Canreef Aquatics Bulletin Board  

Go Back   Canreef Aquatics Bulletin Board > Other > Lounge

Reply
 
Thread Tools Display Modes
  #1  
Old 01-02-2009, 08:15 PM
mark's Avatar
mark mark is offline
Member
 
Join Date: Nov 2002
Location: Edmonton AB
Posts: 4,212
mark is on a distinguished road
Default these sites down?

Picked up some spyware the other day and think I got some of it with the old definitions I had, but now if I try to update Spybot or SuperantiSpyware, I can't.

I've allowed the sites through the firewall as done updates before and even turn the firewall off but can't connect to http://www.spybot.info/ or http://www.superantispyware.com/ .

These sites should be okay as show as the sites home page and come up on google, but could someone try them. Not sure if being paranoid that whatever I got is blocking them or they're just down. There's still something as everytime I open a link in Firefox (default is in a new tab) a second window tries to start (http://sagipsul.com/...).
Reply With Quote
  #2  
Old 01-02-2009, 09:43 PM
Pescador's Avatar
Pescador Pescador is offline
Member
 
Join Date: Apr 2002
Location: Calgary, McKenzie Towne
Posts: 447
Pescador is on a distinguished road
Default

They both worked fine for me with Safari Mark.
__________________
Brian
____________________________________________
220g inwall 48"x36"x30"
110g mangrove refug/sump
Poison Dart Frog Vivarium
Reply With Quote
  #3  
Old 01-02-2009, 10:19 PM
Powertec Powertec is offline
Member
 
Join Date: Jan 2008
Location: Airdrie
Posts: 153
Powertec is on a distinguished road
Default

Hi Mark

Im on firefox and they all open fine for me as we'll.
Reply With Quote
  #4  
Old 01-03-2009, 05:41 AM
midgetwaiter midgetwaiter is offline
Member
 
Join Date: Nov 2005
Location: Calgary
Posts: 546
midgetwaiter is on a distinguished road
Default

open the file c:\windows\system32\drivers\etc\hosts in notepad.

You should see this:
Code:
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
#      102.54.94.97     rhino.acme.com          # source server
#       38.25.63.10     x.acme.com              # x client host

127.0.0.1       localhost
::1             localhost
The last line may be missing in XP, no biggie.

Some spyware will insert additional entries in the file. This file is used to maintain a list of hosts and their numerical addresses so your computer can figure out just who www.whatever.com is. With your internet connection this mapping is provided by your DNS servers but entries in this file will override that. It has become common for spyware to put something like

127.0.0.1 www.spybot.info

into this file so your computer can't find the site, just remove the line and save the file. That will get rid of it.
Reply With Quote
  #5  
Old 01-03-2009, 06:35 AM
mark's Avatar
mark mark is offline
Member
 
Join Date: Nov 2002
Location: Edmonton AB
Posts: 4,212
mark is on a distinguished road
Default

Quote:
Originally Posted by midgetwaiter View Post
open the file c:\windows\system32\drivers\etc\hosts in notepad.

You should see this:
Code:
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
#      102.54.94.97     rhino.acme.com          # source server
#       38.25.63.10     x.acme.com              # x client host

127.0.0.1       localhost
::1             localhost
The last line may be missing in XP, no biggie.

Some spyware will insert additional entries in the file. This file is used to maintain a list of hosts and their numerical addresses so your computer can figure out just who www.whatever.com is. With your internet connection this mapping is provided by your DNS servers but entries in this file will override that. It has become common for spyware to put something like

127.0.0.1 www.spybot.info

into this file so your computer can't find the site, just remove the line and save the file. That will get rid of it.
Thanks, tried this and still no joy. Even thought I would try some other anti-spyware and places like Microsoft Download Ctr is blocked
Reply With Quote
  #6  
Old 01-03-2009, 05:00 PM
midgetwaiter midgetwaiter is offline
Member
 
Join Date: Nov 2005
Location: Calgary
Posts: 546
midgetwaiter is on a distinguished road
Default

open a command prompt and do this

nslookup (enter)

then type in www.spybot.info and hit enter again.

Your output should look like this:

Code:
Microsoft Windows [Version 6.0.6001]
Copyright (c) 2006 Microsoft Corporation.  All rights reserved.

C:\Users\ajs>nslookup
Default Server:  nsc1.ar.ed.shawcable.net
Address:  64.59.184.13

> www.spybot.info
Server:  nsc1.ar.ed.shawcable.net
Address:  64.59.184.13

Non-authoritative answer:
Name:    www.spybot.info
Address:  89.238.64.39
now try http://89.238.64.39 in the address bar of your browser.
Reply With Quote
  #7  
Old 01-03-2009, 09:04 PM
muck's Avatar
muck muck is offline
Member
 
Join Date: Mar 2004
Location: Edmonton, AB (West)
Posts: 4,329
muck is on a distinguished road
Default

What ever you picked up Mark so do I... it seems to block all the anti-spyware/anti-virus sites that I can think of..

Not sure how to go about removing the infection.
Reply With Quote
  #8  
Old 01-03-2009, 10:17 PM
Snaz's Avatar
Snaz Snaz is offline
Member
 
Join Date: Aug 2008
Location: Surrey, BC
Posts: 1,034
Snaz is on a distinguished road
Default

Update your Anti virus definitions if you can. It will probably fail. Then do a full computer scan in SAFE MODE:

1. Enter safe mode by tapping F8 as soon a the computer starts or restarts. You will get a menu to enter safe mode, try safe mode with networking as then you might be able update your AV definitions.

2. Do a full computer scan while in safe mode, delete or quarantine any nasties.

3. Reboot and do it all again, enter safe mode and do a full computer scan.

4. Reboot into normal mode. If the virus comes back then you will need to work harder to clean it up. Tools like Hijackthis will help but are not for the novice. Get a nerd buddy to help or otherwise backup your files, bookmarks etc and wipe the machine.

Good luck
__________________
Reply With Quote
  #9  
Old 01-04-2009, 04:27 AM
DanG's Avatar
DanG DanG is offline
Member
 
Join Date: Mar 2005
Location: Peg City
Posts: 609
DanG is on a distinguished road
Default

You've got vundo, it's a really really nasty piece of spyware.

I've gotten rid of it on a friends laptop using Malware Bytes anti malware program.

www.malwarebytes.org

What are you running for antivirus?
Reply With Quote
  #10  
Old 01-04-2009, 04:42 AM
mark's Avatar
mark mark is offline
Member
 
Join Date: Nov 2002
Location: Edmonton AB
Posts: 4,212
mark is on a distinguished road
Default

Using Superantispyware and Spybot (all freeware).

Thing with this is just tried the malwarebytes site and was blocked;

With Firefox get:

Failed to Connect

The connection was refused when attempting to contact www.malwarebytes.org.


Though the site seems valid, the browser was unable to establish a connection.

* Could the site be temporarily unavailable? Try again later.

* Are you unable to browse other sites? Check the computer's network connection.

* Is your computer or network protected by a firewall or proxy? Incorrect settings can interfere with Web browsing.

Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 02:53 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.