Avast WEBforum

Other => General Topics => Topic started by: Avastfan1 on May 10, 2009, 11:49:33 PM

Title: Infections from agoga.com?!?!?!?!?!
Post by: Avastfan1 on May 10, 2009, 11:49:33 PM
Dear Avast Forum,

Is my computer infected? Should I run the full battery of tests?

Accidentally typed in hxxp://www.google.cm instead of www.google.com and Avast Network Shield blocked access to hxxp://www.agoga.com.

I realise the block was a good thing. Quick google search of the domain seems to be riddled with spyware.

Should I run the full arsenal of tests to see if there is any damage?
- Avast boot time scan
- MBAM full scan
- SAS full scan
- Spyboy full scan
- ZoneAlarm Anti-Spyware full-scan
- HijackThis log

Thanks in advance for your help!

Avastfan1
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: DavidR on May 11, 2009, 12:03:11 AM
If the network shield blocked access I don't believe you have a problem as it shouldn't have activated anything. To reassure yourself it won't hurt to do the first three.

Given that, please modify your post and change the www to wXw.google.cm  to break the link so it isn't active, avoiding accidental exposure.

Interestingly for me the .google.cm doesn't redirect to anywhere other than .google.com and the reason for that I'm sure is down to my using the OpenDNS.ors DNS servers as it tries to correct obvious typos, so I would also suggest you pay a visit to OpenDNS.
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: Avastfan1 on May 11, 2009, 12:06:30 AM
Hi,

Thanks for the reply. Post has been modified. I'll check out the OpenDNS.

Regards,

Avastfan1


Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: DavidR on May 11, 2009, 12:22:20 AM
You're welcome, I wouldn't be without OpenDNS as they too have phishing/malicious site blocking too.
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: bob3160 on May 11, 2009, 06:31:23 AM
I've been singing it's praises since July of 2006.
It protects my whole network since the router determines the networks connection.
http://forum.avast.com/index.php?topic=16849.msg185494#msg185494 (http://forum.avast.com/index.php?topic=16849.msg185494#msg185494)
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: Avastfan1 on May 13, 2009, 11:46:30 PM
Hi,

Sorry for the delayed reply. I had a lot to do at work for the last few days.

1. Avast boot-time scan all files: No infected files found
2. MBAM full scan: No infections found
3. SAS complete scan: No infections found

Excuse my stupid question but how secure are the servers at OpenDNS? Is it a tried and tested product / company?

Would really appreciate expert advice from you lads before a newbie like me starts mucking around with it.

Thanks in advance!

Avastfan1
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: DavidR on May 13, 2009, 11:51:45 PM
We wouldn't be recommending or using OpenDNS ourselves if it weren't.
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: bob3160 on May 14, 2009, 01:36:04 AM
If it wasn't reliable, it would long have been gone.
I've used it since 2006 as noted in the link I provided.
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: Avastfan1 on May 14, 2009, 12:23:07 PM
Hi Bob and DavidR,

Thanks for the replies. It's clear that you are both OpenDNS fans. However have you experienced any issues or problems with the service? Has OpenDNS reduced your internet connection speed?

Would appreciate hearing from your practical experience with OpenDNS.

Thanks!

Avastfan1
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: YoKenny on May 14, 2009, 01:06:15 PM
Hi Bob and DavidR,

Thanks for the replies. It's clear that you are both OpenDNS fans. However have you experienced any issues or problems with the service?
No problems for me.

Quote
Has OpenDNS reduced your internet connection speed?
Not that I have noticed in fact it might have speeded it up.

I do notice that it blocks sites that it knows about that are malware sites but I don't have a sample right now.
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: DavidR on May 14, 2009, 04:49:00 PM
Hi Bob and DavidR,

Thanks for the replies. It's clear that you are both OpenDNS fans. However have you experienced any issues or problems with the service? Has OpenDNS reduced your internet connection speed?

Would appreciate hearing from your practical experience with OpenDNS.

It is so good, you don't know it is there (until it alerts/blocks a site or corrects a typo you made in a URL or offers suggestions if a site isn't found), it doesn't get in the way or impede my blisteringly hot dial-up connection :P
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: Avastfan1 on May 14, 2009, 06:58:17 PM
Hello All,

Thanks for the advice. I followed the installation instructions on the website.

How can I test that it is active and working?

As you all predicted I don't notice any difference.

Thanks,

Avastfan1
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: DavidR on May 14, 2009, 07:34:02 PM
I haven't got any site to suggest as I don't record those that were blocked I just know it that it did work in that regard.
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: Avastfan1 on May 15, 2009, 01:03:05 AM
Hello Forum,

Thanks for the responses.

Are there any security concerns with the data passing through the OpenDNS servers?

For example passwords being extracted?

Best wishes,

Avastfan1
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: bob3160 on May 15, 2009, 01:45:29 AM
Quote
For example passwords being extracted?
Do you really think that we would all still be using the service if there was even a hint
of that kind of activity ???
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: DavidR on May 15, 2009, 01:55:45 AM
<snip>
Are there any security concerns with the data passing through the OpenDNS servers?

