Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Problem with "welcome to nginx" and website logins  (Read 16045 times)

0 Members and 1 Guest are viewing this topic.

SuperDave

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: Problem with "welcome to nginx" and website logins
« Reply #15 on: April 02, 2012, 12:48:23 PM »
Quote
I changed it back to att.my.yahoo.com to see if the nginx still comes up and it does.
This and this is what I know about nginx

We should do some cleanup

StartupLite

Download StartupLite by MalwareBytes to your Desktop.
Doubleclick StartupLite.exe to launch the program.
Ensure the Disable box is checked.
Click Continue.
A pop up message will tell you the unecessary startup items in your list have been disabled and ask you to restart your computer.
Re-start your computer.
********************************************************
To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
******************************************************
To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
  • Click the CleanUp button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
***********************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
*******************************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
Windows 8 and Windows 10 dual boot with two SSD's

pbfoot

    Topic Starter


    Rookie

    Re: Problem with "welcome to nginx" and website logins
    « Reply #16 on: April 04, 2012, 08:33:10 PM »
    When I try to run TFC, my PC freezes. I've let it sit for over 30 minutes and the desktop goes away but just freezes up. Malwarebytes captured this in it's log tonight and I had it quarantined:


    2012/04/04 06:46:06 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   Executing scheduled update:  Daily
    2012/04/04 06:46:54 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   Scheduled update executed successfully:  database updated from version v2012.03.31.14 to version v2012.04.04.02
    2012/04/04 06:46:54 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   Starting database refresh
    2012/04/04 06:47:00 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   Database refreshed successfully
    2012/04/04 19:54:33 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   Starting protection
    2012/04/04 19:54:57 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   Protection started successfully
    2012/04/04 19:55:00 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   Starting IP protection
    2012/04/04 19:55:05 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   IP Protection started successfully
    2012/04/04 20:11:52 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   Starting protection
    2012/04/04 20:12:19 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   Protection started successfully
    2012/04/04 20:12:22 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   Starting IP protection
    2012/04/04 20:12:26 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   IP Protection started successfully
    2012/04/04 20:14:58 -0500   PEARSON-HOME-PC   Administrator   DETECTION   C:\Documents and Settings\Administrator\My Documents\Downloads\B.tmp   Trojan.Dropper.PGen   QUARANTINE
    2012/04/04 20:25:21 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   Starting protection
    2012/04/04 20:25:39 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   Protection started successfully
    2012/04/04 20:25:42 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   Starting IP protection
    2012/04/04 20:25:46 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   IP Protection started successfully
    2012/04/04 20:33:11 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   Starting protection
    2012/04/04 20:33:37 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   Protection started successfully
    2012/04/04 20:33:40 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   Starting IP protection
    2012/04/04 20:34:00 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   IP Protection started successfully
    2012/04/04 20:34:00 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   Stopping IP protection
    2012/04/04 20:34:00 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   IP Protection stopped
    2012/04/04 21:19:29 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   Starting protection
    2012/04/04 21:19:52 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   Protection started successfully
    2012/04/04 21:19:55 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   Starting IP protection
    2012/04/04 21:20:20 -0500   PEARSON-HOME-PC   Administrator   MESSAGE   IP Protection started successfully

    When I go that downloads folder I do not see this b.temp file, I went into Malwarebytes and deleted it there.
     
    At this point I'm ready to dump Chrome and go back to Explorer unless you have any other ideas. I thank you for your time over these past few weeks!

    SuperDave

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: Problem with "welcome to nginx" and website logins
    « Reply #17 on: April 05, 2012, 12:20:17 PM »
    Quote
    When I try to run TFC, my PC freezes. I've let it sit for over 30 minutes and the desktop goes away but just freezes up.
    TFC will do that sometimes. Just do a disk cleanup instead. Double-click on My Computer, right-click on the C drive and select Disk cleanup.
    Quote
    At this point I'm ready to dump Chrome and go back to Explorer unless you have any other ideas.
    I don't know too much about Chrome but FireFox is reputed to be a safer browser.
    Windows 8 and Windows 10 dual boot with two SSD's

    pbfoot

      Topic Starter


      Rookie

      Re: Problem with "welcome to nginx" and website logins
      « Reply #18 on: April 05, 2012, 03:34:04 PM »
      Ok I'll do the disk cleanup. Thanks again for all your help!

      SuperDave

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: Problem with "welcome to nginx" and website logins
      « Reply #19 on: April 06, 2012, 04:40:34 PM »
      You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
      Windows 8 and Windows 10 dual boot with two SSD's