My computer was hijacked to:
hxxp://mega-antiviral-ms.com/200099/scan/
I stopped it as soon as I saw it and no page loaded.
I looked up the url in NetLab which reported the IP as 78.26.179.131, in the Ukraine.
My firewall, and an updated version of TrojanHunter was running, but I had temporally killed avast home for speed. A “quick scan” with TrojanHunter after the hijack found nothing:
Registry scan
No suspicious entries found
Inifile scan
No suspicious entries found
Port scan
No suspicious open ports found
Memory scan
No trojans found in memory
File scan (autostarted files, running executables)
No trojan files found
I have to leave for an appointment and am afraid to leave the computer on while I’m gone (though perhaps I will unleash something when I next boot up …)
I will scan with Avast when I return.
Is there anything else I should do?
Does anyone have any experience about this url and ip? I found nothing through a google search.
Thanks for any help.
Ellen
NetLab Report:
% Information related to ‘78.26.161.0 - 78.26.191.255’
inetnum: 78.26.161.0 - 78.26.191.255
netname: RENOME-SERVICE
descr: Renome-Service: Joint Multimedia Cable Network
country: UA
admin-c: RSM-RIPE
tech-c: RSM-RIPE
status: ASSIGNED PA
mnt-by: RENOME-MNT[/center][/left]
mnt-lower: RENOME-MNT
mnt-routes: RENOME-MNT
source: RIPE # Filtered
role: Renome Service Tech Staff
address: Kosvennaya str., 78, Odessa, Ukraine, 65000
org: ORG-RA159-RIPE
phone: +380487597596
fax-no: +380487597596
mnt-by: RENOME-MNT
abuse-mailbox: abuse@odessa.tv
admin-c: WU-RIPE
admin-c: GA-RIPE
tech-c: WU-RIPE
nic-hdl: RSM-RIPE
source: RIPE # Filtered
% Information related to ‘78.26.128.0/18AS34187’
route: 78.26.128.0/18
descr: Renome-Service: Joint Multimedia Cable Network
remarks: Renome-Service: Aggregated Route
org: ORG-RA159-RIPE
origin: AS34187
member-of: RS-RENOME
mnt-by: RENOME-MNT
source: RIPE # Filtered
organisation: ORG-RA159-RIPE
org-name: Renome-Service
org-type: LIR
descr: Renome-Service: Joint Multimedia Cable Network
address: Renome Service
Andrew Gaidulyan
Kosvennaya str., 78
65000 Odessa
UKRAINE
phone: +3 80487597596
fax-no: +3 80487597596
abuse-mailbox: abuse@odessa.tv
admin-c: GA-RIPE
admin-c: WU-RIPE
admin-c: WU-RIPE
mnt-ref: RENOME-MNT
mnt-ref: RIPE-NCC-HM-MNT
mnt-by: RIPE-NCC-HM-MNT
source: RIPE # Filtered