Won't redirect after weirdness ....

M

M

The other day I had a shock.

I had three IE6 browser windows open; my own site, the reputable
www.adslguide.org.uk and MoveableType (which I was using to update my own
site). I didn't have Outlook Express open.

Suddenly Norton AV popped up and told me that two files in my Temporary
Internet Files were infected with MHTMLRedir.Exploit and "Trojan Horse"
(the files were blahblahblah\man[2].htm and blahblahblah\exploit[1]htm).
Obviously they weren't "blahblahblah" but .... In a bit of a panic I
deleted my Temp. Internet files (including off-line content). The panic
was mainly as I was not surfing unknown/dodgy sites, just my own, MT and
adslguide. I thought someone must have hacked my site but I had friends
check it out the same night and there's nothing odd happening there.

I have my security settings pretty high - so much so that I'm prompted
continually to allow ActiveX controls and plugins to run. That happened
when I got the NAV alerts. I think I must have clicked on "yes" as next
thing I knew, I was being prompted to download "seksdialer.exe" from
69.93.142.154. Obviously I didn't continue with that!

I have all the critical Windows XP patches. I run Spybot S & D,
Spywareblaster, and have scanned my pc with TDS-3. Nothing has been
picked up. I've examined my Hijackthis log and can't see anything
suspicious.

I'd love to know how I got these "virus" infections. As NAV trapped the
problem files and I deleted the cache I thought I had nothing to be
concerned about. However, since that night, whenever I try to download a
file and I'm told "your download will begin automatically" it doesn't, so
I have to click the provided link to start the download. Similarly, on
forums when I've posted a message and I'm told that I'm being taken back,
I'm not, so have to click the "click here if you do not wish to wait"
link.

I've tried running the command regsvr32 /i urlmon.dll which I've seen
mentioned as a cure for loss of autoredirects but that hasn't helped.

If anyone has any ideas I'd be grateful. Sorry for the long-winded post
but I wanted to provide as much info as I could.

thanks
 
F

Frank Saunders, MS-MVP

M said:
The other day I had a shock.

I had three IE6 browser windows open; my own site, the reputable
www.adslguide.org.uk and MoveableType (which I was using to update my
own site). I didn't have Outlook Express open.

Suddenly Norton AV popped up and told me that two files in my
Temporary Internet Files were infected with MHTMLRedir.Exploit and
"Trojan Horse" (the files were blahblahblah\man[2].htm and
blahblahblah\exploit[1]htm). Obviously they weren't "blahblahblah"
but .... In a bit of a panic I deleted my Temp. Internet files
(including off-line content). The panic was mainly as I was not
surfing unknown/dodgy sites, just my own, MT and adslguide. I thought
someone must have hacked my site but I had friends check it out the
same night and there's nothing odd happening there.

I have my security settings pretty high - so much so that I'm prompted
continually to allow ActiveX controls and plugins to run. That
happened when I got the NAV alerts. I think I must have clicked on
"yes" as next thing I knew, I was being prompted to download
"seksdialer.exe" from
69.93.142.154. Obviously I didn't continue with that!

I have all the critical Windows XP patches. I run Spybot S & D,
Spywareblaster, and have scanned my pc with TDS-3. Nothing has been
picked up. I've examined my Hijackthis log and can't see anything
suspicious.

I'd love to know how I got these "virus" infections. As NAV trapped
the problem files and I deleted the cache I thought I had nothing to
be concerned about. However, since that night, whenever I try to
download a file and I'm told "your download will begin automatically"
it doesn't, so I have to click the provided link to start the
download. Similarly, on forums when I've posted a message and I'm
told that I'm being taken back, I'm not, so have to click the "click
here if you do not wish to wait" link.

I've tried running the command regsvr32 /i urlmon.dll which I've seen
mentioned as a cure for loss of autoredirects but that hasn't helped.

If anyone has any ideas I'd be grateful. Sorry for the long-winded
post but I wanted to provide as much info as I could.

thanks

Are you using a firewall?
Windows version?

--
Frank Saunders, MS-MVP, IE/OE
Please respond in Newsgroup. Do not send email
http://www.fjsmjs.com
Protect your PC
http://www.microsoft.com/security/protect/
 
F

Frank Saunders, MS-MVP IE/OE

M said:
Beggar me ..... M ([email protected]) contributed
this in on Sun, 02
May 2004 08:54:47 GMT:
Beggar me ..... Frank Saunders, MS-MVP
([email protected]) contributed this in
46:23 GMT:

[snip]
Are you using a firewall?
Windows version?


Hello Frank. Thanks for the reply.
Yes, I'm using Zonealarm Plus, and my ADSL router is NAT.
... and Windows XP Home [not woken up yet!]

Check your settings in Zone Alarm
and see
http://www.dslreports.com/faq/faq/5.+Troubleshooting#357
and
http://www.mvps.org/inetexplorer/answers4.htm#offline_dsl

--
Frank Saunders, MS-MVP, IE/OE
Please respond in Newsgroup. Do not send email
http://www.fjsmjs.com
Protect your PC
http://www.microsoft.com/security/protect/
 
M

M

Beggar me ..... Frank Saunders, MS-MVP IE/OE ([email protected])
contributed this in on Sun, 02
May 2004 10:53:45 GMT:
M said:
Beggar me ..... M ([email protected]) contributed
this in on Sun, 02
May 2004 08:54:47 GMT:
Beggar me ..... Frank Saunders, MS-MVP
([email protected]) contributed this in
46:23 GMT:

[snip]

Are you using a firewall?
Windows version?


Hello Frank. Thanks for the reply.
Yes, I'm using Zonealarm Plus, and my ADSL router is NAT.
... and Windows XP Home [not woken up yet!]

Check your settings in Zone Alarm
and see
http://www.dslreports.com/faq/faq/5.+Troubleshooting#357
and
http://www.mvps.org/inetexplorer/answers4.htm#offline_dsl
Thanks for the reply but I could do with some pointers re. ZA Pro - which
area of options are you referring to? As for the links, I couldn't find
anything relating to my problem (i.e. redirects no longer working). If I
missed the relevant info. I apologise.
 
F

Frank Saunders, MS-MVP IE/OE

M said:
Thanks for the reply but I could do with some pointers re. ZA Pro -
which area of options are you referring to? As for the links, I
couldn't find anything relating to my problem (i.e. redirects no
longer working). If I missed the relevant info. I apologise.

I can't help with ZA settings; haven't used it for years.

--
Frank Saunders, MS-MVP, IE/OE
Please respond in Newsgroup. Do not send email
http://www.fjsmjs.com
Protect your PC
http://www.microsoft.com/security/protect/
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top