Omega Owners Forum

Please login or register.

Login with username, password and session length
Advanced search  

News:

Please play nicely.  No one wants to listen/read a keyboard warriors rants....

Pages: [1]   Go Down

Author Topic: I.E via Proxy; malware?  (Read 824 times)

0 Members and 1 Guest are viewing this topic.

Debs.

  • Guest
I.E via Proxy; malware?
« on: 02 February 2009, 16:49:52 »

I went `round to visit a neighbour yesterday; he tried to show me a website on his desktop PC, but had terrible problems getting the 'real' site to display, for mostly, search results came back with the same (un asked-for) search-results website (not one I`ve ever seen a`fore)....."it`s been doing that for weeks" he said!

It`s obviously some kind of hijack/spyware/malware; so I dragged the newest versions of CCleaner and Spybot S & D off my pen drive and scanned: many items found by both programmes, all then cleansed and deleted but still I.E seems reluctant to go direct to a (real) specified URL.
As a clue; when installing; Spybot asked about I.E 'currently using a proxy' and if I wanted to update Spybot S & D using that proxy: to which I said no (of course).

Even following all that cleaning carried-out in safe-mode, the problem`s still there; what would be the next option?
I worry for my neighbour in case the malware is harvesting his private info. etc. :(
« Last Edit: 02 February 2009, 16:50:10 by Debs. »
Logged

Gaffers

  • Omega Queen
  • *****
  • Offline Offline
  • Gender: Male
  • NE Hampshire/Surrey
  • Posts: 11322
    • Ford Ranger Wildtrak
    • View Profile
Re: I.E via Proxy; malware?
« Reply #1 on: 02 February 2009, 16:58:18 »

Dont take any chances.  If it is something as complex as you state, wipe the slate clean and start again.  I would only continue using a build if it was a simple bug that I had found and gotten rid of....
Logged

CaptainZok

  • Omega Lord
  • *****
  • Offline Offline
  • Gender: Male
  • Bolton
  • Posts: 8093
  • Victim of Cyberbullying.
    • 3.2 MV6 Estate
    • View Profile
Re: I.E via Proxy; malware?
« Reply #2 on: 02 February 2009, 18:28:55 »

Easy have a look at the dns settings in tpc properties of the connection.
It will be set to a dodgy dns server.
Logged
PM me for code reading/clearing
TuBy's new whipping boy.

amigov6

  • Guest
Re: I.E via Proxy; malware?
« Reply #3 on: 02 February 2009, 18:32:33 »

Quote
Easy have a look at the dns settings in tpc properties of the connection.
It will be set to a dodgy dns server.
I was just thinking that John!!!!!! :D :-?
Logged

TheBoy

  • Administrator
  • *****
  • Offline Offline
  • Gender: Male
  • Brackley, Northants
  • Posts: 107118
  • I Like Lockdown
    • Whatever Starts
    • View Profile
Re: I.E via Proxy; malware?
« Reply #4 on: 02 February 2009, 18:59:07 »

Caught something similar on my work laptop (after using a Power calculator from HP's website :o), spend about 3 days to clear it, in the end, wasn't worth messing about with, Windows CD in drive, rebuild.
Logged
Grumpy old man

TheBoy

  • Administrator
  • *****
  • Offline Offline
  • Gender: Male
  • Brackley, Northants
  • Posts: 107118
  • I Like Lockdown
    • Whatever Starts
    • View Profile
Re: I.E via Proxy; malware?
« Reply #5 on: 02 February 2009, 19:03:08 »

If its like the one I had, its a clever piece of malware that I couldn't actually get my head around.

It wasn't DNS based, wasn't fake proxy based (this was behind our corporate firewall, so would block those), didn't appear to be a browser hijack in the true sense of the word.  I started thinking along the lines of it being a fake browser, but any attempt to reinstall IE6 (yes, IE6 at work :(), or even manually copy all the dlls didn't resolve.  Very, very clever, whatever it is.

I did managed to get it working for a few hours by stripping the registry, but it reinfected itself somehow.
Logged
Grumpy old man

cem_devecioglu

  • Guest
Re: I.E via Proxy; malware?
« Reply #6 on: 02 February 2009, 20:16:30 »

Quote
Caught something similar on my work laptop (after using a Power calculator from HP's website :o), spend about 3 days to clear it, in the end, wasn't worth messing about with, Windows CD in drive, rebuild.

yep..always shorter and guaranteed results :y

and a healthy faster system..
« Last Edit: 02 February 2009, 20:17:08 by cem_devecioglu »
Logged

Turk

  • Omega Baron
  • *****
  • Offline Offline
  • Gender: Male
  • Llanelli, Wales
  • Posts: 4029
    • 2.5td, H-D XL1200
    • View Profile
Re: I.E via Proxy; malware?
« Reply #7 on: 02 February 2009, 23:04:12 »

Quote
I went `round to visit a neighbour yesterday; he tried to show me a website on his desktop PC, but had terrible problems getting the 'real' site to display, for mostly, search results came back with the same (un asked-for) search-results website (not one I`ve ever seen a`fore)....."it`s been doing that for weeks" he said!

It`s obviously some kind of hijack/spyware/malware; so I dragged the newest versions of CCleaner and Spybot S & D off my pen drive and scanned: many items found by both programmes, all then cleansed and deleted but still I.E seems reluctant to go direct to a (real) specified URL.
As a clue; when installing; Spybot asked about I.E 'currently using a proxy' and if I wanted to update Spybot S & D using that proxy: to which I said no (of course).

Even following all that cleaning carried-out in safe-mode, the problem`s still there; what would be the next option?
I worry for my neighbour in case the malware is harvesting his private info. etc. :(
 


I had a wee baddie that got past McAfee. I installed Avira AntiVir. Free on Tucows. It found it and not had a problem with anything since.
May get the "up-grade to Premium for £x.xx" coming up once a night when it runs the auto up-date but that's just a click on the X when the up-date is finished. Apart from that, you don't even know it's there.

http://www.tucows.com/preview/513451
Logged
Only a biker truly understands why a dog sticks it's head out of the window of a moving car.

Vamps

  • Offline Offline
  • Gender: Male
  • Bishop Middleham, Co Durham.
  • Posts: 24708
  • Flying Tonight, so Be Prepared.
    • Mig 2.6CDX and 2.2 Honda
    • View Profile
Re: I.E via Proxy; malware?
« Reply #8 on: 03 February 2009, 01:00:37 »

Sorry guy's and Deb's but didn't understand anything that had been said..... :-[ :-[ :-[
Logged
Pages: [1]   Go Up
 

Page created in 0.012 seconds with 16 queries.