Resolve Target Host Question

Discussion in 'Trojan Defence Suite' started by lostsoul, Jun 25, 2004.

Thread Status:
Not open for further replies.
  1. lostsoul

    lostsoul Registered Member

    Joined:
    Jun 24, 2004
    Posts:
    13

    It seems obvious in hindsight as the odd behaviour began after I reinstalled Spybot. ::smacking hand repeatedly against forehead:: :rolleyes:

    I reckon the test will be when I go back to the Yahoo Game rooms to see if anything happens and if I get odd port readings.

    I do not feel lucky enough to try my hand at it right now.

    THANK YOU for figuring it out FanJ!!

    LS
     
  2. lostsoul

    lostsoul Registered Member

    Joined:
    Jun 24, 2004
    Posts:
    13
    I'm falling behind on the posts as I'm just getting the hang of posting here. I just sent a reply to your post about the Hosts file and it makes perfect sense.

    I'm forever in your debt! :D

    LS
     
  3. FanJ

    FanJ Guest

    Hi Lostsoul :)

    No problem, I'm glad you seem to have fixed it :)

    I have to admit that I myself only use Spybot S&D for on-demand scanning, so I have to leave the answer why it did that on your system to other more experienced users of Spybot S&D :oops:

    If you like, since you're using TDS-3, you could add your HOSTS file to your CRCfiles.txt.
    See for more:
    TDS-3 CRC32-test Guidelines
    Please keep in mind that the CRC32 check of TDS-3 will only show if a file has been changed, but not why nor what changes have been made.

    If you like, you could always post your HijackThis-log following these guidelines:
    HOW TO? Read here about how to post your log!!
     
  4. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    Hi there,
    followed this thread, lots to learn and to look at.

    The HOSTS file, somewhere FanJ posted to lock it, if i remember well it is right-click to see the properties and change the attributes to "read only"
    If i missed something FanJ will correct this.

    You can view your HOSTS file as well (and edit if you did not just lock it) via TDS too: TDS > System Analysis > View File > Network Hosts
    That should open your HOSTS file to look at.

    You said you can't use the wordpad and most probably notepad either in such cases.
    Look for files 0 bytes small in your TDS directory and maybe in more locations, which you can delete, certainly if they are named wordpad.exe or notepad.exe 0 bytes small. Windows makes them, TDS catches them in it's directory, and thus when trying to use one of them from TDS windows looks at the 0 bytes version and thus fails. My own solution: copy the original wordpad.exe and notepad.exe from the windows directory into the TDS directory (they're only around 56 kb small so that is not too bad) and you should be able to use your wordpad and notepad well again, no matter how many times windows creates the 0 bytes version again.

    If you did not post your HiJackThis log in the forum yet, please do so for the experts to check; did not see an earlier one of you in the forums here yet?
    You could also as an extra post the AutoStartViewer log (from the DiamondCS products page) which shows even more then the HJT, but needs an expert view from Gavin.

    For the questions relating Port Explorer if you did not do so yet please open a new thread for that in that forum so we can help you with that information.


    BTW: the portref.dat for Port Explorer (update via Port Explorer > Help > Check For > New Port and Domain Databases ) and portref.txt TDS (update downloading via the TDS website) have a different extension and way of updating, but the ports are the same.
     
  5. Dazed_and_Confused

    Dazed_and_Confused Registered Member

    Joined:
    Mar 4, 2004
    Posts:
    1,831
    Location:
    USA
    Jooske - No one ever answered one of my questions above. How is it possible the host file infection was not eliminated after a reformat? His assertion that he just completed a reformat of the PC sent me completely off in a different direction. Thanks. :)
     
  6. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    Had the impression that came with using the SpybotS&D which seems to have changed the HOSTS file sin this case after the reformat; it's the only possibility i see, unless a backup (with the same infections included) was put back on the cleansed discs.

    If it is corrected now and comes back, it's either again a SBS&D activity or a nasty on the system somewhere still.......
     
  7. Dazed_and_Confused

    Dazed_and_Confused Registered Member

    Joined:
    Mar 4, 2004
    Posts:
    1,831
    Location:
    USA
    Thanks, Jooske. I'm a little baffled as to why S&D would edit the Hosts file in that way. I use S&D, and have not seen that problem.
     
  8. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    Me neither, and i'm between updating it myself to see what happens or wait till more is posted about it in the forum.
     
  9. FanJ

    FanJ Guest

    Hi D&C,

    Sorry, I completely forgot your question.

    Same as you and Jooske: I have to admit that I too am not sure what was causing this thing in the HOSTS file on the system of Lostsoul :oops:
    I agree with Jooske: it would be a good idea if Lostsoul would post a HijackThis-log (and/or AutoStartViewer-log).

    Sorry again D&C !
    Cheers, Jan.
     
  10. dvk01

    dvk01 Global Moderator

    Joined:
    Oct 9, 2003
    Posts:
    3,131
    Location:
    Loughton, Essex. UK
    This is a copy of a post made my Lowwatermark one of the administrators which suggest it ios a fault with the way spybot adds to the hosts file and not a genuine sign of an infection

     
  11. Dazed_and_Confused

    Dazed_and_Confused Registered Member

    Joined:
    Mar 4, 2004
    Posts:
    1,831
    Location:
    USA
    Very interesting! Thanks dvk01 for the info. :D
     
  12. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    This explains why there was nothing added of the kind in my HOSTS file.
    FanJ i was very brave and upgraded my SBS&D, forced to as the older did not update anymore.
    Looks much better, more options.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.