Forum Moderators: open

Message Too Old, No Replies

Content Blocking Help

IE, browsers, IIS, INS, Norton

         

mrfori

10:29 am on Feb 17, 2004 (gmt 0)

10+ Year Member



Hi Guys,

Something wear is happening to me. (To the best of my knowledge).

I try to access sites like www.cj.com or www.linkshare.com and my browser somehow gets redirected to [localhost...] .. where I have a default.asp page.

I am running IIS , Norton Antivirus and Norton Internet Security .. disabling the two last ones doesn't make any difference.

I have updated my Win XP .. with all patches

Here is my NIS Logs .. after attempting www.cj.com

I get few of this errors in the Firewall Tab

Date: 2/17/2004 Time: 21:24:55
Rule "Default Block UPNP" stealthed (FRANK(202.173.135.5),ssdp(1900)). Details:
Inbound UDP packet
Local address,service is (FRANK(202.173.135.5),ssdp(1900))
Remote address,service is (FRANK(202.173.135.5),28120)
Process name is "C:\WINDOWS\System32\svchost.exe"

And these on the privacy tag
Allowed Cookie: Cookie: CONTID=1172994; ASPSESSIONIDQCQTARDC=JENNCCPAGHNEBGNDMJBBEFBN sent to [cj.com...]

Allowed Cookie: Cookie: CONTID=1172994; ASPSESSIONIDQCQTARDC=JENNCCPAGHNEBGNDMJBBEFBN sent to [cj.com...]

Allowed User-Agent: User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 1.0.3705) sent to [cj.com...]

Allowed Cookie: Cookie: CONTID=1172994; ASPSESSIONIDQCQTARDC=JENNCCPAGHNEBGNDMJBBEFBN sent to [cj.com...]

Allowed User-Agent: User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 1.0.3705) sent to [cj.com...]

Allowed Cookie: Cookie: CONTID=1172994; ASPSESSIONIDQCQTARDC=JENNCCPAGHNEBGNDMJBBEFBN sent to [cj.com...]

Allowed User-Agent: User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 1.0.3705) sent to [cj.com...]

I'd appreciate any ideas, suggestions?

Thanks in advance

mrfori

12:54 pm on Feb 17, 2004 (gmt 0)

10+ Year Member



Hi guys

I already fixed my problem.
I edit the file Windows/etc/Hosts

where Windows keeps track of local virtual hosts .. where it says that many sites were local.

This trick is used by adaware/spyware programs. KazaaLite is one of them.

txs

Frank