Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > OS & Software > Misc. Software & Utilities

IE possessed!

Reply
Bookmark / Share this page
Thread Tools
  #1  
Old 09-29-2003
Newcomer, in training
 
Member since: Sep 2003, 6 posts
IE possessed!

Brief: I currently have a cable DSL, RCA router (with a generic IP address, no?) and Norton anti virus. I have recently scanned for viruses, installed all current patches of IE and Windows and still my IE is possessed by smut (gambling, porn, warning your computer can be tracked protection software ads, etc, etc).

Problems:
1. IE will open on its own onto my screen
2. Sites will commandeer my default site
3. Sites will insert themselves onto my favorites list (deleting them only makes room for new ones).

What’s going on? I thought I was protected. Do I have some back door open; wrong setting somewhere, accidentally installed something I shouldn’t have?

*note if I go to Network connections there is an item there which I don’t recognize. It just says: 1394 Connection enabled. I look under properties and am still unsure about. I’d delete/uninstall it but I don’t know if it’s good (necessary to the router) or bad (some Trojan horse), or neither.


BTW: I got an email to introduce myself. I’m currently a grad student, former military and the proud owner of a boxer (just a great dog). I also feel like one of the employees in that SNL skit “Nick Burns, your company computer guy” when it comes to computers, but I’m willing to learn.

This is my second thread and on the first one I was over whelmed at the number of responses. You all are great very helpful… so a heartfelt thanks to all.
Reply With Quote
  #2  
Old 09-29-2003
poertner_1274's Avatar
TS Special Forces
 
Location: Saint Louis, MO, USA
Member since: Feb 2002, 4,561 posts
System specs
Well it sounds like you have some spyware on your system. Download adaware and spybot to look for other stuff. This should get rid of all those popups and stuff.

BTW,
Welcome to TechSpot
Reply With Quote
You can remove this banner by registering, join the TS Community for free.
  #3  
Old 09-29-2003
Nodsu's Avatar
TS Special Forces
 
Location: Estonia
Member since: Feb 2002, 9,430 posts
System specs
Plus, disable "install on demand" in IE options, disable running unsafe scripts and read all dialog boxes carefully before clicking yes
Reply With Quote
  #4  
Old 09-30-2003
StormBringer's Avatar
TechSpot Guru
 
Location: USA
Member since: Apr 2002, 2,871 posts
Quote:
*note if I go to Network connections there is an item there which I don’t recognize. It just says: 1394 Connection enabled. I look under properties and am still unsure about. I’d delete/uninstall it but I don’t know if it’s good (necessary to the router) or bad (some Trojan horse), or neither
1394 is firewire, you probably have one or more firewire ports on your machine. Why it has an active connection is something I can't answer unless your modem is using it rather than an NIC or USB.
Reply With Quote
  #5  
Old 09-30-2003
Rick's Avatar
TS Special Forces
 
Location: Los Angeles, CA
Member since: Feb 2002, 4,839 posts
Sounds like you've been visiting the wrong sites.

www.lavasoft.com should remove your spyware, including browser hijackers etc...

For future protection, AdAware Pro protects your computer from future invasions. Also, setting your IE security settings to something more secure may help you out a bit.
Reply With Quote
  #6  
Old 10-03-2003
Newcomer, in training
 
Location: St.Petersburg,FL
Member since: Aug 2003, 15 posts
search for this file Bootconf.exe it is known to do what you described.
Reply With Quote
  #7  
Old 10-06-2003
Newcomer, in training
 
Member since: Sep 2003, 6 posts
Yes I found "bootconfig" also "tpicfg" and "wmssys" all in C:\ listed as applications but with no summaries.

Should I delete these?
Reply With Quote
You can remove this banner by registering, join the TS Community for free.
  #8  
Old 10-06-2003
vassil3427's Avatar
TechSpot Booster
 
Member since: Feb 2002, 822 posts
Did you even bother to run Adaware??? Run that, it should remove all that stuff....
Reply With Quote
  #9  
Old 10-06-2003
Newcomer, in training
 
Member since: Sep 2003, 6 posts
Yes I bothered!!!! (jeez, nice attitude buddy) and it doesn't erase those three.
Reply With Quote
  #10  
Old 10-06-2003
StormBringer's Avatar
TechSpot Guru
 
Location: USA
Member since: Apr 2002, 2,871 posts
wmssys seems to be bad according to the only result I found on google for it.

This link my also interest you. There is a utility there called Hijack This, which seems to be pretty good at helping to identify spyware that hijacks your browser and help you get rid of it. http://www.spywareinfo.com/~merijn/

Last edited by StormBringer; 10-07-2003 at 01:18 PM.
Reply With Quote
  #11  
Old 10-07-2003
Mictlantecuhtli's Avatar
TS Special Forces
 
Location: Finland
Member since: Feb 2002, 4,749 posts
System specs
Thanks to Windows' file system, files can't be removed if they're in use. Check with Task Manager that they aren't running, kill the processes if they are. Then you should be able to delete them.
Reply With Quote
  #12  
Old 10-09-2003
TS | Thomas's Avatar
TechSpot Elite
 
Location: Ireland
Member since: Feb 2002, 1,327 posts
Try Spybot instead - http:/security.kolla.de
Reply With Quote
  #13  
Old 10-09-2003
Rick's Avatar
TS Special Forces
 
Location: Los Angeles, CA
Member since: Feb 2002, 4,839 posts
For AdAware, did you update the ad defenitions? It works a bit like a virus scanner, requiring the latest definitions to catch new spyware.
Reply With Quote
  #14  
Old 10-09-2003
Rick's Avatar
TS Special Forces
 
Location: Los Angeles, CA
Member since: Feb 2002, 4,839 posts
You may even want to boot into Safe Mode and run AdAware. This will allow it to delete or disable just about anything you cannot in Normal Mode.
Reply With Quote
  #15  
Old 10-11-2003
Tarkus's Avatar
TechSpot Chancellor
 
Location: Martinez, CA
Member since: Mar 2002, 814 posts
try this to remove bootconf

http://www.pestpatrol.com/PestInfo/b/bootconf.asp
Reply With Quote
Reply
Thread Tools

Forum Jump


All times are GMT -4. The time now is 10:17 AM.