![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#21 (permalink) |
|
Registered User
Join Date: Mar 2005
Posts: 72
OS: Win XP
|
I have downloaded the Hoster program and I have a question -
When I first doubleclicked the application to open it I got an error message telling me they couldn't open - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\Hosts but it opened the program anyway, then I clicked 'Restore Original Hosts' and I got this error message - I\O 32 What did I do wrong? Last edited by xdeeliciouzx; 03-23-2005 at 01:23 AM. |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#23 (permalink) |
|
TSF Enthusiast
|
Hello, sorry for the huge delay, that was my fault. I didn't get an email informing me of a reply and I didn't check myself.
Anyway...hoster. I need you to do a little check for me. Can you goto the start menu and click on run Type this in the open box explorer "C:\WINDOWS\SYSTEM32\DRIVERS\ETC\" This is the same as navigating to this folder, if for some reason this doesnt work open up "My Computer" and work through the folder upto "etc". In this folder you should see a file called "hosts", right click on it and choose properties. Near the bottom should be an attributes section, check that "read only" is not ticked. If it is, untick it and try running hoster again. If you have any problems with these instruction post back here. If it is not marked as read only post back here. |
|
|
|
|
#24 (permalink) |
|
Manager Emeritus - Security Center, Expert Analyst, Moderator - Security Team; Rangemaster, TSF Academy & Supporter
|
As an addon to Bob's suggestion..once you do that...open that file with wordpad. Copy and paste the contains here. I just want to confirm it's clean.
__________________
We Are The BORG Spyware KILLER and Adware Destroyer!
![]() ![]() ![]() Spyware/Adware Removal Tools Hijackthis Ad-aware SE Spybot Search&Destroy SpywareBlaster CWShredder |
|
|
|
|
#25 (permalink) |
|
Registered User
Join Date: Mar 2005
Posts: 72
OS: Win XP
|
Don't worry about the delay! I know you're busy! :) Thank you so much though!
BUT.. For some reason I keep getting the same Error Message like the one I first posted when trying to use Hoster.. I made sure that my Hosts file didn't have 'Read Only' checked.. What else could I have done wrong? |
|
|
|
|
#27 (permalink) |
|
Registered User
Join Date: Mar 2005
Posts: 72
OS: Win XP
|
I'm not sure if I did this right but I doubleclicked it and opened it with Notepad.. Here's what I got -
# Start of entries inserted by Spybot - Search & Destroy # End of entries inserted by Spybot - Search & Destroy # End of entries inserted by Spybot - Search & Destroy # End of entries inserted by Spybot - Search & Destroy # End of entries inserted by Spybot - Search & Destroy # End of entries inserted by Spybot - Search & Destroy # End of entries inserted by Spybot - Search & Destroy # End of entries inserted by Spybot - Search & Destroy 127.0.0.1 www.searchforit.com 127.0.0.1 www.nude-teens-bodies.com 127.0.0.1 www.on-search.com 127.0.0.1 www.search4www.com 127.0.0.1 searchx.cc 127.0.0.1 www.sp2admin.biz 127.0.0.1 www.heretofind.com 127.0.0.1 www.teenygirlshome.com 127.0.0.1 www.bundleware.com # ***Inserted By STOPzilla*** 127.0.0.1 www.teen-biz.com # ***Inserted By STOPzilla*** 127.0.0.1 localhost # ***Inserted By STOPzilla*** 127.0.0.1 www.zonebest.com # ***Inserted By STOPzilla*** |
|
|
|
|
#28 (permalink) | |
|
Manager Emeritus - Security Center, Expert Analyst, Moderator - Security Team; Rangemaster, TSF Academy & Supporter
|
Ok..the hosts file is kind of screwed as the entrys are in the wrong place. Open that file again with wordpad...right click..open with...then use wordpad. Highlight and delete all those entrys. Save the file and exit.
Now open spybot. Update it's database. Click tools...hosts files. Click "Add Spybot's-S&D Hosts list". Once complete..open the hosts file again and check it. It should look like this... ** Note** IN the hosts file there will be like 3-4 spaces between the IP and the names. This is also the most recent list from Patrick's Spybot and a few I added recently. Quote:
__________________
We Are The BORG Spyware KILLER and Adware Destroyer!
![]() ![]() ![]() Spyware/Adware Removal Tools Hijackthis Ad-aware SE Spybot Search&Destroy SpywareBlaster CWShredder |
|
|
|
|
|
#29 (permalink) |
|
Registered User
Join Date: Mar 2005
Posts: 72
OS: Win XP
|
GAH.. I'm sorry.. yet another problem --
When I opened SpyBot S&D I couldn't find the Tools option..? I saw 'Check for Updates' and that was it.. Recently I've tried to run SpyBot and everytime I get this message in the results area that says - Error During Check Common HiJacker Where can the Tools Option be found? So sorry.. I'm SO incompetent when it comes to these things..! |
|
|
|
|
#31 (permalink) |
|
Registered User
Join Date: Mar 2005
Posts: 72
OS: Win XP
|
Whenever I click the Hosts File to try and open it I get an error message that reads -
Datei C:\Windows\system32\drivers\etc\hosts\kann nicht geofnett werden. The process can not access the file because it being used by another process. What should I do? Thank you again for all your help! |
|
|
|
|
#32 (permalink) |
|
Manager Emeritus - Security Center, Expert Analyst, Moderator - Security Team; Rangemaster, TSF Academy & Supporter
|
Close down STOPzilla. Your not using another program to lock the hosts file are you?
__________________
We Are The BORG Spyware KILLER and Adware Destroyer!
![]() ![]() ![]() Spyware/Adware Removal Tools Hijackthis Ad-aware SE Spybot Search&Destroy SpywareBlaster CWShredder |
|
|
|
|
#33 (permalink) |
|
Registered User
Join Date: Mar 2005
Posts: 72
OS: Win XP
|
I'm pretty sure my Stopzilla isn't running.. and I'm really not sure if I have another program locking my hosts file.
I'm pretty much clueless when it comes to things like these, which is why I've come to you guys for help.. heh. Thank you! |
|
|
|
|
#35 (permalink) |
|
Analyst, Security Team
|
You mentioned earlier that you could open up the file just by double clicking on it. That shouldn't happen, unless it has a .doc/.txt extension. Make sure that the hosts file has no extensions at all. It's just suppose to say hosts and nothing else as the filename.
Could you open up the hosts file in Safe Mode?
__________________
Please do NOT PM me. Post whatever questions you may have in the forum and we will take a look at it when we get to it. If you have waited for more than 3 days, you may then and ONLY then PM me for assistance. I will take a look at it. |
|
|
|
|
#39 (permalink) |
|
TSF Enthusiast
|
Hello, a few things for you to try
If you have a fast internet connection (broadband), run an online scan at Trend Micro or RAV Antivirus. Please select the autoclean option when using Trend Micro. Run another HijackThis log and post it up here. For the hosts file, can you download WhoLockMe Unzip the files to there own folder and run the install file. This will add an extention to the right click menu in explorer. Navigate to the hosts file again, right click on it and chose "Who Lock Me?". If there is a program running that has a lock on this file it will trace it and a box will come up showing the programs name and location, note it and post it up here. If there is no program running with a lock on hosts nothing will happen. Lastly, how is the computer running, are the original issues with popups still happening? |
|
|
|
|
#40 (permalink) |
|
Registered User
Join Date: Mar 2005
Posts: 72
OS: Win XP
|
Thank you for the help once again!
Here's my HJT Log - Logfile of HijackThis v1.99.1 Scan saved at 9:05:41 AM, on 3/25/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\STOPzilla!\SZServer.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\COMMON~1\aol\ACS\AOLacsd.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe C:\Program Files\BellSouth Internet Tools\blsloader.exe C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe C:\PROGRA~1\McAfee.com\Agent\McAgent.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe c:\progra~1\mcafee.com\vso\mcvsescn.exe C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe C:\Program Files\SpywareGuard\sgmain.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\SpywareGuard\sgbhp.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe C:\Program Files\LimeWire\LimeWire.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Dee\Desktop\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bellsouth.net/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = www.firefox.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bellsouth.net/ O2 - BHO: BlspcHlpr Class - {15C9938F-CB96-496D-800A-B827F2E34EA1} - C:\Program Files\BellSouth Internet Tools\blspc.dll O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O4 - HKLM\..\Run: [blspcloader] "C:\Program Files\BellSouth Internet Tools\blsloader.exe" O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\McAfee.com\Agent\McAgent.exe O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" O4 - HKLM\..\Run: [STOPzilla] C:\Program Files\STOPzilla!\Stopzilla.exe /autostart O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing) O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O20 - Winlogon Notify: STOPzilla - C:\WINDOWS\SYSTEM32\IS3WLHandler.dll O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\aol\ACS\AOLacsd.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - McAfee, Inc. - c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe O23 - Service: STOPzilla Service (szserver) - Unknown owner - C:\Program Files\Common Files\STOPzilla!\SZServer.exe O23 - Service: Windows User Mode Driver Framework (UMWdf) - Unknown owner - C:\WINDOWS\system32\wdfmgr.exe (file missing) O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe I DLed WhoLockMe? but then again I can look at the file in SpyBot. When I tried to look at the Hosts File it gives me the same error message - Datei C:\Windows\system32\drivers\etc\hosts\kann nicht geofnett werden. The process can not access the file because it being used by another process. Also, my computer is running A LOT better! No more pop-ups and whatnot. I just can't look at that file. Oh, and whenever I try to run SpyBot to check for problems it tells me there's an error during check - common hijacker. |
|
|
| Thread Tools | |
|
|