Go Back   Hardware Canucks > PC BUILDERS & TWEAKERS CORNER > Troubleshooting

    
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old December 26, 2012, 07:31 PM
biff's Avatar
Hall Of Fame
F@H
 
Join Date: Jan 2008
Location: Courtice, Ont.
Posts: 1,235
Default Am I dealing with a virus here?

Over at my sister-in-laws and she asked me to look at her toshiba lappy. It wasn't doing much of anything and they couldn't get it to boot. I muddled around with it and got it booting just fine but TBH I really never found the exact reason for the problem. Though I'm not sure if this is related to the problem I'm asking about or not.

They run IE and using the computer there was a bunch of junk an popups coming up but it doesn't look like popups should (if that makes sense). Wanting to do my own surfing without all the extra crap I wanted to install google chrome - since all my bookmarks will be there, etc.. According to IE everything 'google' is dead and I get a 404 error with a "nginx" signature below that. Finally found it from another site and got a clean chrome going and it still has the same popups and all google sites are still dead. Looking at the address bar where google appears to work in IE shows the is an extra bit, shows as "https://encrypted.google.com/". Never seen that before. FWIW google works just fine on any other device in the house.

I thought maybe AVG was acting up. I put in on here a while ago before it got all bloatty, so I uninstalled it and put on MSE. Its what I use for the time being as it seems fairly clean. Anyway, it shows it installed and does a scan and shows nothing but it also doesn't show in the taskbar on the lower right and TBH I cant find anything of it to show it ever really installed. I tried a free online malware scanner and it installed and scanned and showed there were about 6 instances of trojans and worms but when I go to clean it asks me to purchase it. So hard to say I trust it found anything real as it just may be a ploy to purchase their software. I downloaded an MS malware scanner and when I click on it to install it doesn't do anything.

So opinions? Is it some malware/virus or is there some other direction I should be looking?
__________________
Q6600 @ 3.83GHz w/ D-Tek Fusion
Asus P5Q-PRO
2x 2GB PC8000 Mushkin Redlines @ 1020MHz w/5-5-5-12 timings
EVGA GTX 280 (SC?)
OCZ Gamer Xtreme 600W PSU
Cooler Master Cosmos on water
Reply With Quote
  #2 (permalink)  
Old December 26, 2012, 07:40 PM
enaberif's Avatar
Hall Of Fame
 
Join Date: Dec 2006
Location: Calgahree, AB
Posts: 10,604
Default

ComboFix that sucker. Sounds like you probably got something installed and it changed your proxy settings. So go into Control Panel -> Internet Options -> Connections -> LAN Settings

Make sure you proxies are set.
Reply With Quote
  #3 (permalink)  
Old December 26, 2012, 07:41 PM
Galcobar's Avatar
MVP
 
Join Date: Dec 2009
Location: Richmond, B.C.
Posts: 437

My System Specs

Default

Check Task Manager -- bet you'll find processes running which shouldn't be there.

I would suggest to use another computer to download and install Malwarebytes to a USB drive, then take that USB drive to the seemingly infected computer. This way the malware, if there is any, can't block installation.
Reply With Quote
  #4 (permalink)  
Old December 26, 2012, 07:42 PM
sswilson's Avatar
Moderator
F@H
 
Join Date: Dec 2006
Location: Moncton NB
Posts: 14,521

My System Specs

Default

First thing I'd look for would be what dns server is being used, and I sure wouldn't trust a "free" scanner that wanted me to pay money after it "found" some nasties.
__________________
MSI Z87I Gaming AC / i5 4670K / 2X 4G Gskill 1866 DDR3 / XFX XTR 750 / EVGA GTX 680 SC+ 2GB / Intel DC S3700 200G / random 160G Sata HDD
Inwin 904 / Swiftech MCP655-b / Alphacool NexXxos XT45 120 Rad / 2X Scythe GT AP-15 / EK Supreme HF / Dell UltraSharp U2412M

Asrock AM1H-ITX / AM1 Athlon 5350 / 2X4G Gskill PC3-14900 / Intel 6235 Wi-Fi / 90W Targus Power Brick / 320G Seagate Momentus / Mini-Box M350 / 1X 22" Dell IPS / 1X 22" HP
Reply With Quote
  #5 (permalink)  
Old December 26, 2012, 08:16 PM
biff's Avatar
Hall Of Fame
F@H
 
Join Date: Jan 2008
Location: Courtice, Ont.
Posts: 1,235
Default

Thanks for all the responses! Makes me feel better that there is actually something going on and not just a DFU problem on my part. Now, this is kind of new territory for me. I tried googling the problem and found the suggestions for 'ComboFix' but googling that I got into that 'free' scanner which I dont trust as sswilson states. But I don't really know what ComboFix is specifically addressing. Do you have any links for me?

