problem not solved by scans.. Logs provided

Discussion in 'Malware Help (A Specialist Will Reply)' started by Silverhand, Jan 18, 2009.

  1. Silverhand

    Silverhand Private E-2

    My internet starts out fast, but then begins to slow to a crawl. I did a netstat and www.007guard.com shows up multiple times in the list. I have done some googeling and the results say its a data mining site. Some say that its a result of spybot S&D, and it was not there when I removed it, but re-appeared when I installed it the second time.

    Anyway, here are my logs.. thanks for your help.
    Cant find SuperAntispyware logs or Malwarebytes log.. i will have to run them again.. Not sure why the log did not save.
    oh and when i ran combofix, it prompted me that there was a new version so I said ok..the version ran in Dutch, so the log is in Dutch.. if thats a problem let me know..

    Thanks in advance
    Silver
     

    Attached Files:

  2. Silverhand

    Silverhand Private E-2

    superantispyware and malwarebytes logs

    found em
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry but your logs do not show any problems at all. Perhaps you need to have your connection checked out. Is it DSL or cable? Maybe you should try resetting the modem.
     
  4. Silverhand

    Silverhand Private E-2

    its cable, and its running fine on the other systems.. This one just keeps bogging down.. Im in Safe mode now and there are no problems. when I log into normal mode and run IE, it runs for a bit, slows down, and then crashes..

    I am at the point of a reformat.. I may remove spybot and clear the host file again and see if that keeps it running..

    do you have any info on www.007guard.com ???

    how do i run the netstat command so I can copy and paste it to the board?
     
  5. Silverhand

    Silverhand Private E-2

    ok, so I shut my Cable modem down for an hour, and removed spybot search and destroy. I set the host file back to blank, and am running IE..

    I still cant get a fix on what 007guard is, and I dont want to reformat unitl I have tried everything.. I hate to quit even when its an easier solution.

    any ideas?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not have reset your hosts file back to blank. You should keep the protection Spybot is providing you by using the Immunize feature to block thousands of bad URLs.

    Then it sounds like something you are loading in normal boot mode is the cause. You could experiment using MSconfig with trial and error to see if you can locate the cause. You may want to start with Avast.



    Also Click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window
    The output from netstat -s -p tcp was already included in your MGlogs.zip file inside of the runkeys.txt log and it did not show this. You can just redirect the output of netstat to a file using the greater than sign ( like netstat -b -v > filename.txt ) and then attach the file here. You need to run this from a command prompt window.

    I also suggest that you install the below since you need a real software firewall

    PC Tools Firewall Plus <-- make sure you uncheck the options to install Google Toolbar and Threatfire free edition. There's is no sense in installing excess baggage.
     
    Last edited: Jan 19, 2009
  7. Silverhand

    Silverhand Private E-2

    thanks Chaslang, I really only post in the forums if I get stuck. I can usually work my way through a problem but this one has me baffled. I will do what you have outlined, and am installing the firewall.. Dont know why I dont have on on this system.. but I have been quite busy..

    I only removed Spybot S&D because every time I run it and use Immunize, I get the hits from 007guard.com.. I am not fully sure if thats whats causing the IE to bog down and freeze. I will follow the steps you have outlined and figure it out.

    I re-installed my grafix drivers last night because its a new card to this system and I figured it could not hurt.

    Thanks for your help
    I will post results in a day or two and a new netstat log to show what I am seeing.

    Silver
     
  8. Silverhand

    Silverhand Private E-2

    Ok, so it got the best of me and I had to try this..
    so I ran netstat and did a file
    installed spybot S&D and did another
    then waited ten minutes
    then ran another netstat file..
    Here is what I am seeing..
     

    Attached Files:

  9. Silverhand

    Silverhand Private E-2

    and If I wait longer, it gets crazier.. I have not run a netstat when it hangs.. but when I have the control pannel open.. IE is running at 100%..

    this last one is just because I found it funny.. its just a netstat log.. not netstat -b -v :)

    Again, thanks for your time..
    Silver
     

    Attached Files:

    • wtf.txt
      File size:
      6.9 KB
      Views:
      5
  10. Silverhand

    Silverhand Private E-2

    so I was looking at a working system that I have, and I pulled up its host file and noticed one line that is absent on my system.

    the main Local Host line was not in my host file..
    127.0.0.1 Local Host

    not sure when or why its missing, but I have inserted it back in line. There must be some script out there that re-writes the host file.. you may see more of this problem in the future if it is indeed the reason for what I have been dealing with.

    I will let you know if this fixed my problem
    Thanks
    Silverhand
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is your current status? Did adding the localhosts line back help?
     
  12. Silverhand

    Silverhand Private E-2

    No sir, im still haveing problems, just have not had the time to deal with it..
    Is this a normal Netstat log???

    Im still haveing the same problem and I need to go through the process of shutting down one by one with MSconfig to isolate the problem..

    In the end, my IE just bogs down to nothing then stops responding..


    Any idea why the Local Host line was removed from my Host file.. has anyone had that problem in the past??
     

    Attached Files:

  13. Silverhand

    Silverhand Private E-2

    Ok, took this netstat when the system started slowing down.. its very different from the above.. any ideas?
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download DelDomains and unzip it to your desktop. Do not run it yet.

    Find the files from deldomains.zip on your Desktop and RightClick on the deldomains.inf file and select Install.

    Now go here and download SysClean:
    http://www.trendmicro.com/download/dcs.asp

    You will need to download two additional files, one for viruses and the other for spyware. Instructions for which ones to download are found here:
    http://www.trendmicro.com/ftp/products/tsc/readme.txt
    After running SysClean, attach the log from it.


    Now run this Running GMER to detect rootkits and attach the GMER log.


    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.


    Run MGtools.exe then attach the below logs:
    • the log from SysClean
    • the GMER log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  15. Silverhand

    Silverhand Private E-2

    here are the logs.. in a rush to work so cant check to see how system is runnign.. I will let you know to night.. thanks
     

    Attached Files:

  16. Silverhand

    Silverhand Private E-2

    Nope... still maxing out at 100% on and off.. just froze my ie and sent it into no go mode.. had to shut it down and restart.. maybe I need to re run the applications again..

    let me know..
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well these logs are clean too. If you uninstall Spybot to remove all of the Immunizations, do you still have a problem where things slow down after awhile?

    Check your Router settings. See if there is UPnP setting. Possibly under a heading like Administration. If you find the UPnP setting, make sure it is disabled and then see what happens after you save this setting and then reboot your PC.

    It's starting to look like a reinstall is in your future.
     
  18. Silverhand

    Silverhand Private E-2

    is there supposed to be so many domain files in the registry.. I was running some anti spyware and it was stuck in the registry forever.. I looked and under Software/Microsoft/windows/internet settings/domain there are litherally hundreds of sites in the list.. I had to stop the scanner because it was takeing so freaking long..

    Im really at the point of a re-install at this point.. Im just curious now.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Thousands of entries are added by Spybot and other similar programs to protect you from bad domains. They add all the bad domains to your Restricted Zone.
     
  20. Silverhand

    Silverhand Private E-2

    thanks for all your help.. threw in the towel and reformatted.. now im doing the driver download dance.. damn old systems.. :)
    Thanks Again,Silver
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds