go.google nightmare pls help. Thanks

Thread Solved

Join Date: Sep 2008
Posts: 37
Reputation: skiesaregrey is an unknown quantity at this point 
Solved Threads: 0
skiesaregrey skiesaregrey is offline Offline
Light Poster

Re: go.google nightmare pls help. Thanks

 
0
  #41
Sep 30th, 2008
This infected one... and guess what, im on eset doing an online scan!
Ill send that log asap, really want to keep it on this side of the fence! Any other software that I should run?
Reply With Quote Quick reply to this message  
Join Date: Sep 2008
Posts: 37
Reputation: skiesaregrey is an unknown quantity at this point 
Solved Threads: 0
skiesaregrey skiesaregrey is offline Offline
Light Poster

Re: go.google nightmare pls help. Thanks

 
0
  #42
Sep 30th, 2008
Resutls from ESET ONLINE SCAN

# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3483 (20080930)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=5348aad771303c429863e7938ba0c76e
# end=finished
# remove_checked=false
# unwanted_checked=true
# utc_time=2008-09-30 04:28:07
# local_time=2008-09-30 05:28:07 (+0000, GMT Standard Time)
# country="United Kingdom"
# osver=5.1.2600 NT Service Pack 3
# scanned=319712
# found=7
# scan_time=2354
C:\QooBox\Quarantine\C\WINDOWS\system32\tdssadw.dll.vir Win32/Agent.ODG trojan 151046484AEF8DE49A459F2340F09190
C:\QooBox\Quarantine\C\WINDOWS\system32\tdssl.dll.vir Win32/Agent.ODG trojan D14A2ACE850393CA9446DA3BB9CFBF0B
C:\QooBox\Quarantine\C\WINDOWS\system32\tdsslog.dll.vir Win32/Agent.OBU trojan AE7C5EDD787BCDD8ED5966BDF02F1B46
C:\QooBox\Quarantine\C\WINDOWS\system32\tdssmain.dll.vir Win32/Agent.OGC trojan 335915A73568AE9BF532C41DF91A3B31
C:\QooBox\Quarantine\C\WINDOWS\system32\tdssserf.dll.vir Win32/Agent.ODG trojan 67E17F3C7F3C0134CAC7374FD013D9F4
C:\QooBox\Quarantine\C\WINDOWS\system32\tdssserf1.dll.vir Win32/Agent.ODG trojan 69D78C4A5D8CC85A00344C37157B87A2
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\tdssserv.sys.vir Win32/Agent.ODG trojan C9B36AE929D020240A91FF5200E8FE80


thankyou
Dan
Reply With Quote Quick reply to this message  
Join Date: Sep 2008
Posts: 37
Reputation: skiesaregrey is an unknown quantity at this point 
Solved Threads: 0
skiesaregrey skiesaregrey is offline Offline
Light Poster

Re: go.google nightmare pls help. Thanks

 
0
  #43
Sep 30th, 2008
I had unchecked the box on ESET so it would not clean the problems found...

Dan
Reply With Quote Quick reply to this message  
Join Date: Jul 2008
Posts: 3,483
Reputation: jholland1964 is a splendid one to behold jholland1964 is a splendid one to behold jholland1964 is a splendid one to behold jholland1964 is a splendid one to behold jholland1964 is a splendid one to behold jholland1964 is a splendid one to behold 
Solved Threads: 203
Moderator
Featured Poster
jholland1964 jholland1964 is online now Online
Nearly a Senior Poster

Re: go.google nightmare pls help. Thanks

 
0
  #44
Sep 30th, 2008
Don't worry about the items found by ESET they are all in the ComboFix Quarantine and we will get rid of them shortly.
You might try updating and running MBA-M again, FULL scan not the Quick one, Be sure to check Remove Selected Items too if anything is found. Post back with that log.
Judy
Reply With Quote Quick reply to this message  
Join Date: Jul 2008
Posts: 3,483
Reputation: jholland1964 is a splendid one to behold jholland1964 is a splendid one to behold jholland1964 is a splendid one to behold jholland1964 is a splendid one to behold jholland1964 is a splendid one to behold jholland1964 is a splendid one to behold 
Solved Threads: 203
Moderator
Featured Poster
jholland1964 jholland1964 is online now Online
Nearly a Senior Poster

Re: go.google nightmare pls help. Thanks

 
0
  #45
Sep 30th, 2008
After you have done that then do the following;
Run an online scan with Kaspersky from the following link:
Kaspersky Online Scanner

Note: If you have used this particular scanner before, you MAY HAVE YO UNINSTALL the program through Add/Remove Programs before downloading the new ActiveX component

Click Yes, when prompted to install its ActiveX component.
(Note.. for Internet Explorer 7 users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.)
The program launches and downloads the latest definition files.
Once the files are downloaded click on Next
Click on Scan Settings and configure as follows:
Scan using the following Anti-Virus database:
Extended
Scan Options:
Scan Archives
Scan Mail Base
Click OK and, under select a target to scan, select My Computer
When the scan is done, in the Scan is completed window (below), any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.
To obtain the report:
Click on: Save Report As (above - red blinking arrow)
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar
In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply and a new Hijack This log please.

