Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
Home
Discussion GroupsWindows VistaWindows XPWindows MeWindows 98Windows 95Virtual PCInternet ExplorerOutlook ExpressWindows MediaSecurity
Related Topics
MS Server ProductsMS OfficePC HardwareMore Topics ...

Windows Forum / Windows XP / Networking and Web / October 2004

Tip: Looking for answers? Try searching our database.

Browser Hijack

Thread view: 
Enable EMail Alerts  Start New Thread
Thread rating: 
Daniel - 30 Oct 2004 15:08 GMT
hi,
Recently i have experienced problems with the Internet Explorer 6. Everytime
i turn on my computer my default home page has changed to (www.easypic.org) i
tried restoring it but with no luck. New favourite sites has been added
containing adult material. When i am browsing net for like 15 minutes, i keep
getting redirected to a porn site and new programs are installed in my
computer even though my internet security levels are set to medium. I tried
removing the 'porn dialers' from my pc but when i browse the net again they
reappear. My specs are as follows Windows XP home edition SP1. Plz could
someone help because my children really want to use the net. Thanks :)
Stalker81598 - 30 Oct 2004 15:37 GMT
you have spyware on your computer. the two URLs below will bring you to the
download pages for ad-aware and spybot. these will find spyware and adware on
your computer and remove it.

ad-aware
http://www.download.com/Ad-Aware-SE-Personal-Edition/3000-8022_4-10319876.html?t
ag=lst-0-1


spybot
http://www.download.com/Spybot-Search-Destroy/3000-8022_4-10289035.html?tag=lst-0-1
______________

-Stalker
______________

> hi,
> Recently i have experienced problems with the Internet Explorer 6. Everytime
[quoted text clipped - 6 lines]
> reappear. My specs are as follows Windows XP home edition SP1. Plz could
> someone help because my children really want to use the net. Thanks :)
Chuck - 30 Oct 2004 15:49 GMT
>hi,
>Recently i have experienced problems with the Internet Explorer 6. Everytime
[quoted text clipped - 6 lines]
>reappear. My specs are as follows Windows XP home edition SP1. Plz could
>someone help because my children really want to use the net. Thanks :)

Daniel,

You have a an adware / spyware infection.  This is a common problem, but will
require some work, including behaviour modification.

Start by downloading each of the following free tools:
AdAware <http://www.lavasoftusa.com/>
CWShredder <http://www.majorgeeks.com/download4086.html>
HijackThis <http://www.majorgeeks.com/download.php?det=3155>
LSP-Fix and WinsockXPFix <http://www.cexx.org/lspfix.htm>
Spybot S&D <http://www.safer-networking.org/index.php?page=download>
Stinger <http://us.mcafee.com/virusInfo/default.asp?id=stinger>

Create a separate folder for HijackThis, such as C:\HijackThis - copy the
downloaded file there.  AdAware, CWShredder, and Spybot S&D have install
routines - run them.  The other downloaded programs can be copied into, and run
from, any convenient folder.

First, run Stinger.  Have it remove any problems found.

Next, close all Internet Explorer and Outlook windows, and run CWShredder.  Have
it fix all problems found.

Next, run AdAware.  First update it ("Check for updates now"), configure for
full scan (<http://forums.spywareinfo.com/index.php?showtopic=11150>), then
scan.  When scanning finishes, remove all Critical Objects found.

Next, run Spybot S&D.  First update it ("Search for updates"), then run a scan
("Check for problems").  Trust Spybot, and delete everything ("Fix Problems")
that is displayed in Red.

Then, run HijackThis ("Scan").  Do NOT make any changes immediately.  Save the
HJT Log.
<http://forums.spywareinfo.com/index.php?showtopic=227>
<http://forums.spywareinfo.com/index.php?showtopic=11150>

Finally, have your HJT log interpreted by experts at one or more of the
following security forums (and please post a link to your forum posts, here):
Aumha: <http://forum.aumha.org/index.php>
Net-Integration: <http://forums.net-integration.net/>
Spyware Info: <http://forums.spywareinfo.com/>
Spyware Warrior: <http://spywarewarrior.com/index.php>
Tom Coyote: <http://forums.tomcoyote.org/>

If removal of any spyware affects your ability to access the internet (some
spyware builds itself into the network software, and its removal may damage your
network), run LSP-Fix and / or WinsockXPFIx.

Finally, improve your chances for the future.

Harden your browser.  There are various websites which will check for
vulnerabilities, here are three which I use.
http://www.jasons-toolbox.com/BrowserSecurity/
http://bcheck.scanit.be/bcheck/
https://testzone.secunia.com/browser_checker/

Block Internet Explorer ActiveX scripting from hostile websites (Restricted
Zone).
<https://netfiles.uiuc.edu/ehowes/www/main.htm>  (IE-SpyAd)

Block known dangerous scripts from installing.
<http://www.javacoolsoftware.com/spywareblaster.html>

Block known spyware from installing.
<http://www.javacoolsoftware.com/spywareguard.html>

Make sure that the spyware detection / protection products that you use are
reliable:
http://www.spywarewarrior.com/rogue_anti-spyware.htm

Harden your operating system.  Check at least monthly for security updates.
http://windowsupdate.microsoft.com/

Block possibly dangerous websites with a Hosts file.  Three Hosts file sources I
use:
http://www.accs-net.com/hosts/get_hosts.html
http://www.mvps.org/winhelp2002/hosts.htm
(The third is included, and updated, with Spybot (see above)).

Maintain your Hosts file (merge / eliminate duplicate entries) with:
eDexter <http://www.accs-net.com/hosts/get_hosts.html>
Hostess <http://accs-net.com/hostess/>

Secure your operating system, and applications.  Don't use, or leave activated,
any accounts with names or passwords with trivial (guessable) values.  Don't use
an account with administrative authority, except when you're intentionally doing
administrative tasks.

Use common sense.  Yours.  Don't install software based upon advice from unknown
sources.  Don't install free software, without researching it carefully.  Don't
open email unless you know who it's from, and how and why it was sent.

Educate yourself.  Know what the risks are.  Stay informed. Read Usenet, and
various web pages that discuss security problems. Check the logs from the
security products that you use regularly, look for things that don't belong, and
take action when necessary.

How did I get infected in the first place?
http://forums.net-integration.net/index.php?showtopic=3051
Essential tips for infection prevention
http://forums.spywareinfo.com/index.php?showtopic=24339

Cheers,
Chuck
Paranoia comes from experience - and is not necessarily a bad thing.
Victor Bien - 31 Oct 2004 09:28 GMT
>>hi,
>>Recently i have experienced problems with the Internet Explorer 6. Everytime
[quoted text clipped - 29 lines]
> Next, close all Internet Explorer and Outlook windows, and run CWShredder.  Have
> it fix all problems found.

[big snips]

> Chuck
> Paranoia comes from experience - and is not necessarily a bad thing.

Daniel,
  This is undoubtedly good advice but you might be rather punch drunk
that you have to do that much.  This is the indictment of Micro$oft's
software which has materialised directly to you.  A couple of years ago
there was an internet paper which was entitled something like "Windows
Insecure by design".  M$ concentrated on snazziness and saleability and
ignored "boring" stuff like security.  The chicken has come home to roost!

  You migh consider third party browsers which are not subject to the
above problems.  Consider Mozilla or its split up pair
Firefox/Thunderbird - www.mozilla.org/ and Opera  - www.opera.com.

  With these you can do most of your browsing.  Then only use IE when
you have to and that way you'll be able to better able to minimise the
impact of the escalating attacks on M$ products.

Signature

To reply by e-mail edit this address to the correct form: vbien at
attglobal dot net

Jack - 30 Oct 2004 17:56 GMT
Hi
May be this can Help.

Basic Steps in cleaning Internet "Junk" - http://www.ezlan.net/clean.html

Internet Infestation: http://www.ezlan.net/infestation.html

Internet -Basic protection: http://www.ezlan.net/firewall.html

Jack (MVP-Networking).

> hi,
> Recently i have experienced problems with the Internet Explorer 6. Everytime
[quoted text clipped - 6 lines]
> reappear. My specs are as follows Windows XP home edition SP1. Plz could
> someone help because my children really want to use the net. Thanks :)
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2008 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.