3800 i have a BIG problem...

OK... i was surfing last night, hit a few sites I should not have, and i had a TON of crap spyware progs installed. I have run Spybot and adaware several times and they now come up clean.
I have combed the registry and executibles and I am pretty sure i got everything...
whatever got installed was NASTY. I woke this morn to have 86 website shortcuts on my desktop!!!! :eek:
and 36 open instances of IE!!

anyhoo, it is no longer doing all that HOWEVER, i can no long use IE (ver 6 sp1 and all current hotfixes applied). when i try to open ANY site, i get the "Cannot find server or DNS Error" :(
I DO have access to the net cuz my weatherbug, yahoo messenger, email and other things are working fine. I just cant use IE :eek: what gives????

HELP ME!!!!

BTW.. my netscrape 7 is ok and i can surf with that :blink: :unsure:
 

iliveonnitro

TCG Elite Member
Nov 11, 2008
1,036
0
Schaumburg, IL
Isn't weatherbug adware in itself?

Also, try uninstalling IE and scanning through your add/remove programs menu for anything that you know you don't use, and uninstall.

Restart, run adaware and regcleaner (I use RegScrubXP), then reinstall IE from microsofts site and make sure no settings are transfered between each installs.

Also, use AVG 6.0 or w/e version is out, its a free virus scanner, it couldnt hurt.





Stop looking at porn and this wouldnt happen. ;)

GL
 
i have done that as well... cookies gone, history cleared and all security/hotfixes applied...

It has to be some sort of DNS rerouting for IE but I for the life of me cant find it.
the hosts file is ok and at the command prompt, i can ping by name or address. other apps can access the internet as well... even netscrape.

it is just IE. anyone know where it gets its DNS info?
it is not in the NIC properties since that would affect ALL internet connections (and those are correct anyway).

come on peeps!! help me out here!
 

staceyyearsich

TCG Elite Member
Nov 10, 2008
4,087
0
Crete
Same thing happened to me last nite, my IE was NOT working i fI clicked on IE 50freakin pop-ups came and it owuld say page cant be displayed or sumthing, I went into internet options and moved my privacy level to med-high, and then there was no pop ups and I could use IE, very weird cause I downloaded a program on my computer and it had said I had 96applications of spyware on there but nortan virus scan didn't detect it, so now I can get on IE but I have 96spywares on there, I need a FREE program that I can get those off of my NEW computer b4 my dad kills me... uggg
 
I

imported_GraFFix

Guest
Actually Chrys my friend just had this last week...we tried everything to fix it. I forget what exactly this is called but Adaware and Spybot dont take care of it..there was one program that we found that was supposed to take it off but it costs 40 bucks...

He ended up reformatting his drive.

Im at home right now..when i get to work ill call him and ask him what that trojan was. I will post the results give me about an hour :)

he had the exact same problem...
 
I

imported_GraFFix

Guest
OK....

the trojan he had was connected to something called "Internet optimizer"

-----------

Description
Internet Optimizer is an error page hijacker.

Variants
InternetOptimizer/Iopti: unknown-server errors, page-missing errors, server errors and even password-required errors are redirected to Internet Optimizer's controlling server at www.internet-optimizer.com.

InternetOptimizer/Nem: as Iopti, but searches are hijacked to yoogee.com (a search site run by the makers of InternetOptimizer).

InternetOptimizer/Wsem: a larger version of the software, whose purpose is unclear.

InternetOptimizer/Crmrest: an ActiveX downloader control for InternetOptimizer.

Also known as
DyFuCA.

Distribution
May be installed by MoneyTree/DyFuCA, or the Crmrest variant. The latter poses as a comedy or porn video from the site movies-etc.com, and when allowed to install may forward a mail to all contacts in your Outlook address book, promoting movies-etc in your name.

What it does
Advertising
Yes. The 'DyFuCA Active Alert' component can open pop-up 'alerts' when directed by its controlling server.

Privacy violation
Suspected. The EULA at Internet Optimizer's web site states the software may send all your browsing information back to its controllers. At the time of writing, however, this has not been seen to happen with the current version of the software.

Security issues
Yes. Can download and execute arbitrary unsigned code from its controlling server, as an update feature.

Stability problems
Unknown; some unclear user reports of it causing crashes.

Removal
Check the Control Panel's Add/Remove Programs feature for 'Active Alert' and 'Internet Optimizer'. If these entries are there, using both should result in InternetOptimizer's correct removal. Afterwards, ensure MoneyTree/DyFuCA is no longer loaded.

Manual removal
For the Crmrest installer variant, open the Downloaded Program Files folder (inside the Windows folder) and remove the 'Media Manager' entry.

For other variants, open the Windows folder. You should be able to see a file 'ioptiXXX.dll' (Iopti variant), 'nemXXX.dll' (Nem variant) or 'wsemXXX.dll' (Wsem variant). The XXX differs for different versions; common versions are 'iopti130.dll', 'nem207.dll' and 'wsem210.dll'.

Open the registry (click 'Start', choose 'Run' and enter 'regedit') and find the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. Delete the entries 'DyFuCA' and 'DyFuCA Active Alerts'.

Now open a DOS command prompt window (from Start->Programs->Accessories), and enter the following commands (for the Iopti variant):

cd "%WinDir%\System"
regsvr32 /u ..\iopti130.dll
Or, for the Nem variant:

cd "%WinDir%\System"
regsvr32 /u ..\nem207.dll
Or, for the Wsem variant:

cd "%WinDir%\System"
regsvr32 /u ..\wsem210.dll
Restart the computer and you should be able to delete the DLL from the Windows folder, and the 'DyFuCA', 'Internet Optimizer' or 'STWSI' folder you may have inside Program Files. You can also delete the subkey 'FCI' in HKEY_LOCAL_MACHINE\Software and HKEY_CURRENT_USER\Software to clean up if you like.

------------

also you can look here.

http://securityresponse.symantec.com/avcen...toptimizer.html

and finally...if your looking for more info search for this "DyFuCA" or "internet Optimizer"

hope this helps...and pest patrol supposedly takes care of this, but they charge you for it.
 
Originally posted by ThaLord@Dec 11 2003, 10:13 AM
if certain sites are being re-rerouted... then there are programs that modify your HOST file... most likely, that is what it is... if not that virus..

If it is not that virus, because that virus is easy to clean, call me, I will walk you through the other thing...
John,
the host file is fine. I have already checked that. there are no stray or out of the ordinary entries there.

NOW, if the program is modifying the Hosts file on the fly somehow and then reverting it back to its original, THAT would be a pretty kewl trick. I would like to know how that is done :D

I hope that doing the procudure above fixes the problem...

hmmm, now I am wondering how i even GOT the stupid thing!! If it is a virus, then McAfee should have snagged it (unless the virus is less than 4 days old...). I have McAfee scanning, email, internet and regular files. I even have heuristics turned on.
is it spyware or a virus??
 
Old Thread: Hello . There have been no replies in this thread for 90 days.
Content in this thread may no longer be relevant. Consider starting a new thread to get fresh replies.

Thread Info