Author Topic: Can't "Fix"  (Read 52118 times)

0 Members and 1 Guest are viewing this topic.

Offline Zyndstoff (aka Steven Gail)

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2604
  • I can resist anything except temptation.
    • tex62
Re: Can't "Fix"
« Reply #165 on: April 21, 2011, 07:46:13 AM »
So, as one thing I see is a modified hosts file as well - which does not come to me as a complete surprise.  8)

On the laptop use this MS-tool to fix the Hosts-file: TOOL

Download the file to disk and then run it.

Then please start hostsXpert and copy the text on the right side of the window and post it here, pls. There is a "copy to clipboard" command in hostsXpert somewhere, maybe in the "tools" or "editing" sections.
In case you need to download hostsXpert, here is the link: hostsXpert

Thx
7 x64 SP1, FF 8a Aurora, TB6, 6.0.1203 Free
Free MBAM Clear

rlakritz

  • Guest
Re: Can't "Fix"
« Reply #166 on: April 21, 2011, 08:05:04 AM »
Steven, I ran the Tools fix and downloaded HostsXpert.  When I opened the program I got this message:  "Hosts file does not exist. Press OK to create Hosts file. Cancel to Quit." What to do?

Offline Zyndstoff (aka Steven Gail)

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2604
  • I can resist anything except temptation.
    • tex62
Re: Can't "Fix"
« Reply #167 on: April 21, 2011, 08:07:40 AM »
Create it, then copy and post.  8)
7 x64 SP1, FF 8a Aurora, TB6, 6.0.1203 Free
Free MBAM Clear

rlakritz

  • Guest
Re: Can't "Fix"
« Reply #168 on: April 21, 2011, 08:16:04 AM »
# Copyright © 1993-1999 Microsoft Corp.

# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.

# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.

# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a "#" symbol.

# For example:

# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

Offline Zyndstoff (aka Steven Gail)

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2604
  • I can resist anything except temptation.
    • tex62
Re: Can't "Fix"
« Reply #169 on: April 21, 2011, 08:24:56 AM »
Wonderful.  ;D

This one is sorted out.

Since essexboy will be online in the evening only you will have to wait for a detailed analysis of your log, but I think it is looking quite okay so far.

I would suggest in the meantime:

  • Do a quickscan mit Malwarebytes Antimalware (update it via it's GUI first!) and post the log here (just another quick look for me), but do not delete anything, just post the log.
  • Go ahead and check / update your Avast (on the Maintenance tab click on "Update program")

I'm away for a meeting now, but I'll look at the MBAM log in an hour or so.  8)
7 x64 SP1, FF 8a Aurora, TB6, 6.0.1203 Free
Free MBAM Clear

rlakritz

  • Guest
Re: Can't "Fix"
« Reply #170 on: April 21, 2011, 09:07:02 AM »
See attached log.

Offline Zyndstoff (aka Steven Gail)

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2604
  • I can resist anything except temptation.
    • tex62
Re: Can't "Fix"
« Reply #171 on: April 21, 2011, 09:29:43 AM »
That is clean so far, very good.

This entry

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken
in the log refers to a PUM = potentially unwanted modification. This may have been done deliberately by the user or by some software and need not be bad.
This particular entry hides the search in the Windows start-menu.
You can delete it with MBAM if you wish or you can leave it this way, it is a harmless entry.  ;)
If you haven't missed that start-menu entry until now - just leave it.



For further advice please wait for essexboy to look at your OTS-log.

Cheers
Zyndstoff
« Last Edit: April 21, 2011, 09:31:54 AM by Zyndstoff (aka Steven Gail) »
7 x64 SP1, FF 8a Aurora, TB6, 6.0.1203 Free
Free MBAM Clear

rlakritz

  • Guest
Re: Can't "Fix"
« Reply #172 on: April 21, 2011, 09:30:59 AM »
Will do. Thanks.  We'll see what essexboy has to say later on.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Can't "Fix"
« Reply #173 on: April 21, 2011, 07:04:34 PM »
Here I be  ;D you also have a proxy setting and best malware hiding on your laptop - wave bye bye to them

There are also a few temporary files to go so it may take a little longerr than normal to complete the fix

Start OTS. Copy/Paste the information in the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

Code: [Select]
[Unregister Dlls]
[Registry - Safe List]
< Internet Explorer Settings [HKEY_CURRENT_USER\] > ->
YN -> HKEY_CURRENT_USER\: "ProxyEnable" -> 1
YN -> HKEY_CURRENT_USER\: "ProxyServer" -> http=127.0.0.1:25384
< HOSTS File > ([2011/04/14 14:41:49 | 000,002,130 | RHS- | M] - 247 lines) -> C:\WINDOWS\system32\drivers\etc\hosts
YN -> Reset Hosts ->
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\"{D4027C7F-154A-4066-A1AD-4243D8127440}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
YN -> "C:\Documents and Settings\All Users\Application Data\80888d\BM808_2112.exe" -> [C:\Documents and Settings\All Users\Application Data\80888d\BM808_2112.exe:*:Enabled:Best Malware Protection]
[Files/Folders - Created Within 30 Days]
NY ->  BMHQP -> C:\Documents and Settings\All Users\Application Data\BMHQP
NY ->  80888d -> C:\Documents and Settings\All Users\Application Data\80888d
[File - Lop Check]
NY ->  80888d -> C:\Documents and Settings\All Users\Application Data\80888d
NY ->  BMHQP -> C:\Documents and Settings\All Users\Application Data\BMHQP
[Empty Temp Folders]
[EmptyFlash]
[CreateRestorePoint]
 

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix.  Post that information back here

I will review the information when it comes back in.

rlakritz

  • Guest
Re: Can't "Fix"
« Reply #174 on: April 21, 2011, 08:34:50 PM »
Hi there, essexboy. I'm in the middle of running the OTS fix and keep getting a notice that a certain file has been deleted or moved and asking if I want to create it.  I said yes to a couple but now see that there are about 150 more.  What should I do? Thanks.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Can't "Fix"
« Reply #175 on: April 21, 2011, 08:42:03 PM »
What is the name of the files ? A few examples will do

rlakritz

  • Guest
Re: Can't "Fix"
« Reply #176 on: April 21, 2011, 08:44:48 PM »
I can only see one at a time as they pop up. The next one up is 00EE9D56d01

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Can't "Fix"
« Reply #177 on: April 21, 2011, 08:50:24 PM »
What is instigating the notice that the file is being moved ?   Is this while it is trying to remove the best malware folder BMHQP

rlakritz

  • Guest
Re: Can't "Fix"
« Reply #178 on: April 21, 2011, 08:59:06 PM »
I don't know what stage of the fix we're at.  The Paste Fix Here window now has 3 things listed:
[Empty Temp Folder]
[EmptyFlash]
[createRestorePoint]

The pop-up window says:

Copy Folder
The C:\Users\Susan\AppData\Local\Mozilla\Firefox\Profiles\chb...\00EE9D56d01 folder does not exist. The file may have been moved or deleted. Do you want to create it?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Can't "Fix"
« Reply #179 on: April 21, 2011, 10:06:28 PM »
Ah OK answer no to them all - as the main parts have run - it is just clearing the temps from the list it had in memory