onlinevirusscanner.info exploit and system restore

Discussion in 'Malware Help (A Specialist Will Reply)' started by deadred6, Feb 9, 2009.

  1. deadred6

    deadred6 Private E-2

    Yesterday I boot up by computer and after load-up I was immediately asked to allow winlogon notifier to be added as a value by AVG by spybotSD. I thought this was strange because I don't allow auto downloading and I just turned the computer on and I hadn't downloaded anything but I decided to allow it. The first strange thing I noticed was trying to connect to anonib I get an "internet explorer cannot connect to that site even thought it had connected and was showing the site. Then I got an AVG popup that said rogue exploit onlinevirusscanner.info/21 and listed iexplore.exe as being compromised. I try to system restore to a previous time and it goes through all the motions only to boot up and say it could not restore. It is enabled I have checked it. i tried it in safe mode - same thing happened. I ran Spydot SD, MBAM, AVG, and Super antivirus and nothing came up. I noticed when I would try to run these programs the run button would act like I never clicked on it and had to do it again. When I click on internet explorer sometimes my firewall has a message come up that I am trying to go to two diff IP addresses - one of them is 65.55.195.253. Now (today) I can't get the next button to work in the confirm restore date screen ( the very last one before it reboots) - it acts like it was never touched.

    I have followed the steps you listed and have attached my logs - please help
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Your logs are all clean, but you forgot to attach the log from ComboFix. I tend to doubt it will show anything though since your other logs are all clean. The only problem I see is that you have no antivirus program installed even though you mention AVG a couple of times.

    And the 65.55.195.253 IP address is Microsoft and not a problem.
     
  3. deadred6

    deadred6 Private E-2

    Here is combofix. I had to remove AVG to run one of the programs you wanted me to because it was saying it couldn't run with an antivirus running in the background. Shutting AVG down didn't do the trick as I had several AVG exe's running after shutdown.

    Yesterday my Window's defender was removed from startup - or it is being blocked from starting.

    My system restore is making new restore points I just can't go to any of them.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is also clean.

    Only the service for Windows Defender is showing, perhaps you disabled it before you came here because nothing in our procedures do anything to Windows Defender and as you can see from your logs, nothing was removed.

    With no malware being present, this is more of a problem for the Software Forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds