Reply
Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: GOOGLE REDIRECTS TO http://abnow.com

Symantec should not be running realtime protection in safe Mode so that is OK.

 

Don't forget to do the dropping of the script.txt on top of Combofix this time.

 

Quads

Contributor
shevo11
Posts: 93
Registered: ‎03-14-2012

Re: GOOGLE REDIRECTS TO http://abnow.com

THE LOG.

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: GOOGLE REDIRECTS TO http://abnow.com

Run the ESET online scanner like last time.

 

Quads

Contributor
shevo11
Posts: 93
Registered: ‎03-14-2012

Re: GOOGLE REDIRECTS TO http://abnow.com

The eset log.

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: GOOGLE REDIRECTS TO http://abnow.com

Turn off System Restore and leave it turned off

 

As you can see zeroaccess is in the System Restore

 

Find this folder and delete it  C\Documents and Settings\admin\Configuración local\Datos de programa\69c3a23e

 

Then delete this folder C:\Qoobox

 

I am not sure what to do with Symantec and whether it's up to standard with stopping this or not I have never used it to compare to Norton Internet Security.

 

One other thing is has been found that that malware can come in via emails, so if you or others have strange looking emails delete them completely,  

 

Quads

Contributor
shevo11
Posts: 93
Registered: ‎03-14-2012

Re: GOOGLE REDIRECTS TO http://abnow.com

Questions

 

1) I have to leave off system restore until when? forever or what you suggest?

2) I can't remove Qoobox folder because one folder in it that's called Backenv, i 'm doing this in normal mode, what would you suggest to eliminate it?

3) When you say emails you are reffering to hotmail inbox mails? I never open that emails, but you say that by having it closed without opening them the virus can attack anyways?

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: GOOGLE REDIRECTS TO http://abnow.com

1) Say for 2 - 3weeks

 

2)  That's OK I will get it at a later date, once we know you haven't got it back for a 4th time.

 

3) These groups like zeroaccess are infecting PC's in many ways, including ads in websites and Java, and the evil creators are still active and update the malware all the time.

 

Manually Live update Symantec and Malwarebytes making sure the updates are installed and run scans every day for now.

 

Quads

Contributor
shevo11
Posts: 93
Registered: ‎03-14-2012

Re: GOOGLE REDIRECTS TO http://abnow.com

Since your last post i desactivated system restore and no virus were found. Should i turn system restore on or before you want some logs from some programs?

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: GOOGLE REDIRECTS TO http://abnow.com

[ Edited ]

If your PC is still running fine, you can turn System Restore back on.    Just keep updating malwarebytes every day to back sure you have definition updates.  and please don't get any more variants of Zeroaccess etc., you were getting them faster then I was.

 

Just need a new OTL log  Change the file age to 90 days instead of 60days like the last instructions

 

Quads

Contributor
shevo11
Posts: 93
Registered: ‎03-14-2012

Re: GOOGLE REDIRECTS TO http://abnow.com

I don't have malewarebytes, is it freeware?

 

Here's the log.

 

I will wait some mroe days to turn on the system restore, it changes something very important to turn it on?