*******
By the way, I am fairly certain that Chkdsk ran because of the multiple stopping and rebooting when attempting to run combofix. Now you removed the old combofix programs, PLUS this time you didn't download from the internet but brought it to the computer from a clean computer, PLUS disconnected from the internet while running it. I am doing a great deal of "supposing" here, and somebody may post here and say I am wrong, but think all of this shows that "something" was working there in the background to stop everything from proceeding correctly. Disconnecting helped stop that AND bringing in the clean combofix worked too. Plus, hopefully, chkdsk was able to run and remove some corrupted items. We will try to check that shortly
Last edited by jholland1964; Sep 30th, 2008 at 1:43 pm.
Reply With Quote Quick reply to this message  
Join Date: Sep 2008
Posts: 37
Reputation: skiesaregrey is an unknown quantity at this point 
Solved Threads: 0
skiesaregrey skiesaregrey is offline Offline
Light Poster

Re: go.google nightmare pls help. Thanks

 
0
  #46
Sep 30th, 2008
None found on MBA-M

Malwarebytes' Anti-Malware 1.28
Database version: 1225
Windows 5.1.2600 Service Pack 3

30/09/2008 18:32:58
mbam-log-2008-09-30 (18-32-57).txt

Scan type: Full Scan (C:\|)
Objects scanned: 140566
Time elapsed: 56 minute(s), 42 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Dan
Reply With Quote Quick reply to this message  
Join Date: Sep 2008
Posts: 37
Reputation: skiesaregrey is an unknown quantity at this point 
Solved Threads: 0
skiesaregrey skiesaregrey is offline Offline
Light Poster

Re: go.google nightmare pls help. Thanks

 
0
  #47
Sep 30th, 2008
Hi
When i click that Kaspersky link it doesnt load an activex file. Im just sitting on the homepage... what do I do next?

Dan
Reply With Quote Quick reply to this message  
Join Date: Jul 2008
Posts: 3,483
Reputation: jholland1964 is a splendid one to behold jholland1964 is a splendid one to behold jholland1964 is a splendid one to behold jholland1964 is a splendid one to behold jholland1964 is a splendid one to behold jholland1964 is a splendid one to behold 
Solved Threads: 203
Moderator
Featured Poster
jholland1964 jholland1964 is online now Online
Nearly a Senior Poster

Re: go.google nightmare pls help. Thanks

 
0
  #48
Sep 30th, 2008
Originally Posted by skiesaregrey View Post
Hi
When i click that Kaspersky link it doesnt load an activex file. Im just sitting on the homepage... what do I do next?

Dan
Note: If you have used this particular scanner before, you MAY HAVE YO UNINSTALL the program through Add/Remove Programs before downloading the new ActiveX component
Did you check Add/Remove?
Reply With Quote Quick reply to this message  
Join Date: Sep 2008
Posts: 37
Reputation: skiesaregrey is an unknown quantity at this point 
Solved Threads: 0
skiesaregrey skiesaregrey is offline Offline
Light Poster

Re: go.google nightmare pls help. Thanks

 
0
  #49
Sep 30th, 2008
ignore that.
Reply With Quote Quick reply to this message  
Join Date: Sep 2008
Posts: 37
Reputation: skiesaregrey is an unknown quantity at this point 
Solved Threads: 0
skiesaregrey skiesaregrey is offline Offline
Light Poster

Re: go.google nightmare pls help. Thanks

 
0
  #50
Sep 30th, 2008
But what i am having problems with is that it is saying i need Java 1.5 or newer? Even though I change it to 75% still the accept button is not clickable..
Last edited by skiesaregrey; Sep 30th, 2008 at 1:49 pm.
Reply With Quote Quick reply to this message  
Reply

This thread has been marked solved.
Perhaps start a new thread instead?
Message:




Views: 6928 | Replies: 70
Thread Tools Search this Thread



Tag cloud for Viruses, Spyware and other Nasties
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2010 DaniWeb® LLC