happierlarry Posted September 10, 2015 Posted September 10, 2015 (edited) Hi All, I’ve got a very tough little hijack (or that what I think it is). Happens in one classroom only. Brand new clean install of Windows 7 pro (with usual IE11, Office 13, Adobe CC – same as the other IT rooms), then third lesson into the day all machines stopped accessing the internet. This has happened for the second time, the teacher says that they aren’t accessing any doggy sites (I think that one of these sites is infected). Looking at it closer all had proxy setting changed to 127.0.0.1 with random port (10254 for example). I’ve got proxy settings pushed with Group Policies. Changing it manually doesn’t work, as soon as you open IE it resets it back. Checked Registry – HKEY_CURRENT_USER-Software-Microsoft-Windows-CurrenVersion-Internet Settings, Proxy Settings are changed to 127.0.0.1 (with the same port), remove it, start IE - it goes back. Run Malwarebytes it found between 130 to 150 registry Hijacks but doesn’t show which program causing it, run several other antimalware (including ESETPoweliksCleaner) programs after - nothing but problem is still there. Running latest Viper antivirus – it picked up nothing. Not sure if it has got anything to do with it but when I reset proxy settings in IE (just remove proxy) and click OK then in Task Manager two processes kick in. First is DLLHOST.EXE then ABTutorRestart.exe, they stay for 2-3 seconds and then proxy setting are reset to 127.0.0.1. Checked my startup – all on minimum and nothing strange there. Looked in Registry – RUN – all looks clear. Just wander if anybody have any ideas, I’m running out of options here. Thanks. Edited September 10, 2015 by happierlarry
MatthewL Posted September 10, 2015 Posted September 10, 2015 Have a look in your scheduled tasks, I once had some malware that put a load of entries in there.
happierlarry Posted September 10, 2015 Author Posted September 10, 2015 Sorry, forgot to mention - looked there, nothing unusual.
Michael Posted September 10, 2015 Posted September 10, 2015 Are you or do you install any management type software, in addition to using GPOs?
happierlarry Posted September 10, 2015 Author Posted September 10, 2015 The only one is ABTutor (the one that restarts when dllhost kicks in).
happierlarry Posted September 10, 2015 Author Posted September 10, 2015 Tomorrow will try another fresh install but will monitor the software and websites they use and see if I get anywhere with it.
rrrrr Posted September 11, 2015 Posted September 11, 2015 Try and work out what the affected computers have in common. Can you recreate the issue yourself? Does it happen to all the computers at the same time? If so what are the affected boundaries? One classroom, one vlan, one model of pc. Specific time? If its one classroom but there are more computers in same setup (same vlan and build) it says to me something the users are doing as its contained to one room If so, get an effected user to recreate the issue with you
fairm010 Posted September 11, 2015 Posted September 11, 2015 I had this once. Turns out the teacher had set a block internet policy which puts a non existent proxy in blocking all internet traffic. Check your AB Tutor internet policy!
3s-gtech Posted September 11, 2015 Posted September 11, 2015 Yup, I'd be focusing on ABTC. That's just the sort of thing it can do, and just the sort of thing somebody would do.
happierlarry Posted September 11, 2015 Author Posted September 11, 2015 Thanks everyone, I think I've found the problem! It is ABtutor but it's not the Internet block policies as instead of blocking access, it was pushing 127.0.0.1 proxy with random port on different machines. This particular teacher very often pushes her screen to pupil machines for demonstration. She just went to different IT room (different hardware and setup) and the same thing happened again and as I mentioned earlier ABtutor restarts every time I remove the 127.0.0.1 proxy. So, I just uninstalled ABtutor from three machines and they back to normal!!! We are on the phone to ABtutor at the moment. Will keep you posted. Thanks.
box_l Posted September 11, 2015 Posted September 11, 2015 (edited) I have had exactly this with an older version of ABTutor. It was a bug in the client IIRC. An upgrade fixed it. Edited September 11, 2015 by box_l
happierlarry Posted September 11, 2015 Author Posted September 11, 2015 It's all fixed now. Had to get ABtutor support to have a look. And yes between older version of ABtutor and some badly setup policies all the problems happened. The only thing is 150 registry hijacks are unexplained, though the ABtutor support chap said that it could be false positives from bad ABtutor policies. So, no more policies set be teachers and yes - keep on top with updates! Thanks everyone!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now