Technology Questions

Go Back   Technology Questions > Software Questions > Internet > Internet Explorer

Internet Explorer Discuss IE7 or any other IE version.

Reply
 
LinkBack Thread Tools
  #1 (permalink)  
Old 06-17-2007, 08:51 PM
PowerPROM@frwilk.com
Newsgroup Contributor
 
Posts: n/a
hizacked while surfing

This is new this month. When I am in eBay, instead of opening an
auction page, it sends me to blockbuster.com or circuitcity.com or
netflix.com etc. I have win 98 and IE6 SP1. Ran spyware programs and
it is still there.

Does this sound familier? FR Wilk

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

 
Old 06-17-2007, 08:51 PM
  #2 (permalink)  
Old 06-17-2007, 11:40 PM
Wally Anglesea™
Newsgroup Contributor
 
Posts: n/a
Re: hizacked while surfing

On Sun, 17 Jun 2007 20:40:49 -0700, PowerPROM@frwilk.com wrote:

>This is new this month. When I am in eBay, instead of opening an
>auction page, it sends me to blockbuster.com or circuitcity.com or
>netflix.com etc. I have win 98 and IE6 SP1. Ran spyware programs and
>it is still there.
>
>Does this sound familier? FR Wilk


Check to see if you have core.sys It wil be registered as a driver.

This is a particularly nasty one, but relatively easy to get rid of.

I suspect it's this one because it's been surfacing quite a bit
lately, and none of my malware utilities discovered it. I caught it
and got it submitted, so now they do.

here's what I sent out:

Today I began to experience some weird behaviour. Every So often, an
IE window would pop up, trying to take me to various webpages. I could
not find any service etc which would do this.

So I caught one of the urls it was trying to go to: url.cvpfeed.com.

So I went to my Lavasoft A-ware, and it could not recognise anything
(even with a full scan)

Grisoft Professional, with the latest definitions could not find it.

So I googled around, and found this reference:

http://www.lavasoftsupport.com/index...opic=8601&st=0

The discussion explains it. I followed the instructions and fixed it.

I submitted the file to www.virustotal.com and got the attached screen
dump result. So some engines do see it as a trojan. Not sure how it
got to me. I'm Windows XP Pro, with all service packs etc. Not even
Winpatrol saw it coming in.


--

Find out about Australia's most dangerous Doomsday Cult:
http://users.bigpond.net.au/wanglese/pebble.htm

"You can't fool me, it's turtles all the way down."

"Maths proves you know how to plug in some figures into a formula, that's
all"
"Even physics is based on wrong theories, so what's the use of maths"
Carole - demonstrating her mathematical abilities.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #3 (permalink)  
Old 06-18-2007, 06:01 AM
PowerPROM@frwilk.com
Newsgroup Contributor
 
Posts: n/a
Re: hizacked while surfing

Thanks Wally for the reply,

I looked and core.sys is not there. It is something else. Any other
ideas guys?

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #4 (permalink)  
Old 06-18-2007, 06:21 AM
mae
Newsgroup Contributor
 
Posts: n/a
Re: hizacked while surfing

Start here:
http://aumha.org/a/parasite.htm
--
mae

<PowerPROM@frwilk.com> wrote in message
news:1182171222.266754.67020@d30g2000prg.googlegro ups.com...
| Thanks Wally for the reply,
|
| I looked and core.sys is not there. It is something else. Any other
| ideas guys?
|

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #5 (permalink)  
Old 06-18-2007, 08:50 AM
CaffeineOverdose
Newsgroup Contributor
 
Posts: n/a
Re: hizacked while surfing

Sometimes the hackers put the same basic trojan into a different name, but
they tend to use similar names so they can keep track of their work.

I'd suggest a search for EVERYTHING with the extension .sys that has been
modified or installed since a day or two before the problem began.
Additionally, any file with "core" in it (a file search for "core" would
suffice), since it could have been changed from a .sys file.

And although it is stating the obvious, make sure you check ALL files and
folders, including hidden files & folders.

"mae" wrote:

> Start here:
> http://aumha.org/a/parasite.htm
> --
> mae
>
> <PowerPROM@frwilk.com> wrote in message
> news:1182171222.266754.67020@d30g2000prg.googlegro ups.com...
> | Thanks Wally for the reply,
> |
> | I looked and core.sys is not there. It is something else. Any other
> | ideas guys?
> |
>
>

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Surfing the Web Gerald Internet Explorer 0 03-09-2008 11:01 AM
Surfing History Anthony1205 Internet Explorer 3 12-22-2007 05:20 PM
Traces of surfing Dave Neve Internet Explorer 1 08-25-2007 03:20 AM
Surfing Speed RP Notebooks 11 05-29-2007 12:00 AM
Surfing the web - going keyboardless LPH Tablet PC Tips & Tricks 6 09-15-2004 06:04 PM


New To Technology Questions? Do You Need Help with Your Computer or Device? Do You Need Help with this site?

All times are GMT -8. The time now is 09:58 AM.


2003 - 2009 All Rights Reserved. Technology Questions

Search Engine Friendly URLs by vBSEO 3.3.0