PDA

View Full Version : Scan interruption



Jelly
2005-12-14, 18:25
When I scan the computer with Spybot, it gets an error saying:
Error during check!
Anal-Oral.WinMain (Datei C:\\WINDOWS\system32\drivers\etc\hosts kann nicht geffönt werden. The process cannot access the file because it is being used by another process)

(Tick) Congratulations! No immediate threats were found!

I don't like the sound of the error, can there be some program messing up the scan?

md usa spybot fan
2005-12-14, 19:12
Are you running any software that blocks access to the HOSTS file?

ZoneAlarm, STOPzilla and possibly other programs block access to the HOSTS file rather than just set the read-only attribute on the file to protect the file. This offers better protection of the file than just setting the read-only attribute as Spybot’s IE Tweaks does. However, since the access to the file is blocked, Spybot's scan fails attempting to analyze the HOSTS file for problems.

By the way, are you running Spybot 1.3 or Spybot 1.4 (Spybot > Help > About)?

Jelly
2005-12-15, 18:22
I'm running Spybot 1.3

Is this bad?

md usa spybot fan
2005-12-15, 18:37
If you are running Spybot-S&D 1.3 and it is not a Windows 95 system you should consider upgrading to Spybot-S&D 1.4.

Download sites for Spybot-S&D 1.4:
Four (4) here:
Mirror Selection – The home of Spybot–S&D!
http://www.safer-networking.org/en/mirrors/index.html

I recommend that you uninstall before installing a new version:
FAQ - Frequently Asked Questions
How to uninstall?
http://www.safer-networking.org/en/faq/27.html

Upgrading will not solve your HOSTS file problem.

Jelly
2005-12-15, 21:03
I'll clear something else up, I'm not german, I recently downloaded from a German site (Could that be the problem?) and I have not surfed on any pornographic sites so I can't have an error like that because of a firewall problem.

(I only have the windows firewall)

bitman
2005-12-15, 21:19
Jelly: You have a response to your request for Malware Removal assistance from LonnyRJones in the Malware Removal forum.
http://forums.spybot.info/showthread.php?t=924

I'd suggest you respond there, mention the issue you're having with the Hosts file and the thread here.

It's possible that this issue is related to a Malware problem, so trying to work it from both ends just confuses things.

md usa spybot fan
2005-12-15, 22:39
Jelly:

Good luck in the Malware Removal forum:
http://forums.spybot.info/showthread.php?t=924

Just for clarification:

The fact that you are not German and don't surf pornographic sites does not alter the fact that I believe that your HOSTS file is being blocked.

The format of the error message that you got was the tip-off that you were probably running Spybot 1.3.

re: Error during check!: Anal-Oral.WinMain (Datei C:\\WINDOWS\system32\drivers\etc\hosts kann nicht geffönt werden. The process cannot access the file because it is being used by another process)

The following applies:
The German portions of the error message translated to English are:
Datei = File.
kann nicht geöffnet werden = cannot be opened.
Therefore:
Error during check!: Anal-Oral.WinMain (Datei C:\\WINDOWS\system32\drivers\etc\hosts kann nicht geffönt werden. The process cannot access the file because it is being used by another process) ()
Translated to Englis would be:
Error during check!: Anal-Oral.WinMain (File C:\\WINDOWS\system32\drivers\etc\hosts cannot be opened. The process cannot access the file because it is being used by another process) ()
In Spybot 1.4 that same error message would read (without any translation):
Error during check!: Anal-Oral.WinMain [1] (Cannot open file "C:\WINDOWS\system32\drivers\etc\hosts". The process cannot access the file because it is being used by another process) ()
Anal-Oral.WinMain is the spyware check that Spybot-S&D was performing when the error occurred and in Spybot-S&D 1.3 the internal errors were in German, the native language of Spybot-S&D's author Patrick M. Kolla.

Jelly
2005-12-16, 21:08
Oh, ok, thanks.

I've got McAfee now, though, so I can find any considerable problems.