Could you check my reports

Discussion in 'Malware Help (A Specialist Will Reply)' started by jcrubio2001, Jun 8, 2008.

  1. jcrubio2001

    jcrubio2001 Private E-2

    Hello! Could you please check my 3 reports(i couldn't run the 4th) , something that happened after doing all the steps, my hosts file became empty with only this line "127.0.0.1 locahost" the rest was gone, and also avast antivirus didn't show when i start up the pc, but i put back all that again. thanks for the help.
    the mgtools says that is not compatible with my version of windows (vista)
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Why are you running the READ & RUN ME to begin with? What malware problems were you having? You don't appear to have any.

    You can rerun Spybot and Immunize to create a large hosts file blocking thousands of bad sites if that is what you are looking for.

    MGtools works just fine with Vista. That is why it is in the Vista Cleaning procedure. It only will not work with 64bit versions of Windows but you do not have a 64 bit version because ComboFix would not have run.
     
  3. jcrubio2001

    jcrubio2001 Private E-2


    Hello!
    Thanks for helping me. :)
    I mostly worried about having somekind of rootkit or trojan, I have several unknown processess with 0 like this one. Example.

    =================================================================
    Unknown 0 TCP 50801 192.168.1.100 80 http 208.46.174.73 208-46-174-73.dia.static.qwest.net Time Wait N/A 2008-06-08 13:50
    =================================================================
    I had the hosts files update with thousands of bad sites, but yesterday all of them got erased only leaving one line "1270.0.1 localhost" . I don't know why suddenly the whole list just vanished.
    Also i have been using homer to put a little pictures everytime a site gets blocked. Now, I can't used it, It shows a error message "Something is already listening to port 127.0.0.1" , I confirmed already with funktoad.com(homer's creator) that there is not a hidden copy running already using the currports.

    I couldn't run Mgtools maybe a trojan or rootkit not allowing me to use it. i really don't know. I am sending you the picture with the message that says that my OS version is unsupported by mgtools.
     

    Attached Files:

  4. jcrubio2001

    jcrubio2001 Private E-2

    I couldn't edit my last post but today explorer.exe got replaced for Explorer.exe
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not a process. It is a TCP/IP connection which is more than likely just to your ISP.

    Because the cleaning procedures take a shortcut of not checking tens of thousands of lines in a host file for validity. It is easier just to delete them. As I said in my last message, you can added them back in with Spybot's Immunize feature.

    Not malware. You may have other protection software conflicting with Homer.

    I'm not sure why this is occurring since Vista is supported. It may be something related to how your version info is presented. What you you get when you enter the ver command at a command prompt?

    That's the same file. Capital letters make no difference.
     
  6. jcrubio2001

    jcrubio2001 Private E-2

    hi :) thanks for the info about the host file.
    i ran ver command and it showed this : 6.0.6001

    about the explorer being replaced by Explorer, the spybot search and destroy, showed a window with that message. Ii thought it was kind of unsual to show a replacement of this kind.

    I would like to run that program(MGtools) i can't but i don't know why.
    And the other thing about Homer unable to work cause something else listeing to the port 127.0.0.1 also got me thinking.
    I can't figured out what other program or antispyware is doing it.
    thanks
     
  7. jcrubio2001

    jcrubio2001 Private E-2

    hello, I downloaded the secuirty task manager and found out the same "homer" program was active and hidden, but at the end i had to move the folder somewhere else to make it work.
    I am assuming i don't have to worry about spyware, malware etc, thanks for all your help and patience
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need to know everything that is returned on the line. For example a US based version of Windows Vista would say

    Microsoft Windows [Version 6.0.6000] or Microsoft Windows [Version 6.0.6001]

    depending on which Service Pack is installed. If yours does not use the english word Version, then that would be a problem.

    I doubt it was changed. Perhaps you recently did a Windows Update. Right click on the C:\windows\explorer.exe file and select Properties and then select the Version tab and take a look at all the info under the Version tab.

    It may be due to how the version information line is being returned.


    It could be Spybot or any other protection software that is locking your hosts file.
     
  9. jcrubio2001

    jcrubio2001 Private E-2

    hello again, the computer is running fine i think, regarding the version, it is spanish version, and the message says: Microsoft Windows [Versión 6.0.6001]
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's good! :)

    If you would not mind, I would like you to try out the new version below to see if it is able to get around this

    MGtools.exe

    If it runs then attach the C:\MGlogs.zip file. If it does not run, tell me what exactly happens.
     
  11. jcrubio2001

    jcrubio2001 Private E-2

    Hello, thanks for all the help.
    I was able to open the program :)
    I have attached the log file. Just in case, I ran the program but i didn't deactivate any antivirus, firewall o teatimer, Please let me know if that was ok, otherwise I run it again.
    thanks!
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is okay just for the scans. I see 2 quick issues.

    1. your Avast Antivirus program is not installed/running properly.
    2. one of the tools in the scan did not run. This tool is named ShowNew.bat. Please goto the C:\MGtools folder and find the ShowNew.bat and double click on it and tell me what you see in the command prompt window that comes up. Do you get any error messages?
     
  13. jcrubio2001

    jcrubio2001 Private E-2

    Hi,
    when I ran it by itself it says "Your OS Version is Unsupported by ShowNew"

    Could you please help me with the Avast issue, i am not sure what is no running....
    thanks
    jc

    by the way , i just remember that day before yesterday, a program (either the firewall or the spybot, not sure which one) told me that the binaries for Svchost and avast changed, so i decided to download a new version of avast and reinstalled and i did nothing for Svchost. Before when i got updates for a program for avast, not for the database virus, i got a message telling me that a new version of the program is ready to be install, but this time didn't say anything.
    lol, i think i am getting paranoid.

    Later, or next day I run the new mgtools, and Netstat wanted access to internet but i didn't allow it.
     
    Last edited: Jun 16, 2008
  14. jcrubio2001

    jcrubio2001 Private E-2

    I am sorry, don't pay attention to the previous post, i couldn't finish editing it. so i reposted. thanks
    ==========================================
    Hi,
    when I ran it by itself it says "Your OS Version is Unsupported by ShowNew"

    Could you please help me with the Avast issue, i am not sure what is no running....
    thanks
    jc

    by the way , i just remember that day before yesterday, a program (either the firewall or the spybot, not sure which one) told me that the binaries for Svchost and avast changed, Before when i got updates for avast, not for the database virus, i got a message telling me that a new version of the program is ready to be install, but this time didn't say anything , so i decided to download a new version of avast and reinstalled and i did nothing for Svchost.
    lol, i think i am getting paranoid.

    Later, or next day I run the new mgtools, and Netstat wanted access to internet but i didn't allow it.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do the below in the order written.

    Download a new copy of Avast from this link: Avast! Home Edition Don't run it yet!! Just download it.

    Now uninstall your current copy of Avast!
    Now reboot (do not skip the reboot)
    Now install from the new copy just downloaded above.

    Most likely not a problem.

    This is normal and you can allow netstat to have access to your network. GetRunKey.bat is running netstat to create a log of your connections to look for potential problems.

    Please download this View attachment NewSN.zip into the C:\MGtools folder. Then extract the ShowNew.bat file from the ZIP file into the C:\MGtools folder thus overwriting your previous copy. Then try running this new ShowNew.bat file by double clicking on it. Let me know if this one works.
     
  16. jcrubio2001

    jcrubio2001 Private E-2

    Hello again :)
    I ran the program you gave me, shownew.bat, and I got a txt file, and this screen that doesn't close but i think It did what it was supposed to do.
    Thanks for all the help
    jc
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Great! It worked properly now. Thanks for working with me on this. This will help others in the future who have non-english versions of Windows Vista.

    When run this way, the command prompt window will not close until you close the notepad windows that pops up showing the newfiles.txt log.

    Now let's finish up a few things and make sure Avast was installed properly.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5

    Now reboot your PC.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Windows\TEMP
    C:\Users\jc\AppData\Local\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below log:
    • C:\MGlogs.zip
    How is everything working for you now?
     
  18. jcrubio2001

    jcrubio2001 Private E-2

    Hello :)
    I apologize for not writing back sooner.
    The computer seems to run very well.
    I have attached the zip file.
    I followed the steps to reinstall the avast, hopefully it is better now.
    Thanks!
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it is not running properly and neither are many other things because you are using MSconfig to control startups. In step 1 of the READ & RUN ME we specified that you must not do this but you still are.
     
  20. jcrubio2001

    jcrubio2001 Private E-2

    I am sorry, I didn't paid attention. I will go read them again and try to follow. and post the log file.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After you put your system into Normal Startup mode, you should reboot and then run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the new C:\MGlogs.zip file
     
  22. jcrubio2001

    jcrubio2001 Private E-2

    I think i was running my system in custom startup mode because I didn't want some windows processes to run, but if i not mistaken i can't deactivate in services instead. right?

    Today something weird happend, avast found diferent trojans or the same inside this folder
    C:\Users\jc\AppData\Local\Temp\a2temp

    the weird thing is that this folder is recreated after i erased it, and a diferent file inside that folder is created.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really should read the links in the READ & RUN ME sticky thread. This one explained all this too you: Dealing with Startup Processes You should not use MSconfig like this at all. It can cause major problems especially if you disable the wrong service.

    You are wasting your time. This folder is used by A-squared. Avast is incorrect. Either uninstall A-squared or ignore detections at this location in the future.

    You have been running Spybot's Teatimer all of this time and it may be causing problems getting things to uninstall/install properly. You need to disable Teatimer as requested in the READ & RUN ME and then reboot. See this: How to disable Spybot's TeaTimer

    Now that MSconfig is no longer being used and now that Teatimer is disabled, you need to reinstall Avast again. It still is not running properly. This may be a permanent result of what you were doing with MSconfig. The services for Avast are not showing up which means Avast can easily be terminated by malware and some of Avast's features may not work.


    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  24. jcrubio2001

    jcrubio2001 Private E-2

    Hi! thanks for the help and patience.
    with the teatimer off and the normal startup thing, I uninstalled ,restarted, reinstalled , restarted Avast.

    and here is the report :)

    by the way, when this is over, how often do you recommend to run for example ccleaner or others. Is there a link to give advice how to give the pc a regular cleaning?

    I also did the fixme.reg , and it was sucessfull.
    Thanks for the info about A-squared as well.
     

    Attached Files:

  25. jcrubio2001

    jcrubio2001 Private E-2

    I am so happy, I just noticed something else, I had a big problem with my dvd unit, it was showing as a cd rom all the time, and have some problems reading certain data dvd, thanks thanks thanks!!!!! :) , Now i open my pc, and there it is a beautiful "DvD unit" name.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure that you are uninstalling and reinstalling Avast properly? What version are you installing? Did you use the link I gave you?

    Have you been deleting any entries seen in your HijackThis log on your own? Are you filtering any lines with HijackThis. Are you using some other program to control startups? You only show the below for Avast in your HijackThis log's process list:

    C:\Program Files\Alwil Software\Avast4\ashDisp.exe

    Nothing else for Avast is showing. You should be seeing all of the below.

    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

    O4 - HKLM\..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
     
  27. jcrubio2001

    jcrubio2001 Private E-2

    I am sorry i forgot i moved some to the ignore list, i deleted from the ignore list and this is the report. Avast version 4.8
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that's better everything looks fine now.

    For future reference, you should now see that you don't want to use the ignore list when posting in forums for help. ;) We spent a bunch of time trying to fix a problem when there wasn't any.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     
  29. jcrubio2001

    jcrubio2001 Private E-2

    Thank you for everything Chaslang! my pc woorks great now!!!!! (actually even better because the cleaning procedure fixed my dvd units as well).
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  31. jcrubio2001

    jcrubio2001 Private E-2

    Hi Chaslang ( :major ), I am not sure if this is related but i can't see the icons, in some folders, or thumbnails for jpg, i have to go to view and click on big thumbnails, and then they show, and then i click again in view large thummbnails, and then they show. (also some jpg thumbnails are like very low res)

    I was thinking maybe cause i couldn't do the uninstall Combofix. the combofix is renamed as cf, and I copied-paste what you wrote to me , but i don't think i did anything, combo fix seemed to run but i didn't say anything else, and it is still on the desktop
    .
    thanks
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This does not sound like it is related. Are you sure that this is not some how related to viewing of hidden files and folders which ComboFix will disable when it is uninstalled.

    ComboFix should not run! It should just uninstall and the Desktop icon should be removed as the file is deleted. Also temporary files for it and backups will be removed.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds