Host Hijack

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by glennk721, Aug 25, 2004.

  1. glennk721

    glennk721 MajorGeek

    Greetings all, I think I have the answer,,,but just wanted some advice!!!!

    I HAVE A HOST HIJACK ,have run spybot,ad-aware,spywarestormer a paid for program, also any and other fix's and detection software out there to no avail ,,when I try to delete the file it places it self back,,,,I have disabled RESTORE on XP and still writes itself back to disk,,,,


    Also to boot when I run hijack this,,,the file does not show itself on the scan


    The question is can I just enter the IP and port addy to my norton ignore list ??????????...Thanks alot . Glenn


    PS Thanks KODO
     
  2. Kodo

    Kodo SNATCHSQUATCH

    can you explain what you mean by Host Hijack.. are you saying that there is an IP address being placed in your HOSTS file?
     
  3. glennk721

    glennk721 MajorGeek


    Yes it appears as a local host with a IP and port of 8080,,,, as a proxy setting !!! its in there Kodo,,,,and can not remove the proxy setting...


    once in a while I will not be able toclick to a webpage or reload a page I look at my connection status,,,its sending and recieving chunks of data in 300-400k packets,,,remember Im on a T1...so it blasts out the data in and out like 2-3min it sent and recieved 55,000 kb,,,like someone is porting info through my IP addy........


    I disconnect from internet,,,,goes away,,,and then willl start some time later again,,,Thanks in advance Glenn
     
  4. glennk721

    glennk721 MajorGeek

    also this is new ,,,just today !!!
     
  5. Kodo

    Kodo SNATCHSQUATCH

    remove the entry.
    save the file..
    mark the file as read only.

    Sounds like you have a trojan.
     
  6. glennk721

    glennk721 MajorGeek


    \PS I just noticed something off topic,,,you have 2000 posts more them we have members LOLOL...a biiiiisssssssszzzzyyyyyyyy guy..


    Just a update,,I entered the IP addy and port to my Norton Firewall ....as a restricted zone,,,and no connections so far !!!!! Smiles....Glenn

    PS Thanks Kodo,,,will make read only also !!!!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Spyware Stormer is a Rogue/Suspect Anti-Spyware Product. See this http://www.spywarewarrior.com/rogue_anti-spyware.htm.


    I think I have seen:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080


    This in places where individuals said they were using Propel Accelerator.

    Do you use that?
     
  8. glennk721

    glennk721 MajorGeek

    THANKS FOR THE HEADS UP ,Chaslang,,,I am going to remove it ASAP,,,also contact them for a refund,,,Read this followup,,,Thaks much to all who helped today Glenn...dought I will get money back oh well

    http://www.webhelper4u.com/scams/spywarestromer.html

    PS NO accelorator program Im my connection is by far fast enough,,,
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Interesting how much crapware is out there....isn't it?

    By the way the localhost:8080 line has also shown in a few places where users have complained about issues with errorplace.com.
     
  10. glennk721

    glennk721 MajorGeek


    Yes indeed,,,now im looking into all the crap out there,,,what is the BEST one could buy ???? for a anti/spyware,,,,this I placed on my computer,,,,nocking head on wall,,,,but ,easy to remove,,,also the blocking of the port and IP addy solved it for now,,,Glenn
     
  11. glennk721

    glennk721 MajorGeek

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you look at the sticky threads here in the Spyware Forum (most notably this thread: http://forums.majorgeeks.com/showthread.php?t=35407) You will see some of the stuff we recommend.

    Also see:
    http://forums.majorgeeks.com/showthread.php?t=25834

    PestPatrol is also another good tool. No single tool is good enough.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds