SpiritWind, on 17 December 2011 - 02:11 PM, said:
Hi :
There could be multiple reasons WHY these Sites are
suddenly NOT accessible . Norton is NOT the final word
when it comes to detecting a possible computer "Virus"
( nowadays there are no longer "viruses", but a wider
category called "malware" ). Best to use Malwarebytes
Anti-Malware (
http://www.malwarebytes.org/products )
AND "SUPERAntiSpyware" (
http://www.superantispyware.com )
BOTH of which come in a FREE Version . After installation,
and updating their "Definitions", run their "Complete/Full
Scan" and see if anything is detected . Report back here
with what was found, IF anything .
Hey man, thanks a lot! My problem is still not solved, but, I did run Malwarebytes and there 6 infected objects with trojan and one other named dealio someehting. Here are the log files from malwarebytes:
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8388
Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000
12/17/2011 3:50:01 PM
mbam-log-2011-12-17 (15-50-01).txt
Scan type: Full scan (C:\|D:\|)
Objects scanned: 312341
Time elapsed: 1 hour(s), 0 minute(s), 31 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 4
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Bad: (93.188.161.105) Good: () -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Bad: (93.188.166.105) Good: () -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B9C234D9-192A-4517-9EDE-FCE858A3FB35}\DhcpNameServer (Trojan.DNSChanger) -> Bad: (93.188.161.105) Good: () -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B9C234D9-192A-4517-9EDE-FCE858A3FB35}\DhcpNameServer (Trojan.DNSChanger) -> Bad: (93.188.166.105) Good: () -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Users\Ted\AppData\Local\Temp\nse69A4.tmp\dealiotoolbar-stub-1.exe (PUP.Dealio.TB) -> Quarantined and deleted successfully.
also this was in a different log file:
14:48:14 Ted MESSAGE Protection started successfully
14:48:19 Ted MESSAGE IP Protection started successfully
14:54:12 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 62774, Process: svchost.exe)
15:09:14 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 61607, Process: svchost.exe)
15:24:42 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 58548, Process: svchost.exe)
15:34:06 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 64858, Process: svchost.exe)
15:34:14 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 55058, Process: svchost.exe)
15:34:14 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 61845, Process: svchost.exe)
15:34:14 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 53408, Process: svchost.exe)
15:34:14 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 61845, Process: svchost.exe)
15:34:14 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 63636, Process: svchost.exe)
15:34:14 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 55058, Process: svchost.exe)
15:34:14 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 53408, Process: svchost.exe)
15:34:22 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 53408, Process: svchost.exe)
15:34:22 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 63636, Process: svchost.exe)
15:34:22 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 60348, Process: svchost.exe)
15:34:22 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 60348, Process: svchost.exe)
15:34:30 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 63974, Process: svchost.exe)
15:34:30 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 60348, Process: svchost.exe)
15:34:30 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 63974, Process: svchost.exe)
15:34:31 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 59787, Process: svchost.exe)
15:34:31 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 64250, Process: svchost.exe)
15:34:39 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 64150, Process: svchost.exe)
15:39:45 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 56636, Process: svchost.exe)
15:54:54 Ted MESSAGE Protection started successfully
15:55:00 Ted MESSAGE IP Protection started successfully
15:56:02 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 57822, Process: svchost.exe)
15:56:10 Ted IP-BLOCK 93.188.161.105 (Type: outgoing, Port: 58808, Process: svchost.exe)
by the way about superantispyware, I started running it recently after I asked this question and got a bunch of tracking cookies and other infected files and stuff quarantined and deleted! but I'm still having trouble accessing those two sites! :\
Also I keep getting pop up bubbles at the bottom right corner from malwarebytes when I browse saying stuff like for example:
"malwarebytes anti-malware successfully blocked access to potentially malicious website:93.188.161.105
Type: outgoing
port:50496
process:svchost.exe"
Malwarebytes quarantined 4 trojandnschanger files and a PUP.dealio.TB file
that's it and they're quarantined
This post has been edited by deedrio: 17 December 2011 - 04:20 PM