943,900 Members | Top Members by Rank

Ad:
You are currently viewing page 5 of this multi-page discussion thread; Jump to the first page
Sep 30th, 2008
0

Re: go.google nightmare pls help. Thanks

This infected one... and guess what, im on eset doing an online scan!
Ill send that log asap, really want to keep it on this side of the fence! Any other software that I should run?
Reputation Points: 10
Solved Threads: 0
Light Poster
skiesaregrey is offline Offline
37 posts
since Sep 2008
Sep 30th, 2008
0

Re: go.google nightmare pls help. Thanks

Resutls from ESET ONLINE SCAN

# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3483 (20080930)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=5348aad771303c429863e7938ba0c76e
# end=finished
# remove_checked=false
# unwanted_checked=true
# utc_time=2008-09-30 04:28:07
# local_time=2008-09-30 05:28:07 (+0000, GMT Standard Time)
# country="United Kingdom"
# osver=5.1.2600 NT Service Pack 3
# scanned=319712
# found=7
# scan_time=2354
C:\QooBox\Quarantine\C\WINDOWS\system32\tdssadw.dll.vir Win32/Agent.ODG trojan 151046484AEF8DE49A459F2340F09190
C:\QooBox\Quarantine\C\WINDOWS\system32\tdssl.dll.vir Win32/Agent.ODG trojan D14A2ACE850393CA9446DA3BB9CFBF0B
C:\QooBox\Quarantine\C\WINDOWS\system32\tdsslog.dll.vir Win32/Agent.OBU trojan AE7C5EDD787BCDD8ED5966BDF02F1B46
C:\QooBox\Quarantine\C\WINDOWS\system32\tdssmain.dll.vir Win32/Agent.OGC trojan 335915A73568AE9BF532C41DF91A3B31
C:\QooBox\Quarantine\C\WINDOWS\system32\tdssserf.dll.vir Win32/Agent.ODG trojan 67E17F3C7F3C0134CAC7374FD013D9F4
C:\QooBox\Quarantine\C\WINDOWS\system32\tdssserf1.dll.vir Win32/Agent.ODG trojan 69D78C4A5D8CC85A00344C37157B87A2
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\tdssserv.sys.vir Win32/Agent.ODG trojan C9B36AE929D020240A91FF5200E8FE80


thankyou
Dan
Reputation Points: 10
Solved Threads: 0
Light Poster
skiesaregrey is offline Offline
37 posts
since Sep 2008
Sep 30th, 2008
0

Re: go.google nightmare pls help. Thanks

I had unchecked the box on ESET so it would not clean the problems found...

Dan
Reputation Points: 10
Solved Threads: 0
Light Poster
skiesaregrey is offline Offline
37 posts
since Sep 2008
Sep 30th, 2008
0

Re: go.google nightmare pls help. Thanks

Don't worry about the items found by ESET they are all in the ComboFix Quarantine and we will get rid of them shortly.
You might try updating and running MBA-M again, FULL scan not the Quick one, Be sure to check Remove Selected Items too if anything is found. Post back with that log.
Judy
Moderator
Featured Poster
Reputation Points: 725
Solved Threads: 339
Posting Expert
jholland1964 is offline Offline
5,497 posts
since Jul 2008
Sep 30th, 2008
0

Re: go.google nightmare pls help. Thanks

After you have done that then do the following;
Run an online scan with Kaspersky from the following link:
Kaspersky Online Scanner

Note: If you have used this particular scanner before, you MAY HAVE YO UNINSTALL the program through Add/Remove Programs before downloading the new ActiveX component

Click Yes, when prompted to install its ActiveX component.
(Note.. for Internet Explorer 7 users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.)
The program launches and downloads the latest definition files.
Once the files are downloaded click on Next
Click on Scan Settings and configure as follows:
Scan using the following Anti-Virus database:
Extended
Scan Options:
Scan Archives
Scan Mail Base
Click OK and, under select a target to scan, select My Computer
When the scan is done, in the Scan is completed window (below), any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.
To obtain the report:
Click on: Save Report As (above - red blinking arrow)
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar
In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply and a new Hijack This log please.

*******
By the way, I am fairly certain that Chkdsk ran because of the multiple stopping and rebooting when attempting to run combofix. Now you removed the old combofix programs, PLUS this time you didn't download from the internet but brought it to the computer from a clean computer, PLUS disconnected from the internet while running it. I am doing a great deal of "supposing" here, and somebody may post here and say I am wrong, but think all of this shows that "something" was working there in the background to stop everything from proceeding correctly. Disconnecting helped stop that AND bringing in the clean combofix worked too. Plus, hopefully, chkdsk was able to run and remove some corrupted items. We will try to check that shortly
Last edited by jholland1964; Sep 30th, 2008 at 2:43 pm.
Moderator
Featured Poster
Reputation Points: 725
Solved Threads: 339
Posting Expert
jholland1964 is offline Offline
5,497 posts
since Jul 2008
Sep 30th, 2008
0

Re: go.google nightmare pls help. Thanks

None found on MBA-M

Malwarebytes' Anti-Malware 1.28
Database version: 1225
Windows 5.1.2600 Service Pack 3

30/09/2008 18:32:58
mbam-log-2008-09-30 (18-32-57).txt

Scan type: Full Scan (C:\|)
Objects scanned: 140566
Time elapsed: 56 minute(s), 42 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Dan
Reputation Points: 10
Solved Threads: 0
Light Poster
skiesaregrey is offline Offline
37 posts
since Sep 2008
Sep 30th, 2008
0

Re: go.google nightmare pls help. Thanks

Hi
When i click that Kaspersky link it doesnt load an activex file. Im just sitting on the homepage... what do I do next?

Dan
Reputation Points: 10
Solved Threads: 0
Light Poster
skiesaregrey is offline Offline
37 posts
since Sep 2008
Sep 30th, 2008
0

Re: go.google nightmare pls help. Thanks

Hi
When i click that Kaspersky link it doesnt load an activex file. Im just sitting on the homepage... what do I do next?

Dan
Quote ...
Note: If you have used this particular scanner before, you MAY HAVE YO UNINSTALL the program through Add/Remove Programs before downloading the new ActiveX component
Did you check Add/Remove?
Moderator
Featured Poster
Reputation Points: 725
Solved Threads: 339
Posting Expert
jholland1964 is offline Offline
5,497 posts
since Jul 2008
Sep 30th, 2008
0

Re: go.google nightmare pls help. Thanks

ignore that.
Reputation Points: 10
Solved Threads: 0
Light Poster
skiesaregrey is offline Offline
37 posts
since Sep 2008
Sep 30th, 2008
0

Re: go.google nightmare pls help. Thanks

But what i am having problems with is that it is saying i need Java 1.5 or newer? Even though I change it to 75% still the accept button is not clickable..
Last edited by skiesaregrey; Sep 30th, 2008 at 2:49 pm.
Reputation Points: 10
Solved Threads: 0
Light Poster
skiesaregrey is offline Offline
37 posts
since Sep 2008

This thread is solved

Either the thread starter or a moderator has marked this thread as solved. You can most likely trust the responses and answers given. There is most likely no reason for any further responses to be posted here. If you have a related question, please start a new thread in this forum instead.

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in Viruses, Spyware and other Nasties Forum Timeline: Unable to open My computer, Control panel...
Next Thread in Viruses, Spyware and other Nasties Forum Timeline: Slow operations..virus or heavy disks? Windows Live and messenger updates culprit?





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC