Redirection problem on both pc's

Discussion in 'malware problems & news' started by Niels, Mar 14, 2007.

Thread Status:
Not open for further replies.
  1. Niels

    Niels Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    466
    Location:
    Belgium
    This is a strange situation. Sometimes when we try to access the internet with IE wet get redirected too 195.238.10.14 We have scanned both pc's with xsoftspy se,spybot search&destroy and superantispyware free none of them found anything suspicious. The strange thing is internet works fine with Firefox. But the other user only want to use IE. Could please someone could help me?
    Thanks in advance.

    Niels
     
  2. sultan_emerr

    sultan_emerr Registered Member

    Joined:
    Mar 12, 2005
    Posts:
    18
    Location:
    Tokyo, Japan
    Scan for Browser Helper Objects.
     
  3. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    Also scan for LSPs and check the host file and the DNS settings.
     
  4. Niels

    Niels Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    466
    Location:
    Belgium
    I performed a scan with bhoscanner it detected something but when I took a look in hijackthis it's was a part of prevx. So I don't think that it's a bad BHO. I can't find any reference for 195.238.10.14 in both hosts files. I don't know how I can check the dns settings or how to scan for lsp's and check if they are legitimate or not. Could you please help me? So I can check it on the second pc. The problem started after our router/modem was changed by someone of our isp. That person had configured everything. I have entered the ipaddress into my browser and then I go to a page of my isp. I had also contact them but they say all that it must be malware. Thanks both for you very quick replies. I really appreciated it.

    Niels
     
  5. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    - LSP:
    SpyBot S&D (and SAS, I guess) has a LSP enumerator.
    - DNS:
    Check the network settings of your network adapter.

    If you find nothing, then post a Hijackthis log in a specialized forum.
     
  6. Niels

    Niels Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    466
    Location:
    Belgium
    Thanks for your reply. I took a look but every reference in winsock seems fine. I've used spybot search&destroy to check it.
     
  7. MaB69

    MaB69 Registered Member

    Joined:
    Dec 9, 2005
    Posts:
    540
    Location:
    Paris
    Hi all,

    Reverse resolving the IP gives this : portal.skynet.be and you are belgium may be i give you a clue ;-)

    MaB
     
  8. ravin

    ravin Registered Member

    Joined:
    May 2, 2003
    Posts:
    241
    Location:
    South Carolina
  9. Niels

    Niels Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    466
    Location:
    Belgium
    Hi MaB

    That was also the reason why I contacted them (Skynet is my isp) but they said that it must be malware. Thanks also for your reply.

    Niels

    Hi ravin

    Thanks for your suggestion but I already had run cwsshredder on both pc's. Sorry that I forgot to mention that.
    They were both clean.

    Niels
     
  10. ravin

    ravin Registered Member

    Joined:
    May 2, 2003
    Posts:
    241
    Location:
    South Carolina
  11. Niels

    Niels Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    466
    Location:
    Belgium
    Hi ravin

    Is it safe to use that tool? Because I don't want to loose my internet connection and provider settings.Thank you very much.

    Niels
     
  12. ravin

    ravin Registered Member

    Joined:
    May 2, 2003
    Posts:
    241
    Location:
    South Carolina
    I have used the winsock repair tool many times with no problems. I have not used the lsp fix before. you could always make a restore point before running the tool and if all is not well simply restore.
     
  13. Niels

    Niels Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    466
    Location:
    Belgium
    Hi ravin

    Thanks again. I will try it.

    Niels
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.