Hostfile redirections in Ad-Aware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by lynmac, Sep 6, 2004.

  1. lynmac

    lynmac Private E-2

    Hi MG's,

    Your site is my bible for trying to keep it clean! I have run across a roadblock trying to manage 6 hostfile redirections in Ad-Aware everytime I boot. I take care of 4 machines, work related, for a friend and myself, we are always transferring things across the network both here and at his house. They all have the same redirects.

    I followed your directions in READ ME FIRST , running CCleaner, Ad-Aware(with VX2), Spybot, CWS, Kill2me, A2(I have only run the freeware version for a while,and did so here), and about:Buster. I followed each step and updated the programs before starting, all in Safe Mode. I also ran Trend Micro freebie scan. They all showed no problems. I also run other spyware programs : Spystopper, BHODemon, Spyware Doctor (freezes alot but finds some gems on occasion), SpywareBlaster, WindowWasher, and HiJackThis. I have been using Mozilla Firefox for several months, manually clearing out files daily. The redirects have occured while using Mozilla. I use McAfee Security Center and ran that Virus check as well.

    I downloaded the latest version of HiJackThis and scanned and saved the log. For the most part I spend a lot of time referring to your site and the Windows list of system files to try to keep HiJackThis cleaned out, and to keep my running processess up to speed. I can't help but think I missed something along the way. The one entry that shows up in HiJackThis scan I am not sure about deleteing but think I should is an R1 HKCU overide proxy entry. Maybe I am blind, but I can't nail down any other entries in HJT to point to the hostfiles. I know I read on your site how to produce an in depth detailed log of HiJack this or Ad-Aware (although I run ADA with a custom scan), but I have looked and looked for that post and can't find it.

    Any help you would give me is much appreciated! Besides my hairdresser has been making remarks about hair loss.

    Lynmac
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What version of Ad-aware did you run? Is it Ad-aware SE 1.04 with the reference file SE1R7 06.09.2004 ?
    I assume where you said CWS you meant you ran CWShredder? (CWS is the infection not a scanner)
    Have you checked your hosts files?
    What about IE DefaultPrefix settings?
    What OS are we talking about?
     
  3. lynmac

    lynmac Private E-2

    Thanks for helping me chaslang.

    I am running Ad-Aware 6.0 Build 6.181 ref file 01R33926.08.2004
    Yes, I ran CSShredder 1.59.01
    I have not checked my hosts files, that is what stopped me from proceeding...I am not at all familiar with them, what to look for or what to do if I could find something.
    Default in IE is http://
     
  4. lynmac

    lynmac Private E-2

    oops...running XP Pro SP1
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You said, " followed your directions in READ ME FIRST"

    You could not have! Your would not have that version of Ad-aware if you did. Click all the links and get the correct versions.
     
  6. lynmac

    lynmac Private E-2

    I have now downloaded the correct version of Ad-Aware. My mistake was printing up the readme page to follow the directions from that. As a result I did not use the link you had provided, made sure the copy of Ad-aware that was already on my computer was up to date and did not download from the link you had on the original page.

    I ran it in safe mode and saved the log.
     
  7. jdeh

    jdeh Private First Class

    Lynmac, pls read my thread on "real searcher internet homepage" re the problem that my sister had>>>sounds similar to yours. Let me know what happens. All she had to do was get rid of the links referred to in the HiJackThis logfile that had "redirect" in them and similar to the rogue homepage address and it solved her problem.

    Bo Bo
     
  8. lynmac

    lynmac Private E-2

    Thank you! I took a quick look and will read further later. My homepage has not been affected, at least not yet.

    Thanks for your interest!

    Linda
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post your hosts file here as a .txt file attachment and I will look at it.

    Also, create a HijackThis log and post it as a .txt file attachment. Follow the guidelines for HijackThis posting here: http://forums.majorgeeks.com/showthread.php?t=38752
     
  10. lynmac

    lynmac Private E-2

    Hosts file attached. You guys are amazing to weed through all this. Will the attachment show in my reply? I uploaded it, but must have done something wrong since I can't see it there.
     
    Last edited: Sep 7, 2004
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to copy it to a .txt file (like lynhosts.txt) so you can upload it or you will need to copy and paste it into your message. If you tried to upload the hosts file with no extension, the upload actually failed. Read the messages in the upload window.

    Don't forget the HijackThis log as a .txt file attachment too.
     
  12. lynmac

    lynmac Private E-2

    I saved it in notepad as hosts.txt then attached it to my reply, but I will rename it and try again. Thanks for your patience. Yes I will send the HJT log too, was late for work and didn't get to it.

    The file was too big. I had to zip it. Is there a way I can go through it and weed it out a little first to save you the time?
     

    Attached Files:

  13. lynmac

    lynmac Private E-2

    Tradestation entry is a valid program I use.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Other than the below lines (which have nothing to do with redirections) you HJT log is fine:
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - Startup: PowerReg Scheduler V3.exe
    O4 - Startup: PowerReg Scheduler.exe

    See this for info about BackWeb and PowerReg Scheduler:
    http://www.pestpatrol.com/pestinfo/b/backweb.asp
    http://www.pestpatrol.com/pestinfo/p/powerreg_scheduler.asp
    http://www.winpatrol.com/db/freesample/powerreg_scheduler.html

    Neither of these really big problems and they are both a matter of debate as to whether good or bad. Some people feel anything that collects any kind of info at all or that automatically send you stuff (even updates that load without you knowing) are bad.

    SpyStopper added a lot of stuff to your hosts file. Are any of the sites you are being redirected to in there?

    What exactly did you mean in your first message where you said, "6 hostfile redirections in Ad-Aware everytime I boot"?

    You mean everytime you reboot your PC, you are having Ad-aware run? If so, exactly what is it saying? What are the redirects?
     
  15. lynmac

    lynmac Private E-2

    I run my spyware programs often. When Ad Aware first detected the redirects I would delete them, but whenever I rebooted they would be right back again. Tradestation is a program that really chews up the hard drive, so we need to reboot, scan, and defrag a minimum of 2 or 3 times a week. I don't run AA on startup, but do it manually.

    I did a find in my hosts file and all of the redirects were in there! Whoooppeee!!

    I will delete those entries in HJT, silly me for thinking a reputable company would be a safe bet.

    I checked out the log in Spystopper but none of the redirects were in there. I find Spystopper really blocks thousands of unwanted pests as well as a scanner here and there, spyware and ads. However if it is loading up my hosts file is it wise to keep or or find something else?
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well some of those 6 lines you do want to redirect. I'm not sure about altavista.com though. Why is Ad-aware complaining about only those 6 lines being redirected to your localhost? You have many more being redirected the same way. Are you still getting these now that you upgraded to Ad-aware SE?

    You also showed an output detected as CYDOOR. I'm not sure if this is valid. Perhaps the directories created by Eudora are valid for Eudora and thet just match some malware names found with CYDOOR. See this: http://www.pestpatrol.com/PestInfo/c/cydoor.asp

    That could be a false positive from Ad-aware.
     
  17. lynmac

    lynmac Private E-2

    After I upgraded Ad-Aware they showed up 2 more times, but the second time I had Ad-Aware delete them they have not reappeared as of today. I don't know why those 6 hung around for so long.

    I prefer to call it SIGHDOOR. I tracked that one down through Eudora Lite. It is downloaded with Eudora and is I am afraid a necessary evil unless I want to purchase Eudora, which I do not. CYDOOR is unstoppable , as Eudora checks and if I delete it from Ad-Aware it will just reload it within an hour or less. I kept hearing this dull "click" sound and that was what it was. I checked the user agreement and if I delete it permanently Eudora will cease to work.

    I am so glad to have those gone...thank you so much for your time and for sharing your expertise...I am not so shy of the hosts file anymore! Major Geeks is my home page and I imagine I am in the forums most weeks checking things out and trying to find answers to problems...which I almost always do.

    I checked around to see if you accept donations but could not find any reference to that. I usually support those that take all the time to write the freeware programs. But your sites dedication to helping everyone brings it all together in a big way.

    LM
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Happy I could help.

    I'm just a freelancer here! :) I do this on my own time (and a lot of it). This site belongs to Corporal Punishment & Major Attitude. See here: http://www.majorgeeks.com/page.php?id=2

    There are many people like me here that just try to help others. But CP & MA are the ones that make it all possible.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds