»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 11-19-2003, 07:10 AM   #1 (permalink)
Registered User
 
JayMan's Avatar
 
Join Date: Oct 2001
Location: Sydney, Australia
Posts: 3,356
JayMan is on a distinguished road
Send a message via ICQ to JayMan
Browser HiJacking!!!

Hey all...

I'm currently looking after a mates house & pets (and PC) while he's away on holidays.

Today i have noticed that for some reason everytime i reboot the PC, the browser's homepage gets reset back to "www.sexpatriot.net" or something like that... And also 2 links are added to the favourites.

I have run both adaware & spybot, both of which have had no luck fixing the problem. And am currently running housecall antivirus to see what it picks up.

Has anybody got some suggestions which may help me to fix this up before my mate gets back from holidays?

Thanks all

JayMan

JayMan is offline   Reply With Quote
Old 11-19-2003, 07:19 AM   #2 (permalink)
Registered User
 
Join Date: Oct 2001
Location: Lake Helen, FL
Posts: 3,492
TOAD6147 is on a distinguished road
Send a message via ICQ to TOAD6147 Send a message via AIM to TOAD6147
Naughty, naught boy!

Have you used all the latest Ad-aware updates? If Spybot and Ad-aware don't fix it I don't know what can. Have you gone through Add/Remove Programs and Task manager to look for suspect programs running in the background? I had a similar problem with my daughter's computer but it from her looking for game sites and not knowing to resist clicking everything it said to. It took me hours to get it fixed and it seems to me I had to uninstall IE Sp and then update and repair it. It was a PAIN!

Last edited by TOAD6147; 11-19-2003 at 07:26 AM.
TOAD6147 is offline   Reply With Quote
Old 11-19-2003, 07:32 AM   #3 (permalink)
Registered User
 
JayMan's Avatar
 
Join Date: Oct 2001
Location: Sydney, Australia
Posts: 3,356
JayMan is on a distinguished road
Send a message via ICQ to JayMan
Yeh ad-aware & spybot were both in their latest versions.

Hmm... Seems i may have fixed it now....

Not sure exactly how tho...

Housecall found a possible virus, something to do with java... I know i did install sun java2 to allow me to use icq2go. So i uninstalled sun java2.

Also i ran a program called CWShredder which someone else with the same problem (google search) was suggested to try & also "HijackThis".

After a reboot, it now seems fine... Fingers crossed...

Everything so far is running clean again (all the above mentioned programs), might see how housecall goes now.

JayMan
JayMan is offline   Reply With Quote
Old 11-19-2003, 07:41 AM   #4 (permalink)
Registered User
 
JayMan's Avatar
 
Join Date: Oct 2001
Location: Sydney, Australia
Posts: 3,356
JayMan is on a distinguished road
Send a message via ICQ to JayMan
Housecall still got those files with the virus & wouldn't clean/delete them.

So's i just manually deleted them no worries.

JayMan
JayMan is offline   Reply With Quote
Old 11-19-2003, 08:14 AM   #5 (permalink)
Registered User
 
Martoch's Avatar
 
Join Date: Mar 2002
Location: Ft. Walton Beach, FL
Posts: 4,056
Martoch is on a distinguished road
Send a message via AIM to Martoch
What OS is it JayMan? You can use the group policy editor to specify the home page...more stable than going through IE to do so.
I realize this is a little off the virus subject...but it's good to know info for future use.
Martoch is offline   Reply With Quote
Old 11-19-2003, 11:16 AM   #6 (permalink)
Registered User
 
PeterGriffin's Avatar
 
Join Date: Nov 2002
Posts: 339
PeterGriffin is on a distinguished road
Surf'n XXX on your mates computer, eh?

Haha
PeterGriffin is offline   Reply With Quote
Old 11-19-2003, 02:08 PM   #7 (permalink)
Registered User
 
JayMan's Avatar
 
Join Date: Oct 2001
Location: Sydney, Australia
Posts: 3,356
JayMan is on a distinguished road
Send a message via ICQ to JayMan
Martoch, tiz running winXP (but he hasnt' run all the updates, probably why it got done).

lol Peter, nah not surfing for that... <cough>warez<cough>....

JayMan
JayMan is offline   Reply With Quote
Old 11-19-2003, 03:47 PM   #8 (permalink)
Registered User
 
tchang's Avatar
 
Join Date: Sep 2003
Location: Boston, USA
Posts: 84
tchang is on a distinguished road
ok, its not that hard, just follow the steps and u will be fine again

1. Start > run > type regedit

2. find
[HKEY_CURRENT_USER\Software\Policies\Microsoft]
delete theInternet Explorer folder

3. find
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="the page u want"

now enjoy ur browser is back to normal
__________________
Shuttle sb61G2 (intel 865G)
P4 2.6 with 800fsb @3.23GHz
Corsair XMS Pro (2 X 512)
nVIDIA 4600 Ti
WD Raptor SATA 10k 36G
Sony DVD RW
tchang is offline   Reply With Quote
Old 11-19-2003, 04:26 PM   #9 (permalink)
Registered User
 
JayMan's Avatar
 
Join Date: Oct 2001
Location: Sydney, Australia
Posts: 3,356
JayMan is on a distinguished road
Send a message via ICQ to JayMan
Quote:
Originally posted by tchang
ok, its not that hard, just follow the steps and u will be fine again

1. Start > run > type regedit

2. find
[HKEY_CURRENT_USER\Software\Policies\Microsoft]
delete theInternet Explorer folder

3. find
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="the page u want"

now enjoy ur browser is back to normal
Trust me, this had been done already, multiple times. There was something that kept re-hijacking every boot up. Also the hosts file (file which stores IP address for popular webpages to speed up browsing time) had been taken over aswell, so some pages were directed to a different IP address e.g. www.yahoo.com was being directed to some "royalsearch" or something like that. I think it was hijackthis which picked up on those.

JayMan
JayMan is offline   Reply With Quote
Old 11-19-2003, 04:57 PM   #10 (permalink)
Registered User
 
U-96's Avatar
 
Join Date: Oct 2001
Location: Silently running through the English Channel
Posts: 1,373
U-96 is on a distinguished road
on spybot the immunize settings allow you to lock the homepage and hosts file from editing. try locking it down then following the regedit suggested by tchang.
chances are there was a nasty little ActiveX script dropped into the browser. Probably sitting in the root or WINNT(for example) folders. Check the dates on files to find new stuff that coincides with your *ahem* browsing
U-96 is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 01:20 AM.