Something is seriously wrong

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by CaNoFzOo, Jun 12, 2004.

  1. CaNoFzOo

    CaNoFzOo Sergeant Major

    My firewall has blocked over 5000 access attempts today. This worries me. It has never been like this. Its blocking like 20 things per second. I'm kind of freaked out... what should I do? Its blocking so much at one time and this is really unusual for it be be blocking so much per second.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. CaNoFzOo

    CaNoFzOo Sergeant Major

    Hi thank you so much. I downloaded CrapCleaner.. just to get this straight.. anything that it finds is safe to be cleaned right? It found something called DrWatson.... doesn't my computer need that? C:/windows/Q323172.log do you know what that is... theres a ton of em'. :)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is your OS? Where did it find DrWatson? For winXP, it only belongs in C:\windows\system32. (and \I386 if you have that on your hard drive).

    And the logs are okay to get rid of.

    Did you run Ad-aware and SpyBot too?
     
  5. CaNoFzOo

    CaNoFzOo Sergeant Major

    Ran ad-ware it just cleared some cookies. DrWatson was found in: C:\documents and settings\All Users.windows\application data\microsoft\dr watson\user.dmp


    Is it normal for it to be in there?
     
  6. CaNoFzOo

    CaNoFzOo Sergeant Major

    oops sorry. OS:




    Platform: Windows XP (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    :)
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay this is just application data that is not needed. It probably removed the file you mentioned plus another one named drwtsn32.log.

    You should run SpyBot S&D too.

    Are your still getting those access attempts?
     
  8. CaNoFzOo

    CaNoFzOo Sergeant Major

    Thank you for your help! About the access attempts.. they've been slowing down thank goodness. Theres not as much of them as there were before. What do you think might have caused all of that to happen? It has never happened before until today.


    All I can say is thank goodness I have a firewall. ;)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some of the cookies we clean up could have been problems. But if they are still occurring there is still more to fix. You really need to download and run SpyBot S&D : http://www.majorgeeks.com/download2471.html

    By the way is your Ad-aware current, they just added new stuff not more than 12 hrs ago. Current reference list is: Ad-aware referencefile 01R318 13.06.2004

    After doing the above, I would like to see you post a HiJaakThis log: http://www.majorgeeks.com/download3155.html

    Before running HijaakThis, shut down ALL windows applications especially browsers and Win Explorer sessions.
     
  10. CaNoFzOo

    CaNoFzOo Sergeant Major

    one more thing...

    Is it safe to scan for issues? I'm afraid that i'll mess something up.... eek :eek:
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. CaNoFzOo

    CaNoFzOo Sergeant Major

    Re: one more thing...

    Thank you... thing is though... I don't know how to backup my registry :eek:
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  14. CaNoFzOo

    CaNoFzOo Sergeant Major

  15. CaNoFzOo

    CaNoFzOo Sergeant Major

    another question about issue scans

    If I have CCleaner scan for issues, and it finds something will it automatically fix it, or will it ask me if I want it to be fixed?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: another question about issue scans

    It searches for problems and allows you to check off which ones you want to fix.
     
  17. CaNoFzOo

    CaNoFzOo Sergeant Major

    I'm sure you're VERY frustrated with me right now. You're my hero :) LOL. Well, I scanned for issues and it found a lot... i'm not sure what to do now. I'm not sure whether to let them be or fix them. I don't know their value to my computer... so would it be okay if I type all the things it found wrong, post them in here, and have you tell me what I should fix? If you don't want to I understand you've helped me a lot. I appreciate it.:)
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    For now, I would not worry about the items you are seeing here in the issues list. And it is typical to find quite a few issues. If your PC is running OK, leave the issues list alone. The only items here that I would recommend you fix would be things for software that you are sure you recognize and that you are absolutely positive you uninstalled.

    I'm more concerned with the statement "firewall has blocked over 5000 access attempts today". Is this still going on?

    I still have not heard you say that you downloaded and ran SpyBot S&D : http://www.majorgeeks.com/download2471.html

    You also did not say whether you updated Ad-aware to referencefile 01R318 13.06.2004.
     
  19. CaNoFzOo

    CaNoFzOo Sergeant Major

    Should I really download Spybot? Wouldn't it find the same things Ad-ware would find?
    No, I did not download the Ad-Ware reference file yet because of my parental controls on AOL it doesn't allow me to download updates for my anti-virus software, or ad-ware.(Go figure:rolleyes: ) I'll update it later when I get a chance.

    About the access attempts yes they've pretty much stopped there have only been 105 access attempts today. (I've been online for almost 5 hours)
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes absolutely download and run SpyBot. There will be overlap with Ad-aware but they each find things the other does not. As for the Ad-aware update, can you download the reference file from here http://www.majorgeeks.com/download726.html. and then just unzip it to the C:\Program Files\Lavasoft\Ad-aware 6 directory. This will update the reference list.

    There shouldn't be an access attempts. Do the above stuff for Ad-aware and SpyBot, then get HijaakThis from here: http://www.majorgeeks.com/download3155.html
    Then with all applications shutdown (especially browsers and Win Explorer sessions), run HijaakThis. Save its log and post the whole log in a your next message.
     
  21. CaNoFzOo

    CaNoFzOo Sergeant Major

    Hey i'm not done with the things you've asked me to do yet (almost done!), but should I make the backups?
     

    Attached Files:

  22. pegg

    pegg MajorGeek

    Do a backup with Spybot

    If you don't mind me jumping in -- yes, it's a good time to do a backup in case you then go ahead and remove something you didn't mean to in your registry.

    Someone correct me if I'm wrong
     
  23. pegg

    pegg MajorGeek

    Dr Watson

    OK - this is probably dumb to ask-- I decided to search for Dr Watson after reading this and I have WinXP and it is in C:\windows...and I386 but also similar to CaNo I found it in another place but the "folder is empty" so I figure I can delete it right? I know that sounds like a no-brainer but then you wonder why it's there (except I read where chaslang said info just gets moved...) so I'm just double checking.

    C:documents & settings\all users\application data\microsoft
     
  24. CaNoFzOo

    CaNoFzOo Sergeant Major

    Downloaded Spyboy ran that.. it found 14 Gain/Gator things, 5 DSO Exploits, An Alexa related object, and a cookie. I'm really glad I downloaded that. Ad-ware didn't find the Gator stuff surprisingly. But anyway.... here is my Hijack This log as you resquested. I don't see anything wrong with it. I uninstalled CallWave like a month ago though should that entry be fixed?






    Logfile of HijackThis v1.97.7
    Scan saved at 4:23:31 PM, on 6/13/2004
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\WINDOWS\system32\pctspk.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\HijackThis.exe
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
    O9 - Extra button: Real.com (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/7d90ae05585062/housecall.antivirus.com/housecall/xscan53.cab
    O16 - DPF: {89D75D39-5531-47BA-9E4F-B346BA9C362C} (CWDL_DownLoadControl Class) - http://www.callwave.com/include/cab/CWDL_DownLoad.CAB
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38049.3372106481
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Dr Watson

    Hi Pegg, its okay to have those application data files cleaned up.
     
  27. CaNoFzOo

    CaNoFzOo Sergeant Major

    In the past couple of hours i've gotten 23 access attempts. *shrugs* Do you think maybe some of the access attempts are from virus infected computer scanning and looking for other computers to infect?
     
  28. pegg

    pegg MajorGeek

    thanks

    Thanks - when they're empty - I figure there's no reason for them but hey - maybe they're waiting for something (good or bad) :eek:
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The address in your ZoneAlarm alert is for 114.67-19-12reverse.theplanet.com which does seem to exist but does not seem accessible if I try to get more information from them using a Trace Routing Tool. Searching for info on them seems indicate they are some kind of Internet Service company. Are they your ISP? No that can't be....you said you were using AOL?

    Do you use some games that require web hosting? Could that be what this is about?
     
  30. CaNoFzOo

    CaNoFzOo Sergeant Major

    I have A LOT of weird things like that trying to get to me.Yes I have AOL. No I do not use games that require web hosting.

    This is creepy. ><
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, Run and enter this command: notepad c:\windows\system32\drivers\etc\hosts
    Hit Ok.

    Cut and Paste the info from your hosts file into you next message.
     
  32. CaNoFzOo

    CaNoFzOo Sergeant Major



    Here it is:



    127.0.0.1 localhost
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's good. I not sure that there is anything on your PC that is the cause of these incoming access attempts. If they are driving you crazy, you can just tell ZoneAlarm not to display them anymore (but the obvious downside is you won't know if they are getting real bad again without check ZoneAlarms logs periodically yourself.
     
  34. CaNoFzOo

    CaNoFzOo Sergeant Major

    Thank you once again for all the time you've put in helping me. I appreciate it. Well, at least these things are getting blocked. Things wouldn't be too good if they weren't. Heh.
    Also....

    What is a Trace Routing Tool and how can you get one? Is it free?


    :)
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome!

    Check these out (actually I meant DNS Lookup):
    http://samspade.org/t/lookat?a=213.181.81.53+
    http://www.canufly.net/~georgegg/dns/
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you do want to do a trace route, you can do one from the command prompt using windows built in tracert.exe program. The output will look like something (yours will most likely take a different route to the end point) like this:

    C:\WINDOWS\SYSTEM32>tracert 67.19.12.114
    Tracing route to 114.67-19-12.reverse.theplanet.com [67.19.12.114]
    over a maximum of 30 hops:
    1 10 ms 7 ms 7 ms 10.86.128.1
    2 8 ms 7 ms 7 ms dstswr1-vlan2.rh.brfdnj.cv.net [67.83.242.161]
    3 10 ms 11 ms 9 ms ool-4353f281.dyn.optonline.net [67.83.242.129]
    4 9 ms 9 ms 13 ms r2-srp13-0.wan.prnynj.cv.net [65.19.112.18]
    5 11 ms 11 ms 12 ms r1-srp5-0.in.nycmny83.cv.net [65.19.96.53]
    6 16 ms 15 ms 17 ms r1-pos1-0.in.asbnva16.cv.net [167.206.8.150]
    7 * * * Request timed out.
    8 16 ms 18 ms 15 ms so-4-0-0.mpr2.iad2.us.above.net [64.125.30.122]
    9 28 ms 18 ms 16 ms so-0-0-0.mpr1.iad2.us.above.net [64.125.28.25]
    10 16 ms 16 ms 18 ms so-4-0-0.cr2.iad1.us.above.net [64.125.29.133]
    11 19 ms 17 ms 20 ms so-1-0-0.cr2.dca2.us.above.net [64.125.28.129]
    12 45 ms 46 ms 46 ms so-2-2-0.cr2.dfw2.us.above.net [64.125.29.9]
    13 49 ms 49 ms 48 ms 216.200.88.141.theplanet.com [216.200.88.141]
    14 47 ms 47 ms 48 ms dsr2-1-v1.dllstx4.theplanet.com [12.96.160.7]
    15 52 ms 48 ms 48 ms gig1-0-1.sm-car6-2.dllstx4.theplanet.com [67.18.116.4]
    16 48 ms 48 ms 52 ms 114.67-19-12.reverse.theplanet.com [67.19.12.114]
    Trace complete.

    There is also a free program here on MG's call 3D TraceRoute: http://www.majorgeeks.com/download2464.html

    There maybe others too.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds