Helping Malware Removal - Day.js

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by MaDeInRiO, Aug 5, 2008.

  1. MaDeInRiO

    MaDeInRiO Private E-2

    Hi Guys,

    Im brazilian and just learning english, so excusme of some mistake that i´ll make...:eek:

    well, i found some topics about it, but i think that each case is a case.Cause some them are procediments that not aply to me.
    I already read READ AND RUN FIRST and im getting nervous with this virus (day.js) It appears in all, an every page i open in IE. (i dont use FF)
    Im using AVAST, and after a Format, the virus still there!!!

    idont know what to do anymore!! Please help with it!!

    Thanks for all!!!
     
  2. MaDeInRiO

    MaDeInRiO Private E-2

  3. MaDeInRiO

    MaDeInRiO Private E-2

    My logs
     

    Attached Files:

    Last edited by a moderator: Aug 5, 2008
  4. MaDeInRiO

    MaDeInRiO Private E-2

    one more...
     

    Attached Files:

    Last edited by a moderator: Aug 5, 2008
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It appears that this is a somewhat new SQL injection type infection in the wild. You can read about it in the below link:

    http://ddanchev.blogspot.com/2008/07/smells-like-copycat-sql-injection-in.html

    This may not be a problem with your PC but rather with your ISP's DNS. I'm not positive yet. But since you say the problem is still there after a reinstall, it would be unlikely to be your PC. In fact if you have another PC, try it on your network. Does it do the same thing? Also if you could take your PC to another persons house who does not use the same ISP, does your PC still show the same problem?

    You could try adding the below to your Restricted Zone in IE but I'm not sure what the effect will be.

    5iyy .info
    content-type .cn
    63afe561 .info
    633f94d3 .info
    8d77b42a .info
    5iyy .info
    idcads .info
    efreesky .com
    freefl .info
    gggjjj .info
    ads002 .net
    goodnetads .org
    51113 .com
    update999 .cn
    50db34d5 .info

    cn3721 .org
    rm510 .com
    sb941 .com
    ad9178 .com
    91tg .net
     
  6. MaDeInRiO

    MaDeInRiO Private E-2

    i´m a lucky guy..han?! :cry


    To tell the true, we talking about a LanHouse, a kind of store that we rent PCs for internet, and games....BUT....at the clients PCs we use DEEP FREEZE, that discart every change made..you may know better than me....

    So, in the Server, we can´t use this kind of software, and is in this computer that is the problem...

    I´ll try take the server to my network in home, and see what happens!!


    Well, are my logs clean??

    Can i wait some tips of you?! Tell me Yes please!! Im getting crazy with it!!:banghead


    Thanks for the Help!!! and excuseme my english!!!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This would be a good test, but only if you are not using the same ISP to get to the internet as at the store.


    Yes they are all clean.

    Just what I gave you to add to the Restricted Zone. Did you add those URLs to the Restricted Zone?
     
  8. MaDeInRiO

    MaDeInRiO Private E-2

    Ohhh sorry!! i forgot!!

    I did that!
    I added those urls in the restricted zone, but without success...in a first moment I opened sites without any problem..but 3 minutes later it appears again!

    Please explain me what is ISP???
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ISP = Internet Service Provider. This is the company who provides your internet service.
     
  10. MaDeInRiO

    MaDeInRiO Private E-2

    well, let me start my rap! heheheeh

    I am with the server in my network at home right now...and surprise!! i dont have pop ups of virus anymore...!!

    however, it is the same ISP,(becouse the principal provider around here is VELOX) but another telephone line...

    i didnt understand very well that blog you
    show me...becouse have some terms that i dont know yet. So...

    Could you explain me better, maybe with another words??

    Could my moden be infected with any virus??Is it possible?

    Anyway, tomorrow i will try my moden here at home to see what happens and let you know.

    Thanks a lot!!:wave
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well it still indicates that the problem is not in your PC. As I stated earlier, your PC is clean, the problem appears to be in the network equipment you are accessing and I cannot help you with that.

    Are you using a dialup connection or is this a broad band type connection (like DSL or Cable)?
     
  12. MaDeInRiO

    MaDeInRiO Private E-2

    I am using a broad band.(DSL)

    Like i asked before....Could my modem be infected?? is it possible?!

    If yes, Can I change the Firmware, reset, format or anything like it?!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is possible. It is also possible that a router (if you are using one) has become infected.

    You have to talk to your ISP about this.
     
  14. MaDeInRiO

    MaDeInRiO Private E-2

    i think that you cant help me anymore....am i right?

    all that i can do is talk with my ISP, and do some mre tests here to have sure about the problem...

    Thanks again for the help! I would never imagine that the problem could be in the "line"!!

    Any news i will post here...

    thanks a lot! :wave
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Correct. The problem is not in your PC as you noticed when moved to a new location.

    It is not in the line. It is in the equipment connected to the line. It is either in your router, cable modem or the ISP's network equipment.
     
  16. MaDeInRiO

    MaDeInRiO Private E-2

    But..all equipments that i have are a moden( that works like a router) and a switch...

    Today, i noticed that there is another location that the virus is.
    in c:\documents and settings\temp......\day[1].js

    The antivirus clean it (at least is what it shows me) but after appears again...Is the PC being infected by the "source" where is the virus? like the moden?

    i dont know what to think anymore! heheheheeh!!
     
    Last edited: Aug 8, 2008
  17. MaDeInRiO

    MaDeInRiO Private E-2

    sorry.. so many question...but, if its not in the line....do you have any idea where is it coming from??
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But as as I said in my last message
    This means it may or may not be in the equipment in your home or office. You stated when you moved the problem PC from one location to another, that the problem did not exist. If you are connecting the PC to a different network and the problem does not occur then it is not in the PC. It is somewhere outside of the PC. Anything else in the connection path way like router, switch, cable modem (on your end) and network equipment of your ISP or websites that you are connecting to could be the source of the problem. If the PC gets the javascript file (the day.js file) back when reconnected to the original network then you need to look at something related to the original network and pathways..
     
  19. MaDeInRiO

    MaDeInRiO Private E-2

    ok.

    today i will do another test here....i will turn all computer of my network off...so i will discover if are they...correct?

    thanks..see u!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are missing the point. The problem may well be outside of your own computers and equipment.

    Also which network are you referring to?
    Are you talking about your home network where the problem did not occur?
    Or are you talking about what you call a "LanHouse" which is where the problem did occur?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds