Reply
Service Expert
Moms_hooked
Posts: 4,108
Registered: ‎11-16-2003

Virus from Google Search

Yesterday I about had a heart attack!  While doing a Google Search for history on stainless steel flatware that was in the family I clicked on a site...and bam...attacked by a virus :smileysad:.  Didn't think to use the Task Mgr to close just frantically hit the Close while my computer was showing all bells and whistles to let me know I was in trouble.  Didn't even think to do a PrtScn...grrrr.  Ran a Quick Scan with Avast Free 5 and it indicated:  C:\ProductTour.exe  Severity High...Threat: Win32:Malware-gen.   I had it moved to the Chest.  Avast then asked if I wanted a BootScan...and I clicked Yes.  Sheesh...several things found including:  

1.  ... Application Data\Sun\Java\Deployment\  cache  .......  \ goog\main.class is infected by Java : Agent - BW  [ Trj ]

 

2.  ... Application Data\Sun\Java\Deployment\  cache .......  \ YAHO . class is affected by Java : Jade.A  [ Heur ]

 

3. One I accidentally deleted from my camera as I was trying to increase the size so I could type it in an email after everything was safe.  It indicated the Epson printer... spooldriver was corrupted and I don't remember what else it said.  Can't figure out how to get to the log for the BootScan.

 

Ran Malwarebyte's Full Scan after everything was moved to the Avast Chest and it turned up clean.

 

My Safely Remove Hardware icon is missing from my Task Mgr Notification area.  I had a problem with this last week too...so am wondering if I had something then too...but wasn't alerted by Avast or Malwarebytes.

 

Also wondering which program is best to install for Searching sites...McAfee SiteAdvisor...or Norton's Safe Web program?

 

Moms...

 

(XP IE8, Avast Free 5, Malwarebyte's 1.50.1.1100, Windows Defender 1.1.1593.0) 

 

Service Expert
USAF_E-8_RET
Posts: 4,268
Registered: ‎10-28-2003

Re: Virus from Google Search

Moms,

Let's wait and see what LPP suggests, but just some info.  If you go with Norton, Windows Defender will be turned off and MalwareBytes should not be run real time (on demand scanner is fine).  Norton IMHO does a better job than Windows Defender

FWIW, I am running Norton Internet Secuirty 2011 on my Win 7 system (paid version) and Norton Secuirty Suite from Comcast on my XP system and I am very pleased with their performance.  I have also heard good things about Microsoft Security Essentials (freebie).

A veteran - whether active duty, retired, national guard, or reserve - is someone who, at one point in his or her life, wrote a blank check made payable to The 'United States of America', for an amount of 'up to and including my life.'

Security Expert
LoPhatPhuud
Posts: 2,619
Registered: ‎11-01-2005

Re: Virus from Google Search

[ Edited ]

This is my standard response for exploits...

 

I suggest you follow the instructions here:
http://www.dslreports.com/faq/13616
 

When you have the required logs, post  them here:
http://www.dslreports.com/forum/cleanup

 

Note that membership at DSLR is not required to post logs in the SCU forum, but it is highly recommended.

 

 

I'll be watching for the logs at DSLR.

 

And don't install anything until you are certain you're computer is clean. While MBAM is an excellent program and on my recommended list, it does not catch everything. Some of the rootkits need other programs.



"Once I talked to the inmates of an insane asylum in Hartford. I have talked to idiots a thousand times, but only once to the insane..."
Mark Twain

Microsoft MVP, Consumer Security, 2005-2012
Service Expert
Moms_hooked
Posts: 4,108
Registered: ‎11-16-2003

Re: Virus from Google Search

LPP...I won't be home long enough this weekend to do this at one time.  I probably won't be able to post until Monday  (new baby in our extended family).  I've never had to do anything like this...: (.  Do you want me to send you a PM or just post here when I'm ready over on DSL?

 

Assuming that you want me to keep the files in the Avast Chest for now...and not download either program mentioned above to help protect me from nasty virus filled websites that I clicked while doing a Google Search.

 

Thank you!

Moms...

 

(E-8...thanks for your input : ).)

Security Expert
LoPhatPhuud
Posts: 2,619
Registered: ‎11-01-2005

Re: Virus from Google Search

No need to post here. Just run the programs and post the logs at DSLR. I check there several times a day.



"Once I talked to the inmates of an insane asylum in Hartford. I have talked to idiots a thousand times, but only once to the insane..."
Mark Twain

Microsoft MVP, Consumer Security, 2005-2012
Service Expert
Moms_hooked
Posts: 4,108
Registered: ‎11-16-2003

Re: Virus from Google Search

Just read through all that I am to do and will start on this tomorrow evening.

 

I am using Malwarebyte's 1.50.1.1100 and have used it for quite awhile.  How do I know if I have it set to Default?  Directions say..."When the installation begins, follow the prompts and do not make any changes to default settings."  I noticed when going through the settings that one item is unchecked...under General Settings...'Terminate IE during Threat removal.'  Also under Scanner Settings...PUP is on 'Show results list and do not check for removal'....PUM is on 'Show results list and check for removal'.

 

Also in my Quarantine I have 2 Trojan.Agent registry keys sitting there from 3-1-09.  Guess I forgot about those so it's safe to say I can delete them by now :smileyhappy:.

 

Moms...

Security Expert
LoPhatPhuud
Posts: 2,619
Registered: ‎11-01-2005

Re: Virus from Google Search

If you have MBAM installed the only thing to do is make sure you have the most recent definitions, then run the program.

 

Yes, you can delete items in quarantine that old.



"Once I talked to the inmates of an insane asylum in Hartford. I have talked to idiots a thousand times, but only once to the insane..."
Mark Twain

Microsoft MVP, Consumer Security, 2005-2012
Service Expert
Moms_hooked
Posts: 4,108
Registered: ‎11-16-2003

Re: Virus from Google Search

[ Edited ]

LPP...I have all of the scans done..and posted the MBAM over at DSL (Edit to correct)  Just figured out how to add other context...heading back over.

Can't figure out how to correct the time as it shows 3hrs ahead...and I entered my Zipcode upon registering.

 

Thanks for your help!

Moms...

Security Expert
LoPhatPhuud
Posts: 2,619
Registered: ‎11-01-2005

Re: Virus from Google Search

I'll be over a DSLR in little bit to check out the logs.



"Once I talked to the inmates of an insane asylum in Hartford. I have talked to idiots a thousand times, but only once to the insane..."
Mark Twain

Microsoft MVP, Consumer Security, 2005-2012
Service Expert
Moms_hooked
Posts: 4,108
Registered: ‎11-16-2003

Re: Virus from Google Search

Love having our forum and wonderful Experts!  Thanks to LPP for making sure my computer was clean :smileyhappy:.  Now on to adding a couple of good programs to help keep it from happening again!

 

Moms...

Bronze Problem Solver
lunski
Posts: 1,757
Registered: ‎09-03-2008

Re: Virus from Google Search

Hello moms :smileyhappy:

 

I thought I would just share my personal setup.

 

1) OpenDNS (Web Filtering @ Moderate "Protects against all adult-related sites, illegal activity, social networking sites, video sharing sites, and general time-wasters." http://www.opendns.com

 

2) Microsoft Security Essentials (set to scan all inbound and outbound items/drives) http://www.microsoft.com/security_essentials

 

3) Google Chrome (i use liberkey.com portable version, but listed three links below)

 

4) The following Google Chrome extensions

 

 

 That's It :smileyhappy:

 

 

For 'testing' I use VMWare Server @ http://www.vmware.com/products/server/

 

Primarily I use Acronis True Image Home 2011 for quick tests @ http://www.acronis.com/homecomputing/products/trueimage/index.html

 

This is all done a Windows 7 x 64 Ultimate :smileyhappy:

 

Stay Safe Everyone & Enjoy the Internet!

George Lunski
"Retired" Comcast Help Forums Administrator
Service Expert
Moms_hooked
Posts: 4,108
Registered: ‎11-16-2003

Re: Virus from Google Search

Thanks George!  I'm going to install WOT and perhaps add SiteAdvisor later.  I have Norton's Web Safe on FB but reading a little on Open DNS leads me to think it would be a wise selection since it also protects social sites. I'd use the Free version...but need to understand more about it. 

 

Keeping Avast for now and will save the link to MSE to consider later. Also will read up on Acronis...have seen it mentioned before but know nothing about it.

 

Will these all work for my husband's email too as he uses my computer?

 

(XP IE8, Avast Free 5, Windows Firewall, Malwarebyte's 1.50.1.1100, Windows Defender 1.1.1593.0) 

Bronze Problem Solver
lunski
Posts: 1,757
Registered: ‎09-03-2008

Re: Virus from Google Search

 


Moms_hooked wrote:

Thanks George!  I'm going to install WOT and perhaps add SiteAdvisor later.  I have Norton's Web Safe on FB but reading a little on Open DNS leads me to think it would be a wise selection since it also protects social sites. I'd use the Free version...but need to understand more about it. 

 

Keeping Avast for now and will save the link to MSE to consider later. Also will read up on Acronis...have seen it mentioned before but know nothing about it.

 

Will these all work for my husband's email too as he uses my computer?

 

(XP IE8, Avast Free 5, Windows Firewall, Malwarebyte's 1.50.1.1100, Windows Defender 1.1.1593.0) 


 

Hi Moms,

 

There might be a few tweaks for various sites including email, mostly around AdBlock.. But you should have no issues. OpenDNS could also cause a issue, but unlikely...

George Lunski
"Retired" Comcast Help Forums Administrator
Service Expert
Moms_hooked
Posts: 4,108
Registered: ‎11-16-2003

Re: Virus from Google Search

I still use SmartZone for email.  Tried to figure out how to do a 'Backup' but so far am pretty confused...probably because I was reading to much into it at 3AM.  I don't have it on my XP and think my WD Portable Passport might not be large enough.  It's an older model and might only be 190GB.  Knowing what Mady has to do to her computer makes me think I'm going to have to make some serious changes here sometime in the not to distant future.

 

(XPHome, IE8, Avast Free 5, Windows Firewall, Malwarebyte's 1.50.1.1100, Windows Defender 1.1.1593.0 and WOT)