Spyware that can't be detected.
-
Spyware that can't be detected.
I have a site blocked on my firewall - www.emeagwali.com 68.178.211.7 - that seems to have somehow got something onto my PC, as my firewall is reporting numerous attempts, by various programmes (Firefox/BOINC/Yahoo Messenger/LogiTech and others) to connect to this site.
I blocked the site, after reading somewhere (maybe here) that it was a cracker's site. Seems to be the right decision, given the number of alerts that flash up, saying all these different programmes are attempting to contact this site.
However none of my anti-virus/anti-spyware apps are able to find anything relating to what is using the other apps to try to connect. Anyone got any ideas?
ragebe
-
Incidentally, it's status is given as clear, see following google cache <http://72.14.207.104/search?q=cache:iViFs38x3SgJ:www.whois.sc/emeagwali.com+%22emeagwali.com%22&hl=en&gl=uk&ct=c lnk&cd=3>
but why it should be clear, when I've got numerous progs trying to connect to the site, seems odd to me.
On top of which, it seems to host solutions on hacking Yahoo IDs
<http://72.14.207.104/search?q=cache:-h-QcBwll0EJ:call.realtechnews.com/hack-yahoo-email-id.htm+%22emeagwali.com%22&hl=en&gl=uk&ct=clnk&cd= 79>
and
<http://72.14.207.104/search?q=cache:8xtqJxwKBfkJ:discuss.extremetech.co m/forums/1004296045/ShowPost.aspx+%22emeagwali.com%22&hl=en&gl=uk&ct=c lnk&cd=150>
Last edited by ragebe; 09-02-2006 at 12:46 PM.
Reason: Another interesting link
-
If your other anti-virus / anti-spyware apps aren't picking anything up, get yourself a copy of HiJackThis from www.merijn.org and then follow the guidelines for installing it and posting a log file in the Spyware/Security section of our forum. HiJackThis will show us if you have a "browser hijacker" - a bunch of rogue settings on your PC that are modifying the way that applications can connect to the Internet. That IP address that you gave is very useful as that's probably the way that it would be identified in the HiJackThis log file
-
Okay, have posted a log @
<http://www.d-a-l.com/help/showthread.php?p=87318#post87318>
Many thanks,
ragebe
-
Thanks Ragebe. I'm going to close this thread now that I see that it's all in hand in the Security section of the forum 
---------------------------------------------------------------
This thread has been Resolved and has been locked to prevent other users hijacking the thread and to help others know which threads have been Resolved and which are still being worked on.
If you started this thread and the problem returns or the case has not been properly Resolved, please send a Private Message to an Administrator or a Moderator of this forum to have the thread opened again. If you have a different problem, please start a new thread.