Please help!
MBAM frequently blocking outbound access to malicious site 208.73.210.29
Started by captarheel, Jul 04 2012 07:08 PM
#1
Posted 04 July 2012 - 07:08 PM
#2
Posted 05 July 2012 - 06:04 AM
Welcome to the forum again, please start at the link below:
http://forums.malwar...?showtopic=9573
Post back the 2 logs.....DDS.txt and Attach.txt
<====><====><====><====><====><====><====><====>
Next.......
Please remove any usb or external drives from the computer before you run this scan!
Please download and run RogueKiller.
For Windows XP, double-click to start.
For Vista or Windows 7, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.
Click Scan to scan the system (don't run any other options, they're not all bad!!!!!!)
Post back the report.
MrC
http://forums.malwar...?showtopic=9573
Post back the 2 logs.....DDS.txt and Attach.txt
<====><====><====><====><====><====><====><====>
Next.......
Please remove any usb or external drives from the computer before you run this scan!
Please download and run RogueKiller.
For Windows XP, double-click to start.
For Vista or Windows 7, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.
Click Scan to scan the system (don't run any other options, they're not all bad!!!!!!)
Post back the report.
MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#3
Posted 05 July 2012 - 08:43 AM
Hi Mr. C.,
I have absolutely no idea where this came from again, but I would appreciate your help. Here are the logs you requested:
DDS.txt 20.83K
15 downloads
Attach.zip 2.51K
18 downloads
RKreport1.txt 1.26K
16 downloads
I have absolutely no idea where this came from again, but I would appreciate your help. Here are the logs you requested:
DDS.txt 20.83K
15 downloads
Attach.zip 2.51K
18 downloads
RKreport1.txt 1.26K
16 downloads
#4
Posted 05 July 2012 - 10:16 AM
I don't see anything so far, lets run some scans.....
Please make sure system restore is running and create a new restore point before continuing.
XP <===> Vista & W7
XP users > please back up the registry using ERUNT.
-----------------------------------------
Please download and run TDSSKiller to your desktop as outlined below:
Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
For Windows XP, double-click to start.
For Vista or Windows 7, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.

-------------------------
Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.

------------------------
Click the Start Scan button.

-----------------------
If a suspicious object is detected, the default action will be Skip, click on Continue
If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose
Skip and click on Continue
Any entries like this: \Device\Harddisk0\DR0 ( TDSS File System ) - please choose delete.

----------------------
If malicious objects are found, they will show in the Scan results and offer three (3) options.
Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

--------------------
A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.
Sometimes these logs can be very large, in that case please attach it or zip it up and attach it.
-------------------
Here's a summary of what to do if you would like to print it out:
If a suspicious object is detected, the default action will be Skip, click on Continue
If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose
Skip and click on Continue
Any entries like this: \Device\Harddisk0\DR0 ( TDSS File System ) - please choose delete.
If malicious objects are found, they will show in the Scan results and offer three (3) options.
Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
MrC
Please make sure system restore is running and create a new restore point before continuing.
XP <===> Vista & W7
XP users > please back up the registry using ERUNT.
-----------------------------------------
Please download and run TDSSKiller to your desktop as outlined below:
Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
For Windows XP, double-click to start.
For Vista or Windows 7, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.

-------------------------
Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.

------------------------
Click the Start Scan button.

-----------------------
If a suspicious object is detected, the default action will be Skip, click on Continue
If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose
Skip and click on Continue
Any entries like this: \Device\Harddisk0\DR0 ( TDSS File System ) - please choose delete.

----------------------
If malicious objects are found, they will show in the Scan results and offer three (3) options.
Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

--------------------
A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.
Sometimes these logs can be very large, in that case please attach it or zip it up and attach it.
-------------------
Here's a summary of what to do if you would like to print it out:
If a suspicious object is detected, the default action will be Skip, click on Continue
If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose
Skip and click on Continue
Any entries like this: \Device\Harddisk0\DR0 ( TDSS File System ) - please choose delete.
If malicious objects are found, they will show in the Scan results and offer three (3) options.
Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#5
Posted 05 July 2012 - 10:40 AM
Made System Restore point. Ran TDSSKiller. Only saw three items of medium risk. "Cure" was not an option, so I selected "skip" and continue. Report zipped and attached
#6
Posted 05 July 2012 - 10:46 AM
That scan was clean......
Please download and run ComboFix.
The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.
Please visit this webpage for download links, and instructions for running ComboFix
http://www.bleepingc...to-use-combofix
Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Information on disabling your malware programs can be found Here.
Make sure you run ComboFix from your desktop.
Give it at least 30-45 minutes to finish if needed.
Please include the C:\ComboFix.txt in your next reply for further review.
MrC
Please download and run ComboFix.
The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.
Please visit this webpage for download links, and instructions for running ComboFix
http://www.bleepingc...to-use-combofix
Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Information on disabling your malware programs can be found Here.
Make sure you run ComboFix from your desktop.
Give it at least 30-45 minutes to finish if needed.
Please include the C:\ComboFix.txt in your next reply for further review.
---------->NOTE<----------
If you get the message Illegal operation attempted on registry key that has been marked for deletion after you run ComboFix....please reboot the computer, this should resolve the problem. You may have to do this several times if needed.MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#7
Posted 05 July 2012 - 11:27 AM
ran combo fix as administrator from desktop.
Log attached:
Log attached:
#8
Posted 05 July 2012 - 11:59 AM
That looks OK.
The last time resetting Internet Explorer back to defaults seemed to clear it up, give it a try:
http://forums.malwar...ndpost&p=547651
also do you still have MVPS HOSTS installed?
MrC
The last time resetting Internet Explorer back to defaults seemed to clear it up, give it a try:
http://forums.malwar...ndpost&p=547651
also do you still have MVPS HOSTS installed?
MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#9
Posted 05 July 2012 - 02:20 PM
Okay. I reset IE again and deleted all personal data. I normally use Firefox, so don't know if resetting IE will do anything. I am still getting the MBAM blocking access message even after resettinng IE.
I never changed the hosts file after you gave me the MVPS link. I liked how that blocked even the sponsored ads on Google.
Last time we uninstalled Firefox and reinstalled it and that didn't seem to make any difference. That's a huge pain since I lose all bookmarks (I don't have many that I have created this time), but still . . . .
Will follow your directions -- what's next?
I never changed the hosts file after you gave me the MVPS link. I liked how that blocked even the sponsored ads on Google.
Last time we uninstalled Firefox and reinstalled it and that didn't seem to make any difference. That's a huge pain since I lose all bookmarks (I don't have many that I have created this time), but still . . . .
Will follow your directions -- what's next?
#10
Posted 05 July 2012 - 02:30 PM
also, just staring yesterday, I am getting strange spam emails with addresses like the following: 7069823922@vtext.com
#11
Posted 05 July 2012 - 03:06 PM
I don't think you have MVPS hosts installed anymore because RogueKiller shows the default host file:
Please do this.....
Download MiniToolBox:
http://download.blee...MiniToolBox.exe
Right click MiniToolBox and select " Run as administrator " to run it.
Check the following in the list:
List content of Hosts
Click Go
Please post the contents of the Result.txt in your next Reply.
MrC
Quote
¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost
127.0.0.1 localhost
Please do this.....
Download MiniToolBox:
http://download.blee...MiniToolBox.exe
Right click MiniToolBox and select " Run as administrator " to run it.
Check the following in the list:
List content of Hosts
Click Go
Please post the contents of the Result.txt in your next Reply.
MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#12
Posted 05 July 2012 - 03:25 PM
I may have deleted the MVPS hosts by telling Rogue Killer to reset the hosts file. My mistake. I did that yesterday. Here is the MiniToolbox report
MiniToolBox by Farbar Version: 25-06-2012
Ran by Craig Parker (administrator) on 05-07-2012 at 15:24:06
Microsoft Windows 7 Home Premium (X64)
Boot Mode: Normal
***************************************************************************
========================= Hosts content: =================================
127.0.0.1 localhost
**** End of log ****
MiniToolBox by Farbar Version: 25-06-2012
Ran by Craig Parker (administrator) on 05-07-2012 at 15:24:06
Microsoft Windows 7 Home Premium (X64)
Boot Mode: Normal
***************************************************************************
========================= Hosts content: =================================
127.0.0.1 localhost
**** End of log ****
#13
Posted 05 July 2012 - 04:07 PM
You should reinstall it.
Can you post the protection log from MB that shows the ip blocks. MrC
Can you post the protection log from MB that shows the ip blocks. MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#14
Posted 05 July 2012 - 07:22 PM
will reinstall after this post.
Here is the MB log from today:
Here is the MB log from today:
#15
Posted 05 July 2012 - 07:35 PM
I uninstalled FF and logged on using IE. Still getting MBAM blocking messages.
#16
Posted 06 July 2012 - 06:13 AM
Read through this post and see if any of it works for you:
http://forums.malwar...ndpost&p=546749
--------------------------------
Please download OTL from one of the links below:
http://oldtimer.geekstogo.com/OTL.exe
http://oldtimer.geekstogo.com/OTL.com (<---renamed version)
Save it to your desktop.
Double click on the icon on your desktop.
Click the Scan All Users checkbox.
Push the Quick Scan button.
The scan will take about 10 minutes...depends on your hard drive size.
Two reports will open, copy and paste them in a reply here: (or attach them as .txt files)
OTL.txt <-- Will be opened
Extra.txt <-- Will be minimized
MrC
http://forums.malwar...ndpost&p=546749
--------------------------------
Please download OTL from one of the links below:
http://oldtimer.geekstogo.com/OTL.exe
http://oldtimer.geekstogo.com/OTL.com (<---renamed version)
Save it to your desktop.
Double click on the icon on your desktop.
Click the Scan All Users checkbox.
Push the Quick Scan button.
The scan will take about 10 minutes...depends on your hard drive size.
Two reports will open, copy and paste them in a reply here: (or attach them as .txt files)
OTL.txt <-- Will be opened
Extra.txt <-- Will be minimized
MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#17
Posted 06 July 2012 - 06:33 AM
Reading other post now. In the meantime, I ran OTL. I have attached the txt file. I could not find a file called "extra". Can you please tell me where to look?
#18
Posted 06 July 2012 - 06:53 AM
I totally deleted Firefox and all personal information. am now using IE. Still getting the IP block messages from MBAM. Same outbound address.
I read the other post, and saw the suggestion for some OTL fixes, but I was not able to fully copy the suggested fixes -- I couldn't figure out how to pick up the text outside the visible area of the text box and I couldn't get the scroll bar to work at the same time as trying to copy. As such, I have not run any of those suggested fixes.
I read the other post, and saw the suggestion for some OTL fixes, but I was not able to fully copy the suggested fixes -- I couldn't figure out how to pick up the text outside the visible area of the text box and I couldn't get the scroll bar to work at the same time as trying to copy. As such, I have not run any of those suggested fixes.
#19
Posted 06 July 2012 - 07:04 AM
Not much showing.
Can you take a look at these two folders, let me know if you recognize them:
C:\Users\Craig Parker\AppData\Roaming\5E6DB
C:\Users\Craig Parker\AppData\Roaming\8875E
---------------------------------
Please do this:
Run OTL
Can you take a look at these two folders, let me know if you recognize them:
C:\Users\Craig Parker\AppData\Roaming\5E6DB
C:\Users\Craig Parker\AppData\Roaming\8875E
---------------------------------
Please do this:
Run OTL
- Under the Custom Scans/Fixes box at the bottom, paste in the following
:OTL O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found :Commands [EMPTYJAVA] [emptytemp]
- Then click the Run Fix button at the top
- Let the program run unhindered, when done it will say "Fix Complete press ok to open the log"
- Please post that log in your next reply. Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#20
Posted 06 July 2012 - 07:16 AM
I do not recognize those two folders. I opened them and they are both empty.
ran the fix -- here's the log:
All processes killed
Error: Unable to interpret <:OTLO3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.O18:64bit: - Protocol\Handler\ms-help - No CLSID value found:Commands[EMPTYJAVA][emptytemp]> in the current context!
OTL by OldTimer - Version 3.2.42.2 log created on 07062012_071209
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
ran the fix -- here's the log:
All processes killed
Error: Unable to interpret <:OTLO3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.O18:64bit: - Protocol\Handler\ms-help - No CLSID value found:Commands[EMPTYJAVA][emptytemp]> in the current context!
OTL by OldTimer - Version 3.2.42.2 log created on 07062012_071209
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users

Sign In
Create Account
This topic is locked

Back to top









