5 on: December 29, 2008, 05:24 PM »

Try running CWShredder to get rid of CoolWebSearch.

When you say it won't let you remove the line in the hosts file, what do you mean?  You can't delete it or it won't let you save it or what?
Logged

It's the Great PWOT Superhero Rumble!
The Hollywood Treatment, where I give movies the Hollywood endings they deserve.  Updated 11/07!
mattg2
Relatively new

Karma: 0
Offline Offline



View Profile
« Reply #6 on: December 29, 2008, 05:40 PM »

Hi Remington,

Thanks for the reply - I'll give CWShredder a go, although looking at the Spybot forums it may just be a reporting error problem or something - there are lots of CoolwebSearch variables and not all of them are picked up straight away by name by Spybot.

Anyway, about the hosts file - I can't save the changes. I've since discovered that in Vista (I have Vista) I need to change the permissions settings so in Notepad so I can use it as an administrator. If you don't do this you can't edit anything. This is done by going to Start > All Programs > Accessories > Notepad, right click > Run as adminstrator.

I have tried this but it still won't save. I still need to play with this but I think this is the right way to go.

At the moment I'm just running loads of scans to uncover any lurking nasties on my machine. I'll then probably restart it and try and edit the hosts file again.

Do you know what  I need in my hosts file? Is the following line enough by itself, or will I need anything else?

127.0.0.1  localhost

Thanks again for your reply and your help.
Logged
mattg2
Relatively new

Karma: 0
Offline Offline



View Profile
« Reply #7 on: December 29, 2008, 06:40 PM »

All sorted now - phew!

For future reference if anyone else with the same problem stumbles across this thread here's what worked for me:

CWShredder found that CoolWebSearch.SmartSearch was indeed still on my machine but I actually deleted it after running a detailed scan with:

http://www.malwarebytes.org/mbam.php     (Just the free initial download)

Scan took well over an hour. It also found another nasty lingering there that the others missed.


I then replaced the infected hosts file with a template from here:

http://vlaurie.com/computers2/Articles/hosts.htm


I used the method I mentioned in my last post to open a blank notepad file with admin permissions, copied the template hosts file into it, then 'Save As' the host file into the /etc folder, replacing the infected file. I had been trying to directly edit the infected file but this isn't possible.

Thanks again for your help Remington.

Matt

Logged
toolman59
My first post!

Karma: 0
Offline Offline



View Profile
« Reply #8 on: January 02, 2009, 02:59 AM »

Remington

I followed your instructions to remove explore.exe and got rid of the annoying pop up.
Today I installed Widows Defender, after the first scan the Software Explorer tool in defender came up with the following entry in the start up category, it was listed as "N/A".

File Name: explore.exe
Start up Value: G:\WINDOWS\system32\explore.exe
File Path: G:\WINDOWS\system32\explore.exe
Start up Type: Registry: Local Machine
Location: Software\Microsoft\Windows\CurrentVersion\Run
Classification: Disabled
SpyNet Voting: Not Available

I selected disable in defender which removed it from "run" in the  registry.
I can not find an entry for it in G:\WINDOWS\system32, is it still hidden somewhere on the system?

toolman59
Logged
Remington
PWoT Moderator

Karma: 1483
Offline Offline


Big Jerk

TERRIBLE!
View Profile
« Reply #9 on: January 02, 2009, 03:29 AM »

If you got rid of the actual file itself, it looks like what you did with Windows Defender was remove the registry value that was pointing to it, so you should be alright.
Logged

It's the Great PWOT Superhero Rumble!
The Hollywood Treatment, where I give movies the Hollywood endings they deserve.  Updated 11/07!
butts2bombs
Relatively new

Karma: 0
Offline Offline



View Profile
« Reply #10 on: January 02, 2009, 11:55 PM »

soooo
i did everythin u did and i got rid of the comanglia pop-up  :D

but i cant find the 127.0.0.1 local host in the hosts file

ive typed it in and saved it but it hasnt changed anything

wat must i do ????
Logged
Remington
PWoT Moderator

Karma: 1483
Offline Offline


Big Jerk

TERRIBLE!
View Profile
« Reply #11 on: January 03, 2009, 04:16 AM »

Try doing what mattg2 did above, especially if you have Vista.
Logged

It's the Great PWOT Superhero Rumble!
The Hollywood Treatment, where I give movies the Hollywood endings they deserve.  Updated 11/07!
siwelmail
Relatively new

Karma: 0
Offline Offline



View Profile
« Reply #12 on: January 03, 2009, 12:52 PM »

can you help me?

I'm on XP and i did this:
Press CTRL-ALT-DEL to bring up the task manager.  Click on Processes and end any process that says "explore.exe" (NOT explorer.exe).

Start -> Search -> "explore.exe" (again NOT explorer.exe)

Delete any copies of explore.exe found on your computer. (If you searched without quotations you might find copies of iexplore.exe alongside explore.exe--either search with the quotation marks or be sure not to delete the iexplore.exe files)
Logged
siwelmail
Relatively new

Karma: 0
Offline Offline



View Profile
« Reply #13 on: January 03, 2009, 12:54 PM »

sorry for double posting.

then i tryed to do this:


After you've deleted the files...

Start -> Run -> C:\WINDOWS\system32\drivers\etc  (or navigate that file path through My Computer)

Right click on the "Hosts" file and Open With -> Notepad.  You may need to just click open and select notepad from the list.

You should see a line that says

127.0.0.1  localhost

If there is anything below that line, remove it and save (CTRL-S) the file.

but i didnt see anything to do with that all i see is ## Copyright (c) 1993-2001 Microsoft Corp.
#
# This file has been automatically generated for use by Microsoft Internet
# Connection Sharing. It contains the mappings of IP addresses to host names
# for the home network. Please do not make changes to the HOSTS.ICS file.
# Any changes may result in a loss of connectivity between machines on the
# local network.
#

#192.168.0.1 acer-3f31164f8b.mshome.net # 2013 5 2 7 19 2 43 78
Logged
butts2bombs
Relatively new

Karma: 0
Offline Offline



View Profile
« Reply #14 on: January 05, 2009, 07:16 PM »

k

i tryed to set the notepad to run as administrator?

but it still hasnt changed?

i think im the administrator?

btw im runnin XP so im guessing thts why it didnt work

is there anything else i can do ???

plzz help :D
Logged
Remington
PWoT Moderator

Karma: 1483
Offline Offline


Big Jerk

TERRIBLE!
View Profile
« Reply #15 on: January 05, 2009, 11:41 PM »

If you can't edit the file directly, try renaming it to something (like hostdelete, hostremove).  Once you've done this, create a new text document in the \etc\ folder (right click -> new -> text document).  Call it "hosts", with no extension.

Right click and open the new hosts file you created (using notepad), and paste this single line into this new document:

127.0.0.1       localhost

Save the file with CTRL-S.  Delete the file you renamed.
Logged

It's the Great PWOT Superhero Rumble!
The Hollywood Treatment, where I give movies the Hollywood endings they deserve.  Updated 11/07!
buffybaskey
My first post!

Karma: 0
Offline Offline



View Profile
« Reply #16 on: January 12, 2009, 12:13 PM »

hello, i have joined ust to say thank you to everyone who has posted on this topic, i followed the instructions and used the malware and have now solved the problem, thanks again guys very much appreicated xxx
Logged
RayW
Relatively new

Karma: 0
Offline Offline



View Profile
« Reply #17 on: January 18, 2009, 07:39 PM »

I am using vist 64 but and seem to have got rid of the popup, but I can still not get on to youtube, google as it keeps directing me to the "microsoft site" can anyone help

Logged
Remington
PWoT Moderator

Karma: 1483
Offline Offline


Big Jerk

TERRIBLE!
View Profile
« Reply #18 on: January 18, 2009, 07:45 PM »

That's probably your hosts file.  It's telling your browser to go to their IP address for those sites rather than the actual IP address of the site.

Follow the instructions in this thread to revert your hosts file to its default (you may need to make a blank hosts file, rename the old one and then rename the new one, or run notepad as an administrator to edit the existing hosts file).
« Last Edit: January 18, 2009, 10:52 PM by Remington » Logged

It's the Great PWOT Superhero Rumble!
The Hollywood Treatment, where I give movies the Hollywood endings they deserve.  Updated 11/07!
RayW
Relatively new

Karma: 0
Offline Offline



View Profile
« Reply #19 on: January 18, 2009, 07:52 PM »

I have completely deleted the HOSTS files that I can find...and still they same thing
Logged
Pages: [1] 2 Print 
Jump to:  
Powered by MySQL Powered by PHP Powered by SMF 2.0 RC1.2 | SMF © 2006–2009, Simple Machines LLC Powered by SMF 1.1.8 | SMF © 2006, Simple Machines LLC Valid XHTML 1.0! Valid CSS!
Powered by SMF 2.0 RC1.2 | SMF © 2006–2009, Simple Machines LLC