Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old November 21st, 2006, 06:05 AM
Mick2015 Mick2015 is offline
Infrequent Poster
 
Join Date: Nov 2006
Posts: 4
Unhappy need some advice

hi all
im new to Nod32, since last friday (17/01/06) ive ben getting hit by alot of trojans and nod32 been delte them straght away but every time i shut down and restart the pc they hit my pc again

first off i was hit by Win32/TrojanDownloader.Zlob.AJB that was in v.1867 (20061115) update and now thats gone im ketp on getting hit by the following thats in the log file
Quote:
Time Module Object Name Threat Action User Information
21/11/2006 09:47:45 AMON file C:\WINDOWS\system32\xknyrhnb.exe Win32/Adware.Toolbar.SearchColours application deleted GUNS4HIRE\Michael Event occurred at an attempt to access the file by the application: C:\Program Files\NoAdware4\NoAdware4.exe.
21/11/2006 09:47:44 AMON file C:\WINDOWS\system32\vbrmkyaa.exe Win32/Adware.Toolbar.SearchColours application deleted GUNS4HIRE\Michael Event occurred at an attempt to access the file by the application: C:\Program Files\NoAdware4\NoAdware4.exe.
21/11/2006 09:47:44 AMON file C:\WINDOWS\system32\uumkmqwd.exe Win32/Adware.Toolbar.SearchColours application deleted GUNS4HIRE\Michael Event occurred at an attempt to access the file by the application: C:\Program Files\NoAdware4\NoAdware4.exe.
21/11/2006 09:47:43 AMON file C:\WINDOWS\system32\utachgtn.exe Win32/Adware.Toolbar.SearchColours application deleted GUNS4HIRE\Michael Event occurred at an attempt to access the file by the application: C:\Program Files\NoAdware4\NoAdware4.exe.
21/11/2006 09:47:42 AMON file C:\WINDOWS\system32\uqswbier.exe Win32/Adware.Toolbar.SearchColours application deleted GUNS4HIRE\Michael Event occurred at an attempt to access the file by the application: C:\Program Files\NoAdware4\NoAdware4.exe.
21/11/2006 09:47:42 AMON file C:\WINDOWS\system32\twpluiiw.exe Win32/Adware.Toolbar.SearchColours application deleted GUNS4HIRE\Michael Event occurred at an attempt to access the file by the application: C:\Program Files\NoAdware4\NoAdware4.exe.
21/11/2006 09:47:41 AMON file C:\WINDOWS\system32\oygjnsrg.exe Win32/Adware.Toolbar.SearchColours application deleted GUNS4HIRE\Michael Event occurred at an attempt to access the file by the application: C:\Program Files\NoAdware4\NoAdware4.exe.
21/11/2006 09:47:40 AMON file C:\WINDOWS\system32\lgttevjk.exe Win32/Adware.Toolbar.SearchColours application deleted GUNS4HIRE\Michael Event occurred at an attempt to access the file by the application: C:\Program Files\NoAdware4\NoAdware4.exe.
21/11/2006 09:47:39 AMON file C:\WINDOWS\system32\keksdmrt.exe Win32/Adware.Toolbar.SearchColours application deleted GUNS4HIRE\Michael Event occurred at an attempt to access the file by the application: C:\Program Files\NoAdware4\NoAdware4.exe.
21/11/2006 09:47:36 AMON file C:\WINDOWS\system32\fmchkfen.exe Win32/Adware.Toolbar.SearchColours application deleted GUNS4HIRE\Michael Event occurred at an attempt to access the file by the application: C:\Program Files\NoAdware4\NoAdware4.exe.
21/11/2006 09:47:34 AMON file C:\WINDOWS\system32\dyiyahqb.exe Win32/Adware.Toolbar.SearchColours application deleted GUNS4HIRE\Michael Event occurred at an attempt to access the file by the application: C:\Program Files\NoAdware4\NoAdware4.exe.
21/11/2006 09:47:27 AMON file C:\DOCUME~1\MICHAE~1.GUN\LOCALS~1\Temp\ferdkuto.exe Win32/Adware.Toolbar.SearchColours application quarantined - deleted GUNS4HIRE\Michael Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
21/11/2006 09:42:02 IMON file http://82.98.235.61/execpyd.exe?uid=...18972DAB794B2A Win32/Adware.Toolbar.SearchColours application Connection terminated GUNS4HIRE\Michael
20/11/2006 19:17:14 IMON archive http://download.cdn.winsoftware.com/...reeInstall.cab Win32/Adware.WinFixer application Connection terminated GUNS4HIRE\Michael
  #2  
Old November 21st, 2006, 06:20 AM
Blackspear's Avatar
Blackspear Blackspear is offline
Global Moderator
 
Join Date: Dec 2002
Location: Gold Coast, Queensland, Australia
Posts: 15,114
Default Re: neeed some advace

Hi Mick2015, welcome to Wilders.

Please check your settings against those found HERE

After this run a scan by following these steps:

1. Click on the NOD32 Control Centre (Green and White split square on the bottom right hand corner of your computers screen).
2. Click on NOD32.
3. Click on Run NOD32.
4. Click on “Scan and Clean”.

Let us know how you go...

Cheers
__________________
"Illegitimis non carborundum"
translation:
"Don't let the bastards grind you down"
U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946)
Two Photographers
  #3  
Old November 21st, 2006, 07:43 AM
Mick2015 Mick2015 is offline
Infrequent Poster
 
Join Date: Nov 2006
Posts: 4
Default Re: neeed some advace

thanks for ur replay and ill get back to you asp
  #4  
Old November 21st, 2006, 08:54 AM
scaa's Avatar
scaa scaa is offline
Frequent Poster
 
Join Date: Feb 2005
Posts: 202
Default Re: neeed some advace

Quote:
Originally Posted by Blackspear
Hi Mick2015, welcome to Wilders.

Please check your settings against those found HERE

After this run a scan by following these steps:

1. Click on the NOD32 Control Centre (Green and White split square on the bottom right hand corner of your computers screen).
2. Click on NOD32.
3. Click on Run NOD32.
4. Click on “Scan and Clean”.

Let us know how you go...

Cheers

I think you ought to modify the settings tutorial once more for version 2.7 and thanks in advance.
  #5  
Old November 21st, 2006, 12:49 PM
Mick2015 Mick2015 is offline
Infrequent Poster
 
Join Date: Nov 2006
Posts: 4
Default Re: neeed some advace

yup i agree m8


now the only problem ive got is now i get this popup block by Nod 32

Quote:
NOD32 antivirus system alert: IMON
Access denied !

Details:

Web page:
[url]http://www.winantivirus.com/pages/scanner/?p=15&j=1&ex=1&ax=1&h=10&aid=nm_sh_wav_kw3&lid=adsare&affid=nm_66973_
1baa50de73f111db818600167647fa98_ec49f22a+4754d5660b584f10b718972dab794b2a

Description:
Access to the web page was blocked by IMON. The web page is on the list of websites with potentially dangerous content.




and this 1 too

Quote:
NOD32 antivirus system alert: IMON
Access denied !

Details:

Web page:
http://www.drivecleaner.com/.freeware/?p=56&a=0&j=1&pp=1&w=1&ex=1&ap=1&hv=10&ed=2&mpt=1164130920&ad=nm_
sh_dc_meta_kw&lid=bad&affid=nm_66973_1BAA50DE73F111DB818600167647FA98_ec49f22a+4754D5660B584F10B718972DAB794B2A

Description:
Access to the web page was blocked by IMON. The web page is on the list of websites with potentially dangerous content.

