Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.
Collaborate in the cloud with Office, Exchange, SharePoint, and Lync
|
|||||||
Collaborate in the cloud with Office, Exchange, SharePoint, and Lync
8 step results, need help
|
|
Thread Tools | Search this Thread |
|
#1
|
|||
|
|||
|
8 step results, need help
A little background first. I got infected with the Security Tool malware. I used malwarebytes to remove it. That was a couple days ago. From that point on, I am having problems with anything related to google. Gmail gives me a "data transfer interrupted" error before even loading the login page. I can get to google.com but if I do a search the page goes white and nothing happens. I just completed the 8 step virus/spyware removal instructions and have included my logs. Thanks in advance for the help.
|
|
#2
|
||||
|
||||
|
You're going to need more in-depth help. Try running the ESET On-Line Scanner and see if you pick up anything else:
ESET Scanner |
|
#3
|
|||
|
|||
|
I just ran ESET scanner and found one threat. It was win32/rootkit.kryptik.AFtrojan.
Last edited by oates; 12-27-2009 at 11:34 AM.. |
|
#4
|
||||
|
||||
|
Turn off System Restore, rerun the 8-Steps and post the scan results. Turn System Restore back on
|
|
#5
|
|||
|
|||
|
Just completed the second 8-step with system restore off this time. None of the scans found anything malicious.
|
|
|
|
#6
|
||||
|
||||
|
You have a DNS hijacker active according to your new hijackthis log. A router reset and Combofix may be needed now... Stay tuned
|
|
#7
|
||||
|
||||
|
Welcome to TechSpot, oates. I';d like to get you back on track. Unfortunately, the information you've had so far is useless and incorrect.
Your searches are going to a website in Poland- your Host files have been hijacked. Please reopen Hijackthis to 'do system scan only'. Check each of the following if present: Note: the 2 Optional Removals are in green. Check all others: O1 - Hosts: ::1 localhost O1 - Hosts: 91.212.127.227 antiviraprof-2009.microsoft.com O1 - Hosts: 91.212.127.227 antiviraprof2009.com O1 - Hosts: 91.212.127.227 www.antiviraprof2009.com O1 - Hosts: 78.159.110.41 www.google.com O1 - Hosts: 78.159.110.41 www.google.de O1 - Hosts: 78.159.110.41 www.google.fr O1 - Hosts: 78.159.110.41 www.google.co.uk O1 - Hosts: 78.159.110.41 www.google.com.br O1 - Hosts: 78.159.110.41 www.google.it O1 - Hosts: 78.159.110.41 www.google.es O1 - Hosts: 78.159.110.41 www.google.co.jp O1 - Hosts: 78.159.110.41 www.google.com.mx O1 - Hosts: 78.159.110.41 www.google.ca O1 - Hosts: 78.159.110.41 www.google.com.au O1 - Hosts: 78.159.110.41 www.google.nl O1 - Hosts: 78.159.110.41 www.google.co.za O1 - Hosts: 78.159.110.41 www.google.be O1 - Hosts: 78.159.110.41 www.google.gr O1 - Hosts: 78.159.110.41 www.google.at O1 - Hosts: 78.159.110.41 www.google.se O1 - Hosts: 78.159.110.41 www.google.ch O1 - Hosts: 78.159.110.41 www.google.pt O1 - Hosts: 78.159.110.41 www.google.dk O1 - Hosts: 78.159.110.41 www.google.fi O1 - Hosts: 78.159.110.41 www.google.ie O1 - Hosts: 78.159.110.41 www.google.no O1 - Hosts: 78.159.110.41 search.yahoo.com O1 - Hosts: 78.159.110.41 us.search.yahoo.com O1 - Hosts: 78.159.110.41 uk.search.yahoo.com O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) (AVG) O15 - Trusted Zone: http://*.somethingcool.com (HKLM)>> See Optional 1 O17 - HKLM\Software\..\Telephony: DomainName = lesterville.wan>> See Optional 2 Optional 1: Trusted Zone: somethingcool.com I would encourage removing this from the Trusted sites. It is a legitimate entry, but no reason for it to be able to pass the lower security for this zone- Optional 2: unidentified> lesterville.wan I can't identify this. Do you have a network set up in the Lesterville area or group> If not, check for removal. Close all Windows except HijackThis and click on "Fix Check." Please download ComboFix HERE:
Notes:
You have 2 out of date Adobe Reader entries. These are vulnerabilities: Acrobat 5.0 and Acrobat 7.0 Visit this Adobe Reader site get the most current version, v9.xx Uninstall any earlier updates as they are vulnerabilities. Rescan with HijackThis and include a new log. |
|
#8
|
||||
|
||||
|
"Unfortunately, the information you've had so far is useless and incorrect"...
There you go again Bobbye! Insulting and rude... I am trying to help, and all you can say is this? |
|
#9
|
||||
|
||||
|
Tmagic, You're just running up your post count.
|
|
#10
|
||||
|
||||
|
... and you're insulting and narcissistic by nature. You think the World revolves around you. Let me be the first to tell you, it doesn't
|
|
#11
|
||||
|
||||
|
oates, I hope you will continue to attempting to clean the system.
|
|
#12
|
|||
|
|||
|
I have ran the first hijackthis, and I am ready to run combofix. When you said to disable internet connection, did you want me to close browsers or were you talking about shutting down router or what?
|
|
#13
|
||||
|
||||
|
Yes Oats,
just turn off the router disabling the Internet temporarily. Good luck. Sorry about the Bobbye stuff |
|
#14
|
|||
|
|||
|
Here is the logs for the combofix and hijackthis.
|
|
#15
|
||||
|
||||
|
Please update and run the Eset Online scan:
Run Eset NOD32 Online AntiVirus Scanner HERE Note: You will need to use Internet Explorer for this scan.
Reset your Host Files: MVPS Hosts files This replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer. Scroll down to right below "Editors Note" for the download. Quote:
Your Adobe Reader is way out of date> v5. The current version is v9.xx. Having the earlier program presents a vulnerability to your system. Visit this Adobe Reader site and get the most current update. Uninstall any earlier updates as they are vulnerabilities. Leave the Eset log and let me know your status. Edit: I strongly suggest that you install a Recovery Console. This site will walk you through doing it: http://www.bleepingcomputer.com/tuto...torial117.html Last edited by Bobbye; 12-30-2009 at 07:07 PM.. Reason: Add Recovery Console |
|
#16
|
|||
|
|||
|
I thought that I had already taken care of the Adobe Reader problem as I have version 9.2 installed. I thought that installing the new version would get rid of the old one. I think I have version 5 uninstalled now. The google problem is now fixed. The eset scan did not find any threats. I have attached the log.
I will install a recovery console. |
|
#17
|
||||
|
||||
|
Unfortunately, Adobe doesn't overwrite earlier versions. Java didn't either, but appears to be doing so now.
Since the problem has resolved and the online scan is clean (it's nice to see a clean one once in a while!) I'll have you remove the cleaning tools and old restore points: Uninstall ComboFix.exe And all Backups of the files it deleted
If you are prompted to Reboot during the cleanup, select Yes. You should now set a new Restore Point to prevent infection from any previous Restore Points. The easiest and safest way to do this is:
More details and screenshots for Disk Cleanup in Windows Vista can be found here. Please follow these simple steps to keep your computer clean and secure: 1.Disable and Enable System Restore: This will help you to drop the old restore points and set a new, clean one: System Restore Guide 2.Stay current on updates:
3.Make Internet Explorer safer. Follow the suggestions HERE This Tutorial will help guide you through Configuring Security Settings, Managing Active X Controls and other safety features. 4.Remove Temporary Internet Files regularly: Use5. Use an AntiVirus Software(only one)
6.Use a good, bi-directional firewall(one software firewall) See Understanding and Using Firewalls including links to download a firewall. 7.Consider these programs for Extra Security
If I can be of further assistance, please let me know. Wishing you a Happy New year! |
![]() |
| Similar Topics | ||||
| Topic | Replies | Forum | ||
Infection- 8 step results
|
1 | Virus and Malware Removal | ||
8 step results
|
3 | Virus and Malware Removal | ||
8 Step Results for Laptop
|
1 | Virus and Malware Removal | ||
8 step results
|
15 | Virus and Malware Removal | ||
8 step results
|
12 | Virus and Malware Removal | ||
| Thread Tools | Search this Thread |
|
|
All times are GMT -4. The time now is 03:34 PM.




Infection- 8 step results