WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionMBAM keeps blocking an IP - Page 1 EmptyRe: MBAM keeps blocking an IP

more_horiz
You are running old versions of Java, Mozilla Firefox, VLC Video Player, Acrobat Reader. You should uninstall them and install the newest version.

I´m looking through your logs and I don´t really see anything yet.

descriptionMBAM keeps blocking an IP - Page 1 EmptyRe: MBAM keeps blocking an IP

more_horiz
Okl, there is something I don´t quite like in your aswMBR log - it failed to properly read your MBR, so we´re going to use a boot disk to be able to read you MBR and see if anything is wrong with it. It is a bit of work, but for a good purpose Smile...

Please download MBRCheck by a_d_13 from either of the following mirrors and save it to your system disk (probably C:\).


You have already downloaded aswMBR.exe, please copy that tool to your system disk (C:\) as well.

We are going to create a boot CD to help us with your problem.

  • You will need a blank CD to burn the boot CD
  • Download OTLPEStd.exe by OldTimer from here (a big download)
  • Double-click on OTLPEStd.exe to burn the boot CD
  • Reboot your system using the boot CD you just created. If you don´t know how to boot from CD, check out this page
  • Booting will take quite some time, so please be patient
  • Finally you should see the REATOGO-X-PE desktop.
  • Browse to your system disk, run mbrcheck.exe and post the resulting log back here.
  • Also run aswMBR.exe and post the resulting log back here.


descriptionMBAM keeps blocking an IP - Page 1 EmptyRe: MBAM keeps blocking an IP

more_horiz
its not letting me boot from my cd. is there another way of doing this? Thank you

descriptionMBAM keeps blocking an IP - Page 1 EmptyRe: MBAM keeps blocking an IP

more_horiz
So you burned the CD, but you cannot boot from it?

That is weird, every computer should be able to boot from the CD
What kind of computer do you have?

descriptionMBAM keeps blocking an IP - Page 1 EmptyRe: MBAM keeps blocking an IP

more_horiz
I have a HP laptop..i burned the cd and i tried rebooting it, but it keeps asking me if i want to start up my windows normally

descriptionMBAM keeps blocking an IP - Page 1 EmptyRe: MBAM keeps blocking an IP

more_horiz
OK, we need to go a little bit more into the details, otherwise I don´t understand where exactly it goes wrong.

You burned the CD and it is in your CD drive
You restart the computer and you try and boot from the CD, correct?

Now where exactly does it go wrong. Is the CD found? Do you notice that your computer is trying to read the disk? Or does it skip directly to a normal windows boot?
if it tries to boot from the CD, what messages appear?

It could be that the CD is not recognized as a boot CD because something went wrong in the burn process, for example

descriptionMBAM keeps blocking an IP - Page 1 EmptyRe: MBAM keeps blocking an IP

more_horiz
When i boot from the CD, it reads for a little bit and then it jumps to the screen where it ask's me if i want to start windows normally or start in safe mode etc. it did it 3 times. When i burnt the CD, i tested to see if it burned and the data was there.

descriptionMBAM keeps blocking an IP - Page 1 EmptyRe: MBAM keeps blocking an IP

more_horiz
Sad tearing

Well if that does not work, lets try another tool.

In the following step we are going to disable any CD-emulation drivers you might be running (e.g. Daemon tools, Roxio). These drivers can be a source of problems (blue screens, false positives) for our anti-malware tools. We will not re-enable them until after we clean up your machine.

Download DeFogger by jpshortstuff from here and save it to your Desktop.

  • Doubleclick DeFogger.exe to run the tool (rightclick > Run as Administrator for Windows Vista)
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A Finished! message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK

If you receive an error message while running DeFogger, please post the defogger_disable log that will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.

====================

Download GMER Rootkit Scanner from here and save it to your desktop.
Note that it will have a random name.

  • Double click the file to run the tool. It may take a while to load.
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan, click No
  • In the right panel, you will see several boxes that have been checked
  • Make sure this is unchecked: Show All
  • Make sure only your system drive (usually C:\) is checked and uncheck all other drives you might have on your system
  • Click Scan to start the scan
  • When it has finished, click Save and save the log as gmer.txt on your desktop
  • If GMER reports any <--- ROOTKIT entries, don´t take any action. It could be a false positive.
  • Click OK to quit GMER.
  • Please post the contents of gmer.txt into your next reply.

descriptionMBAM keeps blocking an IP - Page 1 EmptyRe: MBAM keeps blocking an IP

more_horiz
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-10-17 20:50:53
Windows 6.1.7600
Running: icupq9s6.exe


---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x17 0x27 0x3F 0x23 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x30 0x6A 0x18 0x24 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x80 0xB3 0x88 0x27 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x17 0x27 0x3F 0x23 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x30 0x6A 0x18 0x24 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x80 0xB3 0x88 0x27 ...

---- EOF - GMER 1.0.15 ----

descriptionMBAM keeps blocking an IP - Page 1 EmptyRe: MBAM keeps blocking an IP

more_horiz
OK so that looks fine.
Seems to me that your computer is not infected with anything.
But various programs you have installed are outdated and you should update them.
====================

You have an old version installed of Adobe Reader. This old version has security issues.
I recommend that you uninstall Adobe Reader through Start > Control Panel > Add or Remove Programs.
After that you should install a PDF reader that is more secure.
Please note that Adobe Reader has a history of security issues and is a prime target for malware writers due to its popularity. You might want to consider installing a non-Adobe PDF reader. Your choice!
  • Adobe Reader 10. The last and most safest version of Adobe Reader.
  • SumatraPDF. Very small and very light PDF viewer.
  • PDF XChange. Also available in 64-bit version if you have a 64-bit OS. Can be installed as portable.

====================

You need to install the latest version of Java. Having the latest version is important to take advantage of fixes that have eliminated security vulnerabilities.
  • Go to Start > Control Panel
  • Double-click on Add or Remove Programs
  • Look for entries that say Java, Java RunTime Environment or J2SE.
  • Uninstall all of them that are not named Java (TM) 6 Update 27

After doing this, you can go to java.com, click on Free Java Download and proceed from there to install the latest version of Java (currently Version 6 Update 27).

After installing Java, go to Start > Control Panel > Java to open the Java Control Panel.
Under the General tab, Temporary Internet Files click Settings, then click Delete Files.
Select both options and click OK to delete the Java cache.

====================

You do not have the latest version of Mozilla Firefox installed. Browsers are the prime target of malware writers. Having Firefox updated is important, because it will have less security holes than any previous version. I recommend you upgrade to version 7.0.1 which can be downloaded here.
====================

Do you have any more questions or do you want to see my ALORTKYCC (Awesome List Or Recommendations To Keep Your Computer Clean)?

descriptionMBAM keeps blocking an IP - Page 1 EmptyRe: MBAM keeps blocking an IP

more_horiz
can you help me with my desktop? to see if its clean or not? i keep getting a blue screen of death...should i continue to post here or start a new thread? and should i scan it wtih OTL and put the log here?

descriptionMBAM keeps blocking an IP - Page 1 EmptyRe: MBAM keeps blocking an IP

more_horiz
For another computer., please start a new thread.

descriptionMBAM keeps blocking an IP - Page 1 EmptyRe: MBAM keeps blocking an IP

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum