Strange HJT errors

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Disco Albino, Sep 30, 2007.

  1. Disco Albino

    Disco Albino Private E-2

    I've done all the "read and run me first" things, but I'm still having some problems running HJT. It's a very new computer (less than a month old), but my browser is already slowing down. Here are the error messages I recieved:

    This one concerns me the most: HijackThis was denied write access to Host files. I manually edited C:\Windows\system32\etc\hosts, and removed the "::1 LocalHost" entry, but it wouldn't allow me to save it. It doesn't show up on the log, but on the scan it includes "O1-Hosts: ::1 localhost", and HJT told me to edit that out manually, but I couldn't

    Second error message: "An unexpected error has occurred at procedure: modMain_CheckOther1Item()
    Error #75 - Path/File access error

    Please email me at merijn@spywareinfo.com, reporting the following:
    * What you were trying to fix when the error occurred, if applicable
    * How you can reproduce the error
    * A complete HijackThis scan log, if possible

    Windows version: Windows NT 6.00.1904
    MSIE version: 7.0.6000.16512
    HijackThis version: 1.99.1"

    I'm wondering if "::1 localhost" could be a hijacker, or if it's a normal entry? If it's not normal, how could I go about removing it without write access? Attached is my HJT log, thanks for any help. If there is nothing abnormal, sorry for bothering with this but I've never had these HJT errors before.
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, do you have Administrator rights?

    Second, you need to relocate and rename HijackThis. It should be ran from C:\Program Files\HJT and be renamed to "analyzethis.exe".

    We also need a few more logs if you want us to assist you.

    I will post our initial instructions as a reference.

     
  3. Disco Albino

    Disco Albino Private E-2

    Thanks for the response, I actually was able to remove the unwanted entry in my host file in safe mode. It appears the entry was some kind of hijacker. My browser is running much faster, and all the scans I've run have shown no signs of malware. I'll redo the scans and post the logs if I need any more help. Thanks!
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    By default your Windows HOSTS file should look like the below.

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds