Need help to solve problem - Don't know if it is Spyware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ezmamos, Oct 22, 2004.

  1. ezmamos

    ezmamos Private E-2

    Ok I posted a few weeks ago but here is my problem. I can't browse to certain website (such as http://www.macromedia.com). I read the "How to: Spyware, Trojan And Virus Removal" and followed all the instructions. I did not find anything. I tried both IE and Firefox but with no success. I just get an immediate page not found. I can ping and tracert the websites without a problem. I also know that it's not my firewall because all the other machines in the network work fine. I am at a lost as what to do next. I am inclined to reformat but somehow I feel like I should beat the problem so maybe I'm being stubborn. So does anybody have any ideas as to what to try next. I posted in this forum because it seems like such a spyware symptom.
    Any help would be appreciated.
    Eric
     
  2. Kodo

    Kodo SNATCHSQUATCH

    what OS are you using?
     
  3. ezmamos

    ezmamos Private E-2

    Oh sorry. Im using Windows XP SP1.
     
  4. Kodo

    Kodo SNATCHSQUATCH

    go to start.. run.. type

    notepad c:\windows\system32\drivers\etc\hosts

    it should look like this unless you've modified it knowingly.


    # Copyright (c) 1993-1999 Microsoft Corp.
    #
    # This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
    #
    # This file contains the mappings of IP addresses to host names. Each
    # entry should be kept on an individual line. The IP address should
    # be placed in the first column followed by the corresponding host name.
    # The IP address and the host name should be separated by at least one
    # space.
    #
    # Additionally, comments (such as these) may be inserted on individual
    # lines or following the machine name denoted by a '#' symbol.
    #
    # For example:
    #
    # 102.54.94.97 rhino.acme.com # source server
    # 38.25.63.10 x.acme.com # x client host

    127.0.0.1 localhost


    if it doesn't , then copy and paste mine into yours and save it.
     
  5. ezmamos

    ezmamos Private E-2

    Check. My host file is unmodified and looks like yours. I'm telling you this problem is just bizarre.
    Eric
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you check to see if the sites you are having problems getting to are listed in Internet Explorer, Tools, Internet Options, Security, Restricted Sites, Sites?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If my previous post does not help, you should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, from any sub-folder of C:\Documents and Settings or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  8. ezmamos

    ezmamos Private E-2

    Here is the HijackThis Log file attached in txt format as requested.
    Eric
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I have a few questions:

    1) Why do you have this proxy setting:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.0.0.100

    2) The O17 lines show some IP addresses that look suspicious:
    O17 - HKLM\System\CCS\Services\Tcpip\..\{719FFE7F-D9BA-4AE7-BBA5-994BE5977050}: NameServer = 10.0.0.101,216.231.41.22,216.231.41.2,4.2.2.1
    O17 - HKLM\System\CCS\Services\Tcpip\..\{D5190354-7FCC-4161-BF16-B104C7394D91}: NameServer = 10.0.0.101,216.103.134.2,216.103.134.3
    O17 - HKLM\System\CCS\Services\Tcpip\..\{D6F706F3-80F2-4D4B-81B1-093CE7727893}: NameServer = 10.0.0.101,216.103.134.2,216.103.134.3

    The 216.231.41.22, 216.231.41.2 are for PacBell and are most like okay. And 216.103.134.2 and 216.103.134.3 are also PacBell. I assume that is your ISP.

    However the 10.0.0.101 and the 4.2.2.1 do not look okay and the 10.0.0.101 is in the same subnet as the proxy setting above.

    4.2.2.1 = [ vnsc-pri.sys.gtei.net ]
    OrgName: Level 3 Communications Inc.
    OrgID: LVLT
    Address: 1025 Eldorado Blvd.
    City: Broomfield
    StateProv: CO

    3) Are you sure you are not having a problem with PeerGuardian?

    4) Did you put this in your Trusted Zones:
    O15 - Trusted Zone: http://*.voyager

    5) These lines look suspicious.
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\inetrepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\inetrepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\inetrepl.dll

    Do you know what this program is? What is Create Mobile Favorite about?

    6) Do you know what the SetiHide program is? Is this somekind of astronomy program?
    C:\Program Files\Seti\SetiHide.exe

    I need answer for the above before we can do too much more but here are a few things to fix.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -

    Now reboot and post a new HJT log. Answer my questions and tell me how things are working.
     
  10. ezmamos

    ezmamos Private E-2

    1) Ok my internal network net 10 so everything 10.0.0.x.
    Nevertheless, 10.0.0.100 does not exist on my network.

    2) 10.0.0.101 is a valid internal dns server and that is why this is there.
    As far as the other dns servers, 4.2.2.1 is ok. It is a public dns server that is fast and I use it for testing when trying to figure out problems like this one. Now my isp use to be Pacbell. I now have another ISP whose dns servers are 216.231.41.22 and 216.231.41.2.

    3) I don't think it is peer guardian but I will ditch it. Don't think I really need it anyway (don't download music...too much).

    4) http://.voyager - This is an internal pc but I don't remember specifically adding it to the trusted zone for any reason.

    5) I have no clue what Mobile Favorites is so it's gone.

    6) SetiHide is a program that runs Seti which is an astronomy program that downloads signals in space and process them looking for intelligent life (don't ask).

    Ok. I will do what you said and test things out and repost the htj.log if needed.

    Eric
     
  11. ezmamos

    ezmamos Private E-2

    Chaslang....SUPERB WORK!!
    And so you know, you guessed it. It was in the end, Peerguardian. I can't believe I didn't think of that. That's ok cause we all need help from time to time.
    Also, HijackThis really came in helpful. I ditched and/or correct much of what it found. I attached again in case you are interested (and in case you see anything else that needs to be gone).
    Anyway, I really appreciate the help.
    Eric
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds