PDA

View Full Version : Something exploiting IE?? HELP!


Anonymous
08-22-2005, 02:58 PM
When I log onto windows now iexplorer.exe comes up as trying to send data to 210.245.166.133 over port 80. Located in hong kong (thanks dan) this looks very dodgy :-( Tried spybot search and destroy and adaware with no luck.

Tried reinstalling IE which is also showing text alot bigger than it should :-( but with no luck Tried the steps here http://support.microsoft.com/default.aspx?kbid=318378 ( i don't have an xp cd only recovery currently)

Anybody got any ideas?, running xp home SP2. if i can't sort this i'll have to get hold of a copy of xp pro and do a clean install. For the moment i've just blocked IE from the net but this means i can't keep windows up to date i think, which causes more problems :roll:

RC45
08-22-2005, 03:04 PM
Host Control, Inc.
Your globe hosting service


So these guys are not buddies of yours? ;)



HTTP/1.1 400 Bad Request
Server: Zeus/4_3
Date: Mon, 22 Aug 2005 19:03:48 GMT
Connection: close
Content-Type: text/html

<html><head><title>Error 400 Bad Request
</title></head><body bgcolor=#ffffff><h2>Error 400 Bad Request
</h2>

Powered by Zeus Technology (http://errors.zeus.com/)<
/body></html>


Connection to host lost.

H:\>


Why not try exploit their server? ;)

Anonymous
08-22-2005, 03:22 PM
Host Control, Inc.
Your globe hosting service


So these guys are not buddies of yours? ;)



HTTP/1.1 400 Bad Request
Server: Zeus/4_3
Date: Mon, 22 Aug 2005 19:03:48 GMT
Connection: close
Content-Type: text/html

<html><head><title>Error 400 Bad Request
</title></head><body bgcolor=#ffffff><h2>Error 400 Bad Request
</h2>

Powered by Zeus Technology (http://errors.zeus.com/)<
/body></html>


Connection to host lost.

H:\>


Why not try exploit their server? ;)

Of course i wouldn't condone hacking the owner of that IP off the planet :wink: :P , but i would think any hacker would use a proxy surely???! not sure what they shit they could send or if it ever got through but i am pretty worried right now!, at least i don't use IE for anything but still.........

Anonymous
08-22-2005, 03:35 PM
a top tip, use microsoft antispyware!

which requires me to use IE as far as i can work out, which is the problem in itself! it needs some validation thing which requires active x which firefox won't do! Sadly i've never DL'd it, somehow i never trust microsoft software unless i'm forced to use it :-(

ZfrkS62
08-22-2005, 09:41 PM
Al, i've mentioned it before, but McAfee's antivirus will find pretty much everything. PUPs, Viruses, and worms.

40 USD gets you a year subscription, and constantly updates from it's server. If your comp crashes you can just go redownload and install it. Just use Firefox to go get it, doesn't take long. I'm pretty sure they have it availible all over the world.

www.mcafee.com

I've had it for a year and a half now and nto one problem :D

5vz-fe
08-22-2005, 11:58 PM
a top tip, use microsoft antispyware!

which requires me to use IE as far as i can work out, which is the problem in itself! it needs some validation thing which requires active x which firefox won't do! Sadly i've never DL'd it, somehow i never trust microsoft software unless i'm forced to use it :-(

deleted link

Then download the antispyware. (I hope this didn't breach the rulez)

Anonymous
08-23-2005, 09:24 AM
a top tip, use microsoft antispyware!

which requires me to use IE as far as i can work out, which is the problem in itself! it needs some validation thing which requires active x which firefox won't do! Sadly i've never DL'd it, somehow i never trust microsoft software unless i'm forced to use it :-(

deleted link

Then download the antispyware. (I hope this didn't breach the rulez)

cheers but i got there in the end :-) after finally getting my firewall to block that addy properly. It found one thing, just an IE toolbar so i doubt thats it, but i'll try unblocking the IP and see if IE still tries to contact it.

At the moment i'm considering blocking all the dodgy countries, bit extreem but i kind of thought i was resonably safe with a regularly updated antivirus, 2 firewalls (hard and software), peerguardian 2, spybot search and destroy, adaware, both updated and run regularly :roll: Shows you should never become complacent really!

paulrudz
08-23-2005, 12:33 PM
deleted link

Then download the antispyware. (I hope this didn't breach the rulez)


:lol: you're kidding right ?

pharzo
08-23-2005, 12:42 PM
You know the IE executable is hidden as system file

Try turning off the "Hide Protected Operating System Files", then going in and deleting the IEXPLORE.exe file

Also try to run a search for IEXPLORE.EXE, you might find some dodgy one somewhere masquerading as the real thing.

edit: You wrote that iexplorer.exe is trying to access, that was a mispelling right?

Anonymous
08-23-2005, 01:06 PM
You know the IE executable is hidden as system file

Try turning off the "Hide Protected Operating System Files", then going in and deleting the IEXPLORE.exe file

Also try to run a search for IEXPLORE.EXE, you might find some dodgy one somewhere masquerading as the real thing.

edit: You wrote that iexplorer.exe is trying to access, that was a mispelling right?

no it was a fucking bit of malicious spyware

tried methlabs and got pointed to hijack this, read my n00bness here

http://methlabs.org/forums/showthread.php?p=96860#post96860

I "think" i've got it fixed now, been driving me nuts, but now the right one is running IEXPLORE.EXE rather than IEXPLORER.EXE, easy to miss i guess, one letter difference and i didn't know what it was supposed to be myself!!, anyway i'm just disappointed nothin i have here picked up on it :-( gonna run that hijack this thing pretty regularly i think!!!

ZfrkS62
08-23-2005, 09:37 PM
good to see you got rid of it Al.

if that wasn't bad enough, a worm infected the entire network at work today. all the comps running XP were find but a the ones running office 2000 got nailed with djsadjf.xxx (can't remember what the ending was, i want to say exe) it set into the system32 folder int he registry and if it didnt' get deleted right, it would come back. They had to call in an outside company to help out cuz our IT guy is apparently not as smart as he thinks :roll:

(i'm trying to learn this stuff but i still dont' think i'll ever be good at it :lol: )