Also I've really not dealt with proxy or DNS settings directly so I'm not sure I would be able to tell if something is fishy or not. Also for services, again I've brushed by it a few times in the past but don\t really know what to look for. Starting to feel like a newb again. :-)

[edit]not sure I can check processes as task manager wont run[/edit]

Thanks again!
__________________
Q6600 @ 3.83GHz w/ D-Tek Fusion
Asus P5Q-PRO
2x 2GB PC8000 Mushkin Redlines @ 1020MHz w/5-5-5-12 timings
EVGA GTX 280 (SC?)
OCZ Gamer Xtreme 600W PSU
Cooler Master Cosmos on water
Reply With Quote
  #6 (permalink)  
Old December 26, 2012, 08:24 PM
Lpfan4ever's Avatar
Hall Of Fame
F@H
 
Join Date: Sep 2008
Location: Calgary
Posts: 2,763

My System Specs

Default

Here's the link to downlaod ComboFix: ComboFix Download

And a more detailed list of instructions: ComboFix: A guide and tutorial on using ComboFix
__________________
Quote:
Originally Posted by encorp
I don't know, maybe if you get a big enough compacticator you can put it in your butt and name yourself "sexbuttplug"...
Code:
<martin_metal_88> I think I am gonna sell my server
...
<firebane> i will offer pereniums mom
<firebane> slightly used
<Keltron> slightly is an understatement
<LPfan4ever> Who're you kidding...slightly?
<martin_metal_88> peri's mom, slightly used? lol...

Reply With Quote
  #7 (permalink)  
Old December 26, 2012, 08:46 PM
enaberif's Avatar
Hall Of Fame
 
Join Date: Dec 2006
Location: Calgahree, AB
Posts: 10,604
Default

ComboFix is probably the one best free program to run in Safe Mode with Networking as they keep up to date on all the weird and strange crap out there.

Its my go to program whenever I suspect an infection of a system first.
Reply With Quote
  #8 (permalink)  
Old December 26, 2012, 09:16 PM
Hall Of Fame
F@H
 
Join Date: Feb 2010
Location: Markham
Posts: 1,569

My System Specs

Default

Quote:
Originally Posted by biff View Post
Also I've really not dealt with proxy or DNS settings directly so I'm not sure I would be able to tell if something is fishy or not. Also for services, again I've brushed by it a few times in the past but don\t really know what to look for. Starting to feel like a newb again. :-)

[edit]not sure I can check processes as task manager wont run[/edit]

Thanks again!
For checking DNS settings open up a command line and use "ipconfig /all"

If it's not the IP of their router/modem or their ISP's default something's probably wrong. If it's the router/modem check its DNS settings page.

Task manger not running is a bad sign though.
__________________
Reply With Quote
  #9 (permalink)  
Old December 26, 2012, 10:19 PM
biff's Avatar
Hall Of Fame
F@H
 
Join Date: Jan 2008
Location: Courtice, Ont.
Posts: 1,235
Default

Started reading the ComboFix instructions and got a couple pages in and gave up.... but that's pretty good for me. So I just ran it. It did it's thing and spit out a pretty big log file which appeared that it found a lot of stuff. I rebooted and now the browsers can actually load google.ca (or .com) and MSE is now showing in the taskbar on the lower right. Task manager works too. All good signs. Putting some stuff through it's paces now to make sure all is good but so far it looks good. So what's the cause here? was it a virus? Should I post the log file to diagnose it? Just trying to learn something so I can help prevent this kind of thing in the future.

Thanks for helping me fix this!
__________________
Q6600 @ 3.83GHz w/ D-Tek Fusion
Asus P5Q-PRO
2x 2GB PC8000 Mushkin Redlines @ 1020MHz w/5-5-5-12 timings
EVGA GTX 280 (SC?)
OCZ Gamer Xtreme 600W PSU
Cooler Master Cosmos on water
Reply With Quote
  #10 (permalink)  
Old December 26, 2012, 10:24 PM
Lpfan4ever's Avatar
Hall Of Fame
F@H
 
Join Date: Sep 2008
Location: Calgary
Posts: 2,763

My System Specs

Default

If you posted the log I could probably get an idea of what it was.
__________________
Quote:
Originally Posted by encorp
I don't know, maybe if you get a big enough compacticator you can put it in your butt and name yourself "sexbuttplug"...
Code:
<martin_metal_88> I think I am gonna sell my server
...
<firebane> i will offer pereniums mom
<firebane> slightly used
<Keltron> slightly is an understatement
<LPfan4ever> Who're you kidding...slightly?
<martin_metal_88> peri's mom, slightly used? lol...

Reply With Quote
Reply


Thread Tools
Display Modes

Similar Threads
Thread Thread Starter Forum Replies Last Post
So... i had a virus? bliz Off Topic 16 October 25, 2012 09:21 AM
Advice dealing with an ebay seller krajee Off Topic 3 April 7, 2011 02:03 AM
Do I have a virus? NineLives Troubleshooting 7 August 25, 2010 12:00 PM
Help Dealing with a Crook and a Bad Trader! Nademon Off Topic 86 April 30, 2009 09:47 AM
Way OT: Dealing with back injuries Ging9 Off Topic 14 March 25, 2009 07:15 PM