Jump to content

Recommended Posts

Posted (edited)

Hi All,

I’ve got a very tough little hijack (or that what I think it is). Happens in one classroom only. Brand new clean install of Windows 7 pro (with usual IE11, Office 13, Adobe CC – same as the other IT rooms), then third lesson into the day all machines stopped accessing the internet. This has happened for the second time, the teacher says that they aren’t accessing any doggy sites (I think that one of these sites is infected). Looking at it closer all had proxy setting changed to 127.0.0.1 with random port (10254 for example). I’ve got proxy settings pushed with Group Policies. Changing it manually doesn’t work, as soon as you open IE it resets it back. Checked Registry – HKEY_CURRENT_USER-Software-Microsoft-Windows-CurrenVersion-Internet Settings, Proxy Settings are changed to 127.0.0.1 (with the same port), remove it, start IE - it goes back.

 

Run Malwarebytes it found between 130 to 150 registry Hijacks but doesn’t show which program causing it, run several other antimalware (including ESETPoweliksCleaner) programs after - nothing but problem is still there. Running latest Viper antivirus – it picked up nothing.

 

Not sure if it has got anything to do with it but when I reset proxy settings in IE (just remove proxy) and click OK then in Task Manager two processes kick in. First is DLLHOST.EXE then ABTutorRestart.exe, they stay for 2-3 seconds and then proxy setting are reset to 127.0.0.1. Checked my startup – all on minimum and nothing strange there. Looked in Registry – RUN – all looks clear.

 

Just wander if anybody have any ideas, I’m running out of options here.

 

Thanks.

Edited by happierlarry
Posted

Try and work out what the affected computers have in common.

 

Can you recreate the issue yourself?

 

Does it happen to all the computers at the same time? If so what are the affected boundaries? One classroom, one vlan, one model of pc. Specific time?

 

If its one classroom but there are more computers in same setup (same vlan and build) it says to me something the users are doing as its contained to one room

 

If so, get an effected user to recreate the issue with you

Posted
I had this once. Turns out the teacher had set a block internet policy which puts a non existent proxy in blocking all internet traffic. Check your AB Tutor internet policy!
Posted

Thanks everyone,

I think I've found the problem! It is ABtutor but it's not the Internet block policies as instead of blocking access, it was pushing 127.0.0.1 proxy with random port on different machines.

This particular teacher very often pushes her screen to pupil machines for demonstration. She just went to different IT room (different hardware and setup) and the same thing happened again and as I mentioned earlier ABtutor restarts every time I remove the 127.0.0.1 proxy. So, I just uninstalled ABtutor from three machines and they back to normal!!!

 

We are on the phone to ABtutor at the moment. Will keep you posted.

 

Thanks.

Posted (edited)

I have had exactly this with an older version of ABTutor.

 

It was a bug in the client IIRC.

 

An upgrade fixed it.

Edited by box_l
Posted

It's all fixed now. Had to get ABtutor support to have a look. And yes between older version of ABtutor and some badly setup policies all the problems happened. The only thing is 150 registry hijacks are unexplained, though the ABtutor support chap said that it could be false positives from bad ABtutor policies. So, no more policies set be teachers and yes - keep on top with updates!

 

Thanks everyone!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...