For example passwords being extracted?
<snip>

What assurances do you have of your existing DNS server (none), do you even know who operates it (you probably don't know).

So when you answer both those responses then ask yourself the same about an Organisation that you do know who are committed to protection from malware and if you set it up parental controls, etc. There really is no contest.

Recently there was a DNS server issue where many were being exploited by malware, and there are still many that are vulnerable to exploit, but guess what OpenDNS never was they have been ahead of the curve in that regard.

That is my last on the issue, you can lead a horse to water but they have to want to drink, your choice.
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: YoKenny on May 15, 2009, 09:59:04 AM

That is my last on the issue, you can lead a horse to water but they have to want to drink, your choice.
You can lead a horse to water but you can't make it think.
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: Avastfan1 on May 15, 2009, 02:58:11 PM
Hi Bob3160 and DavidR,

Thank you again for your contributions. Compared to one plonker on this board you have both demonstrated kindness, patience and a professional approach.

OpenDNS is now up and running and appears to be working well.

I wish you both a very relaxing weekend.

Best regards,

Avastfan1
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: bob3160 on May 15, 2009, 10:46:33 PM
Quote
I wish you both a very relaxing weekend.
I hope you'll also enjoy yours.  :)
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: !Donovan on May 17, 2009, 01:44:46 AM
Here is some extra information about the site:

hXXp://www.google.cm redirects you to hXXp://login.tracking101.com/sw/83574/CD15759/ (See picture for proof) and when I try viewing the source of hXXp://login.tracking101.com/sw/83574/CD15759/ it says unable to access the website.
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: DavidR on May 17, 2009, 02:18:06 AM
Well if you have OpenDNS as your DNS server (what the later half of this topic has been about), it redirects nowhere it corrects the typo and sends you to google.com.
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: scythe944 on May 18, 2009, 06:51:23 AM
Just wanted to give some more praises for opendns.  LOVE IT, as any Network Admin should.  Don't question it, just embrace it.  Trust me, they kick butt.

The founder is a genius, as much as I'd not like to say that.  Once you use OpenDNS, you'll never go back.  Trust me!
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: SpeedyPC on May 18, 2009, 08:07:11 AM
Just wanted to give some more praises for opendns.  LOVE IT, as any Network Admin should.  Don't question it, just embrace it.  Trust me, they kick butt.

The founder is a genius, as much as I'd not like to say that.  Once you use OpenDNS, you'll never go back.  Trust me!

What about for home computer users that don't have a network, running from cable using optusnet broadband can I used OpenDNS while I'm registered with Optus.
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: YoKenny on May 18, 2009, 11:56:18 AM
What about for home computer users that don't have a network, running from cable using optusnet broadband can I used OpenDNS while I'm registered with Optus.

Yes you can use it.

Try it you'll like it.
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: Lisandro on May 18, 2009, 01:55:11 PM
What about for home computer users that don't have a network, running from cable using optusnet broadband can I used OpenDNS while I'm registered with Optus.
Sure. OpenDNS does not depend of your ISP. Enjoy it ;)
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: SpeedyPC on May 18, 2009, 04:11:04 PM
What about for home computer users that don't have a network, running from cable using optusnet broadband can I used OpenDNS while I'm registered with Optus.
Sure. OpenDNS does not depend of your ISP. Enjoy it ;)

And this doesn't affect my user broadband account correct because I've never heard and haven't used OpenDNS, because this is new to me. Before I jump in to OpenDNS could you please share me your details, review and your experience with OpenDNS.

Thank you.
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: bob3160 on May 18, 2009, 05:24:02 PM
Speedy,
I'm on Comcast Cable and it doesn't effect my service..... ;D
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: Lisandro on May 18, 2009, 05:27:25 PM
There is much info in their webpages.
My experience is very good. I've enabled the filters for some other categories that are known as malware sharing.
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: !Donovan on May 19, 2009, 01:26:05 AM
HTML Source Viewer finally showed the code to hXXp://www.agoga.com/ and it only had 2 things in it. A iframe for two sites. (See images & text document of landing.php)

Avast is correct this time as the site attempts to change your homepage. Good thing there's Super AntiSpyware! ;)
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: SpeedyPC on May 19, 2009, 03:37:38 AM
Thanks YoKenny, Bob and Tech I'll setup the OpenDNS tonight when I get home  ;D ;)
Title: OpenDNS Thanks
Post by: hlecter on May 20, 2009, 06:35:44 PM
I want to thank the posters of this thread.

I'm up and running with OpenDNS thanks to them. :)


Regards
HL

Edit:
And a special thank to DavidR who helped me out with a  problem
in a separate thread.
Title: Re: Infections from agoga.com?!?!?!?!?!
Post by: DavidR on May 20, 2009, 07:46:34 PM
You're welcome.