?
Solved

Hijacked browser on company laptop

Posted on 2003-11-06
14
Medium Priority
?
3,627 Views
Last Modified: 2012-05-04
Hi all. The problem I have is that my browser default page is set to some russian porn site either sexyque or www.puh.ru . I have installed hijack blaster which keeps it at bay but I want rid of it.  No matter what I try I can't get rid of it. Tried Spyware, virus protection both of which didn't work. Is there something in the registry that can be deleted? Heard that downloading music files can cause this? Deleted WinMx and MPEGs but still no luck. The reason why this is priority for me is that it's my company laptop, so you can understand my dilema.

Thanks.

Gee.
0
Comment
Question by:graemen
10 Comments
 
LVL 49

Expert Comment

by:sunray_2003
ID: 9696817
After these try repairing IE

Description of the Internet Explorer Repair Tool
http://support.microsoft.com/default.aspx?scid=http://support.microsoft.com:80/support/kb/articles/Q194/1/77.asp&NoWebContent=1

How to Reinstall or Repair Internet Explorer and Outlook Express in Windows XP
http://support.microsoft.com/?kbid=318378

Repair Internet Explorer 6
http://www.theeldergeek.com/repair_ie6.htm

http://support.microsoft.com/?kbid=293907

Unable to Open Link
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q281679&sd=tech

Sunray
0
 
LVL 97

Accepted Solution

by:
war1 earned 2000 total points
ID: 9696826
Greetings, graemen!

A Porn site has downloaded something into your computer.

1. If you have Windows Messenger Service, disable it.  The Messenger service is typically not needed for home users.

Right-click My Computer and click Manage.
Fold out the Services and Applications option and click Services.
Right-click the Messenger entry, select Properties, and choose Disable under Startup Type.
Click OK.

You should no longer receive messages sent via the messenger service.

2. Use the following scanners to find and remove the website.  Sunray has mentioned these scanners.

SpyBot S&D searches your harddisk for so-called spy- or adbots;
http://security.kolla.de/
or
Adaware
http://www.lavasoftusa.com/software/adaware/

Download the latest updates and run the scanner.

3. Some porn websites redirects links to their websites using your HOSTS file. Do a search for the HOSTS (without extension) file and remove the entry.

4. If still no joy, download HijackThis from Spywareinfo download page

http://www.spywareinfo.com/downloads.php

Run the program and you will find many entries. Most are OK. Post the log. I will find the problem for you.

5. For future preventive maintenance, make sure programs cannot just download on your computer without your permission.  From the Internet Toolbar, go to Tools > Internet Options > Advanced.  Make sure "Enable Install On Demand (Internet Explorer)" and "Enable Install On Demand (Other)" are unchecked.

Best wishes, war1
0
Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

 
LVL 15

Expert Comment

by:VincentPuglia
ID: 9698487
Hi,

  Did you try changing your browser's default home page?  

windows:
settings-->control panel-->internet options-->General-->default home page.

  IE:  tools-->internet options-->general-->default home page

NN6: edit-->preferences-->navigator-->home page

Firebird: Tools-->General-->home page

Vinny

Vinny
0
 
LVL 2

Expert Comment

by:cubolahead
ID: 9700382
Just to ad my experiences:

BHO Demon - deals very effectively with your problem, if it is done with Browser Helper Objects. Many browser hijackers go to this category. And it's freeware.

Cheers,
Cubolahead
0
 
LVL 97

Expert Comment

by:war1
ID: 9705292
Check these items in HijackThis log and let HT remove them.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.radiometer.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.radiometer.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.puh.ru/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://acc.count-all.com/--/?riqrq (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://acc.count-all.com/--/?riqrq (obfuscated)

O17 - HKLM\System\CCS\Services\Tcpip\..\{55E917B6-4227-496B-84DB-C4F6BB30F41F}: NameServer = 194.168.4.100 194.168.8.100

The above are search files.  No obivous sign of naked ladies except maybe the last one. If the above does not work, check your HOSTS (without extention) file.
0
 
LVL 49

Expert Comment

by:sunray_2003
ID: 9705630
Is this the one

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.puh.ru/search.html

Try deleting it

Sunray

0
 
LVL 49

Expert Comment

by:sunray_2003
ID: 9705635
just go to start --> run --> regedit

it will open registry .


You can delete the entries  there ..should not affect other files if you know what you are deleting


Sunray
0
 
LVL 49

Expert Comment

by:sunray_2003
ID: 9705639
Sorry for posting in different areas. I should have acted prior to posting the comments

Sunray
0
 

Author Comment

by:graemen
ID: 9753562
Thx to all that helped. This is a top class site.

Regards.

Gee.
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Bada platform is becoming more and more famous this days and people talking about same. Some friends included those who have bada OS mobile asked me "what is bada?"and "what its features?". That encouraged me to research and write this article. [st…
Ever visit a website where you spotted a really cool looking Font, yet couldn't figure out which font family it belonged to, or how to get a copy of it for your own use? This article explains the process of doing exactly that, as well as showing how…
How to create a custom search shortcut to site-search Experts Exchange using Google in the Firefox browser. This eliminates the need to type out site:experts-exchange.com whenever you want to search the site. Launch your Bookmark Menu: Press 'Ctrl +…
Want to learn how to record your desktop screen without having to use an outside camera. Click on this video and learn how to use the cool google extension called "Screencastify"! Step 1: Open a new google tab Step 2: Go to the left hand upper corn…
Suggested Courses

616 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question