Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: FOUND 5ROOTKITS AND DNSCHANGER THANK U EVILFANTASY BUT WHAT NEXT  (Read 2971 times)

0 Members and 1 Guest are viewing this topic.

inno

  • Guest
zone firewall(zfw) says at startup everytime that symptom1
generic host process for win32 services is trying to access the internet destination ip xx.xxx.xxx.xxx and sometimes destinaton ip is yy.yyy.yyy.yyy.
they do not belong to my isp.
i traced them.both IPs belong to the same guy in another country.
i am not posting the ip addresses yet.
now if i deny ghp access to those IPs then i cant access the internet.symptom2 windows explorer is trying to act as servesymptom3 cannot turn on automatic updates for avg free.
i scanned with hijackthis and found two other IPs(not the IPs that zone alarm was showing) in a registry entry.i made hijack this fix those two problems.
I followed Evilfantasy's malware removal guide
and FOUND ROOTKITS etc.
but i made mistakes with super antispyware:
 didnt uncheck anything.started a COMPLETE SCAN.
when asked to reboot  to quarantine the 19malware found(5 rootkits,12 tracking cookies and 2something else)i restared the computer but it was taking along time to shut down
so i pressed the reset/restart button .
when the computer restarted i found the things quarantined alright(OR ARE THEY QUARANTINED)
well at any rate the symptom1 &symptom2 stopped.
    now my computer is not trying to connect to those two IPs.
then i followed the next steps as told in the guide.THANK YOU EVILFANTASY
WHAT SHOULD I DO NEXT

[attachment deleted by admin]
« Last Edit: January 24, 2009, 03:04:10 AM by inno »

Nci



    Greenhorn

    Re: the case of the mysterious ip
    « Reply #1 on: January 23, 2009, 05:56:05 AM »
    i got that 2 ???

    JohnLace



      Newbie

      Re: the case of the mysterious ip
      « Reply #2 on: January 23, 2009, 06:54:21 AM »
      You can try Nod32.  It includes a firewall where you can configure which ports or ip addresses to block.    You can use the trial version.

      Hope it helps.

      Nci



        Greenhorn

        Re: the case of the mysterious ip
        « Reply #3 on: January 23, 2009, 07:34:11 PM »
        no i got the same thing running in zone    But i couldent find the ips?