being attacked by 208.73.210.29; MBAB blocking outbound access every 5-10 minutes
#21
Posted 29 April 2012 - 07:10 AM
I have been using Firefox.
I started OTL from my desktop and clicked the Scan All Users box. The scan was humming along and then just seemed to crash when it got to 'scanning Chrome settings'.
I got an error message that did not stay on screen long but sadi something like "File List out of bounds"
Now the scan seems to just be stuck.
#22
Posted 29 April 2012 - 07:13 AM
LIst index out of bounds 433
#23
Posted 29 April 2012 - 07:21 AM
Uninstall Firefox and any related file/folders and reinstall.
Let me know, MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#24
Posted 29 April 2012 - 09:59 AM
#25
Posted 29 April 2012 - 10:11 AM
#26
Posted 29 April 2012 - 10:15 AM
being attacked by 208.73.210.29
Reinstall Chrome and /or FF and see what happens.
MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#27
Posted 29 April 2012 - 10:17 AM
I did not remove all of my FF personal settings and bookmarks when I uninstalled.
#28
Posted 29 April 2012 - 10:24 AM
Quote
That's where the problem may be, old bookmarks and RSS feeds.
Let me know, MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#29
Posted 29 April 2012 - 10:25 AM
#30
Posted 29 April 2012 - 10:35 AM
also, tried to re-run OTL, and it still got stuck at scanning Chrome settings and gave the List index out of bounds messge.
#31
Posted 29 April 2012 - 10:47 AM
#32
Posted 29 April 2012 - 10:59 AM
#33
Posted 29 April 2012 - 12:59 PM
Like I said before, I saw someone say a week or so ago that this infection was caused by a bookmark or RSS feed in Firefox, I was reading another post on this forum this morning and it looks like that's exactly what the problem was.
So take a look at your bookmarks in FF and delete any strange ones.
Here's the link to the post I was referring to:
http://forums.malwar...ndpost&p=547206
=============================
For OTL.....
Please do this:
Run OTL
- Under the Custom Scans/Fixes box at the bottom, paste in the following
:OTL O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. [2011/11/22 06:43:04 | 000,000,000 | ---D | M] -- C:\Users\Craig Parker\AppData\Roaming\BaammH66sW [2011/11/22 06:42:54 | 000,000,000 | ---D | M] -- C:\Users\Craig Parker\AppData\Roaming\nSSS11ivD [2011/11/22 06:47:23 | 000,000,000 | ---D | M] -- C:\Users\Craig Parker\AppData\Roaming\O6dWW77fL9gXjYe [2011/11/22 07:16:07 | 000,000,000 | ---D | M] -- C:\Users\Craig Parker\AppData\Roaming\OfEELL9gTZqjC [2011/11/22 06:43:03 | 000,000,000 | ---D | M] -- C:\Users\Craig Parker\AppData\Roaming\OPPP0uucS1ib3oG [2011/11/22 06:47:23 | 000,000,000 | ---D | M] -- C:\Users\Craig Parker\AppData\Roaming\oxA00vv2ibFpGaQ [2011/11/22 06:42:53 | 000,000,000 | ---D | M] -- C:\Users\Craig Parker\AppData\Roaming\wNttxxA0ucS2b :Commands [EMPTYJAVA] [emptytemp]
- Then click the Run Fix button at the top
- Let the program run unhindered, when done it will say "Fix Complete press ok to open the log"
- Please post that log in your next reply. Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#34
Posted 29 April 2012 - 01:53 PM
I opened OTL and pasted the fix you asked me to run. Here are the results:
OTL by OldTimer - Version 3.2.42.1 log created on 04292012_134702
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
#35
Posted 29 April 2012 - 01:55 PM
The MBAM pop up box is still occasionally appearing saying MBAM blocked access to a potentially malicious site with the same IP address -- 208.73.210.29
Sorry to hear about your main machine -- hopefully it can be resurrected!
#36
Posted 29 April 2012 - 01:57 PM
Here it is:
:OTL
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
[2011/11/22 06:43:04 | 000,000,000 | ---D | M] -- C:\Users\Craig Parker\AppData\Roaming\BaammH66sW
[2011/11/22 06:42:54 | 000,000,000 | ---D | M] -- C:\Users\Craig Parker\AppData\Roaming\nSSS11ivD
[2011/11/22 06:47:23 | 000,000,000 | ---D | M] -- C:\Users\Craig Parker\AppData\Roaming\O6dWW77fL9gXjYe
[2011/11/22 07:16:07 | 000,000,000 | ---D | M] -- C:\Users\Craig Parker\AppData\Roaming\OfEELL9gTZqjC
[2011/11/22 06:43:03 | 000,000,000 | ---D | M] -- C:\Users\Craig Parker\AppData\Roaming\OPPP0uucS1ib3oG
[2011/11/22 06:47:23 | 000,000,000 | ---D | M] -- C:\Users\Craig Parker\AppData\Roaming\oxA00vv2ibFpGaQ
[2011/11/22 06:42:53 | 000,000,000 | ---D | M] -- C:\Users\Craig Parker\AppData\Roaming\wNttxxA0ucS2b
:Commands
[EMPTYJAVA]
[emptytemp]
MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#37
Posted 29 April 2012 - 02:02 PM
All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
File PTYJAVA] not found.
File ptytemp] not found.
OTL by OldTimer - Version 3.2.42.1 log created on 04292012_135937
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
#38
Posted 29 April 2012 - 02:18 PM
#39
Posted 29 April 2012 - 02:51 PM
MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#40
Posted 29 April 2012 - 02:55 PM
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users



This topic is locked









