Hello
I have a computer that when the user accesses 53.com or scottrade.com it takes you to the login but as soon as enter any account info and password and hit "login" it takes you to another site where it proceeds to ask for all kinds of personal info. These fake sites claim to be using the same SSL certificate. I have scanned this system till I am blue with all the known engines (sophos, panda, trend micro, f-secure, Oncare and a few others) I also ran several of the rootkit revealers. I ran Combofix. Found nothing out of the oridinary with hijackthis that I can see. The system comes up clean over and over. This only pertains to IE, it does not do this with any other browser. I did remove all addon also. All updates are current with windows XP sp3 and IE 7.0
I really would like to know if this is a common bug and anyone else seen this. I don't know where else to look.
Thanks sparkspnt
I have a computer that when the user accesses 53.com or scottrade.com it takes you to the login but as soon as enter any account info and password and hit "login" it takes you to another site where it proceeds to ask for all kinds of personal info. These fake sites claim to be using the same SSL certificate. I have scanned this system till I am blue with all the known engines (sophos, panda, trend micro, f-secure, Oncare and a few others) I also ran several of the rootkit revealers. I ran Combofix. Found nothing out of the oridinary with hijackthis that I can see. The system comes up clean over and over. This only pertains to IE, it does not do this with any other browser. I did remove all addon also. All updates are current with windows XP sp3 and IE 7.0
I really would like to know if this is a common bug and anyone else seen this. I don't know where else to look.
Thanks sparkspnt