What happened to the Messenger Plus! forums on msghelp.net?
Shoutbox » MsgHelp Archive » Skype & Technology » Tech Talk » Google search results forwards me to 201.218.196.152

Pages: (2): « First « 1 [ 2 ] Last »
Google search results forwards me to 201.218.196.152
Author: Message:
zaher1988
Senior Member
****

Avatar
Inseperable

Posts: 699
Reputation: 10
36 / Male / Flag
Joined: Jun 2005
Status: Away
O.P. RE: Google search results forwards me to 201.218.196.152
quote:
Originally posted by djdannyp
also try resetting all the advanced settings, etc

Delete all browsing history/temporary files/cookies/downloaded program files (Tools->Internet Options)

One of these has done it, in spite that i did those things from the begning and before trying to use any AV or anti spyware, but now for some reason it worked it out.

Thanks to all who contributed in this thread.
09-30-2007 01:40 PM
Profile E-Mail PM Web Find Quote Report
zaher1988
Senior Member
****

Avatar
Inseperable

Posts: 699
Reputation: 10
36 / Male / Flag
Joined: Jun 2005
Status: Away
O.P. RE: Google search results forwards me to 201.218.196.152
quote:
Originally posted by zaher1988
quote:
Originally posted by djdannyp
also try resetting all the advanced settings, etc

Delete all browsing history/temporary files/cookies/downloaded program files (Tools->Internet Options)

One of these has done it, in spite that i did those things from the begning and before trying to use any AV or anti spyware, but now for some reason it worked it out.

Thanks to all who contributed in this thread.

Okay i withdraw what i said.

This seemed either to fix it temporary or never fixed it, because just today, a day or two after applying this i'm again faced with the same issue even though i'm not browsing any suspecious site so that i catch the spyware again.

10-02-2007 01:26 PM
Profile E-Mail PM Web Find Quote Report
Adeptus
Senior Member
****


Posts: 732
Reputation: 40
Joined: Oct 2005
RE: Google search results forwards me to 201.218.196.152
Try to disable any IE add-ons (Tools->Manage Add-ons). 

Other than that, it is safe to say that you have acquired malware of some sort.  If no antivirus and antispyware product will find and remove it (which is possible -- there's always something new out there), then you may just have to reinstall Windows clean.
10-02-2007 09:30 PM
Profile E-Mail PM Find Quote Report
zaher1988
Senior Member
****

Avatar
Inseperable

Posts: 699
Reputation: 10
36 / Male / Flag
Joined: Jun 2005
Status: Away
O.P. RE: Google search results forwards me to 201.218.196.152
there are two weird addons one is called capesnp.dll another called Research, both with no publisher mentioned.

This post was edited on 10-02-2007 at 09:42 PM by zaher1988.
10-02-2007 09:38 PM
Profile E-Mail PM Web Find Quote Report
Adeptus
Senior Member
****


Posts: 732
Reputation: 40
Joined: Oct 2005
RE: Google search results forwards me to 201.218.196.152
The "Research" add-on usually comes from Microsoft Office, in which case it is safe.  However, you can disable it anyway, as it is only required for the research pane nobody uses.

The other one is definitely malware trying to disguise itself as a system file.  The Windows system DLL of similar name is capesnpn.dll and it's not a BHO.   Disable it and see if that fixes your problem (at least for a while -- malware often manages to come back).
10-02-2007 10:00 PM
Profile E-Mail PM Find Quote Report
rk302
New Member
*


Posts: 1
Joined: Oct 2007
201.218.196.152 [SOLVED...FOR NOW]
I've been experiencing the same thing here since Sept 27.  Went thru all of the suggestions found all over the internet (not many because this, I think is a relatively new malware) including SmitFraudFix.  Finally, as a result of Adeptus's fine suggestion, I started disabling all of the unsigned or un-verified publisher add ons on MSIE.  This worked!  Then I started re-enabling them one by one to see if I could zero in on the culprit.  For me, it was a file called ACTXPRX.DLL    Anyway, for now, I am not being hijacked by 201.218.196.152   Good Luck....Thanks Adeptus!

Oh, by the way, the problem was unique (of course) to MSIE.  Never had the problem when running other browsers (Firefox), which I need to do because I'm a web developer.
10-03-2007 03:50 PM
Profile E-Mail PM Find Quote Report
RaceProUK
Elite Member
*****

Avatar

Posts: 6073
Reputation: 57
39 / Male / Flag
Joined: Oct 2003
RE: Google search results forwards me to 201.218.196.152
Firefox doesn't have BHOs, which is why its not vulnerable.

This post was edited on 10-03-2007 at 06:01 PM by RaceProUK.
[Image: spartaafk.png]
10-03-2007 06:01 PM
Profile PM Web Find Quote Report
zaher1988
Senior Member
****

Avatar
Inseperable

Posts: 699
Reputation: 10
36 / Male / Flag
Joined: Jun 2005
Status: Away
O.P. RE: Google search results forwards me to 201.218.196.152
I can confirm so far after searching for couple of days without being redirected that disabling the addon called capesnp.dll solved the problem.

The file is in system32, i just wonder why no program was able to identify it as something wrong. Anyway i guess it is safe to manually delete the dll file from there.

Thank you again
10-04-2007 04:17 PM
Profile E-Mail PM Web Find Quote Report
Pages: (2): « First « 1 [ 2 ] Last »
« Next Oldest Return to Top Next Newest »


Threaded Mode | Linear Mode
View a Printable Version
Send this Thread to a Friend
Subscribe | Add to Favorites
Rate This Thread:

Forum Jump:

Forum Rules:
You cannot post new threads
You cannot post replies
You cannot post attachments
You can edit your posts
HTML is Off
myCode is On
Smilies are On
[img] Code is On