Welcome to WinForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Internet Home Page

 
   Windows XP (Home) -> XP Security Admin RSS
Next:  KB933666 fails to install  
Author Message
BobS

External


Since: Sep 28, 2006
Posts: 5



(Msg. 1) Posted: Thu May 10, 2007 9:53 am
Post subject: Internet Home Page
Archived from groups: microsoft>public>windowsxp>security_admin (more info?)

I have just cleaned my files and registry of the SpyLock virus. It all looks
good, except when I attempt to logon to the internet, the page that is
openned is still the "asecurityupdate.com" (host of Spylock) rather than my
web browser that I request in Internet Options. A search of my whole system
and registry fails to find any further trace of this intrusion, however, I
must be missing something. Are there any further ideas out there?

 >> Stay informed about: Internet Home Page 
Back to top
Login to vote
nass

External


Since: May 06, 2006
Posts: 2771



(Msg. 2) Posted: Thu May 10, 2007 10:11 am
Post subject: RE: Internet Home Page [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"BobS" wrote:

> I have just cleaned my files and registry of the SpyLock virus. It all looks
> good, except when I attempt to logon to the internet, the page that is
> openned is still the "asecurityupdate.com" (host of Spylock) rather than my
> web browser that I request in Internet Options. A search of my whole system
> and registry fails to find any further trace of this intrusion, however, I
> must be missing something. Are there any further ideas out there?


If all clean it is likely in the Hosts File there is an entry for it there
and every time you open the browser it resurrect itself, so open the Hosts
file as instructed below and remove the entry for it.
1... Click start >> Control Panel >> Double Click Network and Internet
Connections >> Double click Internet Options, on the IE Properties window
you will see these Options:
General | Security | Privacy | Content | Connections | Programs
| Advanced .

Click on General Tab (1st Tab on the left) and you will see a Button called
[ Clear History ..] click on it to clear your History caches, then click on
[Delete Files..] to delete Internet Files created over the time, click on [
Delete Cookies...] to delete your cookies left by visiting websites.

= Then try to Disable the Add-Ons on your Browser somehow installed on your
browser, On how to disable the Add-ons follow this:
Click on Programs Tab and then click the Manage Add-Ons Button there Disable
the None/Not Verified Plug-ins/Add-ons ( you need to Renable them one-by-one
later and see which is the culprit or you can send them here in your next
post) and click [OK] to confirm your Changes.

Click on Advanced Tab and scroll down under the browsing option and uncheck
this box:
[&] Browsing
[ ] Enable Third-Party browser extensions (Req Rest) and click Apply
then OK to close your IE Properties.

2.... And also for malwares from here:
http://www.lavasoft.com/products/ad-aware_se_personal.php
http://www.safer-networking.org ; for Spybot S&D
Download and install after installing this software and
update then run a scan in both safe mode and normal:
http://free.grisoft.com/doc/5390/lng/us/tpl/v5
= Open the Windows
Explorer and locate this path:
C:\Windows\System32\drivers\etc = look in the Right Pane/window for this
file called the HOSTS file but not the one with the extension *.SAM* leave
this as is.
If you can't see it try to click Tools >> Folder Options and select show
Hidden files and folder, then right Click the Hosts file and select open with
Notepad.
There see any reference for that site and remove it, you Hosts file will
looks like this:
# 102.54.94.97 rhino.acme.com # Source server
# 38.25.63.10 x.acme.com # Client Host
127.0.0.1 LocalHost
------------------------------------------
Remove all other References other than those above.

Run disk Clean Up and Defrag in safe mode, then Open run command and type in:
sfc /scannow click [OK]
Note the space between sfc_/

If you still directed Download the Hijackthis and send the report to one of
many
forums for analysis and troubleshooting:
When all else fails, HijackThis v1.99.1
(http://aumha.org/downloads/hijackthis.zip) is the preferred tool to use.
It will help you to both identify and remove any hijackware/spyware. Post
your log to http://aumha.net/viewforum.php?f=30,
http://castlecops.com/forum67.html,
http://forums.subratam.org/index.php?showforum=7, or other appropriate
forums for expert analysis, not here.
HTH.
Let us know.
Regards,
nass
----------
www.nasstec.co.uk

 >> Stay informed about: Internet Home Page 
Back to top
Login to vote
BobS

External


Since: Sep 28, 2006
Posts: 5



(Msg. 3) Posted: Thu May 10, 2007 1:28 pm
Post subject: RE: Internet Home Page [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Update on what I've done: I have done all of what was suggested under Item
#1. I disabled the "Third-Party browser extensions", and then disabled all of
the "Not verified add-ons". When I restarted, the browser went to the proper
internet home page. As I enabled these add-ons (and restarted each time)
one-by-one, the browser was still OK...this seemed to tell me that enabled or
disabled, these add-ons were OK. However, when I went back and checked
(allowed) the Third-Party browser extensions, the browser went to the
"asecurity.com" site again. Is there a legitimate reason for this
"Third-Party browser access", or should I turn it off permanetly?

"nass" wrote:

>
>
> "BobS" wrote:
>
> > I have just cleaned my files and registry of the SpyLock virus. It all looks
> > good, except when I attempt to logon to the internet, the page that is
> > openned is still the "asecurityupdate.com" (host of Spylock) rather than my
> > web browser that I request in Internet Options. A search of my whole system
> > and registry fails to find any further trace of this intrusion, however, I
> > must be missing something. Are there any further ideas out there?
>
>
> If all clean it is likely in the Hosts File there is an entry for it there
> and every time you open the browser it resurrect itself, so open the Hosts
> file as instructed below and remove the entry for it.
> 1... Click start >> Control Panel >> Double Click Network and Internet
> Connections >> Double click Internet Options, on the IE Properties window
> you will see these Options:
> General | Security | Privacy | Content | Connections | Programs
> | Advanced .
>
> Click on General Tab (1st Tab on the left) and you will see a Button called
> [ Clear History ..] click on it to clear your History caches, then click on
> [Delete Files..] to delete Internet Files created over the time, click on [
> Delete Cookies...] to delete your cookies left by visiting websites.
>
> = Then try to Disable the Add-Ons on your Browser somehow installed on your
> browser, On how to disable the Add-ons follow this:
> Click on Programs Tab and then click the Manage Add-Ons Button there Disable
> the None/Not Verified Plug-ins/Add-ons ( you need to Renable them one-by-one
> later and see which is the culprit or you can send them here in your next
> post) and click [OK] to confirm your Changes.
>
> Click on Advanced Tab and scroll down under the browsing option and uncheck
> this box:
> [&] Browsing
> [ ] Enable Third-Party browser extensions (Req Rest) and click Apply
> then OK to close your IE Properties.
>
> 2.... And also for malwares from here:
> http://www.lavasoft.com/products/ad-aware_se_personal.php
> http://www.safer-networking.org ; for Spybot S&D
> Download and install after installing this software and
> update then run a scan in both safe mode and normal:
> http://free.grisoft.com/doc/5390/lng/us/tpl/v5
> = Open the Windows
> Explorer and locate this path:
> C:\Windows\System32\drivers\etc = look in the Right Pane/window for this
> file called the HOSTS file but not the one with the extension *.SAM* leave
> this as is.
> If you can't see it try to click Tools >> Folder Options and select show
> Hidden files and folder, then right Click the Hosts file and select open with
> Notepad.
> There see any reference for that site and remove it, you Hosts file will
> looks like this:
> # 102.54.94.97 rhino.acme.com # Source server
> # 38.25.63.10 x.acme.com # Client Host
> 127.0.0.1 LocalHost
> ------------------------------------------
> Remove all other References other than those above.
>
> Run disk Clean Up and Defrag in safe mode, then Open run command and type in:
> sfc /scannow click [OK]
> Note the space between sfc_/
>
> If you still directed Download the Hijackthis and send the report to one of
> many
> forums for analysis and troubleshooting:
> When all else fails, HijackThis v1.99.1
> (http://aumha.org/downloads/hijackthis.zip) is the preferred tool to use.
> It will help you to both identify and remove any hijackware/spyware. Post
> your log to http://aumha.net/viewforum.php?f=30,
> http://castlecops.com/forum67.html,
> http://forums.subratam.org/index.php?showforum=7, or other appropriate
> forums for expert analysis, not here.
> HTH.
> Let us know.
> Regards,
> nass
> ----------
> www.nasstec.co.uk
 >> Stay informed about: Internet Home Page 
Back to top
Login to vote
nass

External


Since: May 06, 2006
Posts: 2771



(Msg. 4) Posted: Thu May 10, 2007 2:18 pm
Post subject: RE: Internet Home Page [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hi Bob,
As the name refer to Third-Party nothing to do with Windows which is your
Operating system.
There are Third_party like Google, Yahoo, ...etc that they are legitimate,
try to Disable it and check your Hosts File as indicated in my earlier Post
and remove any Entry for that Site in your Hosts File.
Download the HijackThis and run a scan, better if you sent to a proper forum
that deal with HijackThis Log file analysis.
Run Disk Clean and delete your temp files and see if that will cure the Issue.
HTH.
Let us know.
Regards,
nass
----
www.nasstec.co.uk

"BobS" wrote:

> Update on what I've done: I have done all of what was suggested under Item
> #1. I disabled the "Third-Party browser extensions", and then disabled all of
> the "Not verified add-ons". When I restarted, the browser went to the proper
> internet home page. As I enabled these add-ons (and restarted each time)
> one-by-one, the browser was still OK...this seemed to tell me that enabled or
> disabled, these add-ons were OK. However, when I went back and checked
> (allowed) the Third-Party browser extensions, the browser went to the
> "asecurity.com" site again. Is there a legitimate reason for this
> "Third-Party browser access", or should I turn it off permanetly?
>
> "nass" wrote:
>
> >
> >
> > "BobS" wrote:
> >
> > > I have just cleaned my files and registry of the SpyLock virus. It all looks
> > > good, except when I attempt to logon to the internet, the page that is
> > > openned is still the "asecurityupdate.com" (host of Spylock) rather than my
> > > web browser that I request in Internet Options. A search of my whole system
> > > and registry fails to find any further trace of this intrusion, however, I
> > > must be missing something. Are there any further ideas out there?
> >
> >
> > If all clean it is likely in the Hosts File there is an entry for it there
> > and every time you open the browser it resurrect itself, so open the Hosts
> > file as instructed below and remove the entry for it.
> > 1... Click start >> Control Panel >> Double Click Network and Internet
> > Connections >> Double click Internet Options, on the IE Properties window
> > you will see these Options:
> > General | Security | Privacy | Content | Connections | Programs
> > | Advanced .
> >
> > Click on General Tab (1st Tab on the left) and you will see a Button called
> > [ Clear History ..] click on it to clear your History caches, then click on
> > [Delete Files..] to delete Internet Files created over the time, click on [
> > Delete Cookies...] to delete your cookies left by visiting websites.
> >
> > = Then try to Disable the Add-Ons on your Browser somehow installed on your
> > browser, On how to disable the Add-ons follow this:
> > Click on Programs Tab and then click the Manage Add-Ons Button there Disable
> > the None/Not Verified Plug-ins/Add-ons ( you need to Renable them one-by-one
> > later and see which is the culprit or you can send them here in your next
> > post) and click [OK] to confirm your Changes.
> >
> > Click on Advanced Tab and scroll down under the browsing option and uncheck
> > this box:
> > [&] Browsing
> > [ ] Enable Third-Party browser extensions (Req Rest) and click Apply
> > then OK to close your IE Properties.
> >
> > 2.... And also for malwares from here:
> > http://www.lavasoft.com/products/ad-aware_se_personal.php
> > http://www.safer-networking.org ; for Spybot S&D
> > Download and install after installing this software and
> > update then run a scan in both safe mode and normal:
> > http://free.grisoft.com/doc/5390/lng/us/tpl/v5
> > = Open the Windows
> > Explorer and locate this path:
> > C:\Windows\System32\drivers\etc = look in the Right Pane/window for this
> > file called the HOSTS file but not the one with the extension *.SAM* leave
> > this as is.
> > If you can't see it try to click Tools >> Folder Options and select show
> > Hidden files and folder, then right Click the Hosts file and select open with
> > Notepad.
> > There see any reference for that site and remove it, you Hosts file will
> > looks like this:
> > # 102.54.94.97 rhino.acme.com # Source server
> > # 38.25.63.10 x.acme.com # Client Host
> > 127.0.0.1 LocalHost
> > ------------------------------------------
> > Remove all other References other than those above.
> >
> > Run disk Clean Up and Defrag in safe mode, then Open run command and type in:
> > sfc /scannow click [OK]
> > Note the space between sfc_/
> >
> > If you still directed Download the Hijackthis and send the report to one of
> > many
> > forums for analysis and troubleshooting:
> > When all else fails, HijackThis v1.99.1
> > (http://aumha.org/downloads/hijackthis.zip) is the preferred tool to use.
> > It will help you to both identify and remove any hijackware/spyware. Post
> > your log to http://aumha.net/viewforum.php?f=30,
> > http://castlecops.com/forum67.html,
> > http://forums.subratam.org/index.php?showforum=7, or other appropriate
> > forums for expert analysis, not here.
> > HTH.
> > Let us know.
> > Regards,
> > nass
> > ----------
> > www.nasstec.co.uk
 >> Stay informed about: Internet Home Page 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
internet - When on internet program nacar.com when I try to go into a live program like raceview etc... after a few seconds it shuts off my connection to the internet, whats wrong? Does it have to do with security?

internet - When on internet program nacar.com when I try to go into a live program like raceview etc... after a few seconds it shuts off my connection to the internet, whats wrong? Does it have to do with security?

internet - When on internet program nacar.com when I try to go into a live program like raceview etc... after a few seconds it shuts off my connection to the internet, whats wrong? Does it have to do with security?

MCE vs Home - Hello. I have MCE on one machine, Home on another. On MCE, Windows Explorer has a Security tab for file properties that allows me to tailor permissions for groups/usernames. Can/how do I get the same detailed Security tab on Home? Thanks in advance...

Internet security - where did it come from? - I should start this question by saying I know hardly a thing about computers, I never had any training, so please remember this when answering this question - I am unfamiliar with most terms and actions on a PC. After having numerous problems with..
   Windows XP (Home) -> XP Security Admin All times are: Eastern Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You can edit your posts in this forum
You can delete your posts in this forum
You can vote in polls in this forum

Categories:
  Windows XP
 Windows Vista!
 Win 2000/NT/98/ME


[ Contact us | Terms of Service/Privacy Policy ]