Last edited by Blackspear : November 21st, 2006 at 09:50 PM. Reason: Fixed width of quote
  #6  
Old November 21st, 2006, 01:04 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: need some advace

WinAntivirus is a known rogue site
NOD 32 indicates the software NoAdware(don´t know of this) as the possible source of infection. Could be a FP too
Run an in-depth scan with NOD 32 and another AT/AS scanner if possible
Run them in safe mode
  #7  
Old November 21st, 2006, 02:40 PM
ASpace
 
Posts: n/a
Default Re: need some advace

Quote:
Originally Posted by lucas1985
WinAntivirus is a known rogue site
NOD 32 indicates the software NoAdware(don´t know of this) as the possible source of infection. Could be a FP too
Run an in-depth scan with NOD 32 and another AT/AS scanner if possible
Run them in safe mode

No , it isn't false positive . The application NoAdware4 tries to access the infected files (Adware.Toolbar...) and NOD32 blocks them

Mick2015 , I would recommend you start with checking in Start->Settings->Control Panel->Add/Remove programs if you have the software NoAdware . If you have such a program , immediately remove it/uninstall it . It is considered rogue program which will do nothing to remove your infections but will , however , infect you more .

After that , perform Blackspear's suggestion to perform full Scan&Clean over the system and remove the infections . I would also recommend you download and run Ewido micro scanner / Spybot Search and Destroy , so that you have a second good opinion

Good luck

Last edited by ASpace : November 21st, 2006 at 03:58 PM.
  #8  
Old November 21st, 2006, 03:42 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: need some advace

Quote:
Originally Posted by HiTech_boy
No , it isn't false positive . The application NoAdware4 tries to access the infected files (Adware.Toolbar...) and NOD32 blocks them
Thanks, the rogue list is very large and it´s difficult to remember all of them
I´d like to know how the infection happened
  #9  
Old November 21st, 2006, 03:59 PM
ASpace
 
Posts: n/a
Default Re: need some advace

Quote:
Originally Posted by lucas1985
Thanks, the rogue list is very large and it´s difficult to remember all of them

No worries

Quote:
Originally Posted by lucas1985
I´d like to know how the infection happened
From the infromation provided I personally can't say but I don't think it is so important now . The OP should take actions to clean the machine because it seems to be really infected
  #10  
Old November 21st, 2006, 09:50 PM
Blackspear's Avatar
Blackspear Blackspear is offline
Global Moderator
 
Join Date: Dec 2002
Location: Gold Coast, Queensland, Australia
Posts: 15,114
Default Re: neeed some advace

Quote:
Originally Posted by Mick2015
now the only problem ive got is now i get this popup block by Nod 32
If the Tutorial has been completed there will not be any popups; everything is automated.

Cheers
__________________
"Illegitimis non carborundum"
translation:
"Don't let the bastards grind you down"
U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946)
Two Photographers
  #11  
Old November 23rd, 2006, 06:55 AM
Mick2015 Mick2015 is offline
Infrequent Poster
 
Join Date: Nov 2006
Posts: 4
Default Re: need some advace

Quote:
Originally Posted by lucas1985
WinAntivirus is a known rogue site
NOD 32 indicates the software NoAdware(don´t know of this) as the possible source of infection. Could be a FP too
Run an in-depth scan with NOD 32 and another AT/AS scanner if possible
Run them in safe mode
thanks alot for that infor m8, i do have Noadware installed too and will take it off


Quote:
Originally Posted by HiTech_boy
No , it isn't false positive . The application NoAdware4 tries to access the infected files (Adware.Toolbar...) and NOD32 blocks them

Mick2015 , I would recommend you start with checking in Start->Settings->Control Panel->Add/Remove programs if you have the software NoAdware . If you have such a program , immediately remove it/uninstall it . It is considered rogue program which will do nothing to remove your infections but will , however , infect you more .

After that , perform Blackspear's suggestion to perform full Scan&Clean over the system and remove the infections . I would also recommend you download and run Ewido micro scanner / Spybot Search and Destroy , so that you have a second good opinion

Good luck

thanks alot, for the infor anf linsk and will get back to u asp


Quote:
Originally Posted by HiTech_boy
No worries

From the infromation provided I personally can't say but I don't think it is so important now . The OP should take actions to clean the machine because it seems to be really infected

tell u this i not to sure how it happened myself, but i think its been ina zip file i downlaoded but saying taht i vuirs scan all my files before i open them
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:55 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums