Hijacked browser on company laptop

Hi all. The problem I have is that my browser default page is set to some russian porn site either sexyque or www.puh.ru . I have installed hijack blaster which keeps it at bay but I want rid of it.  No matter what I try I can't get rid of it. Tried Spyware, virus protection both of which didn't work. Is there something in the registry that can be deleted? Heard that downloading music files can cause this? Deleted WinMx and MPEGs but still no luck. The reason why this is priority for me is that it's my company laptop, so you can understand my dilema.

Thanks.

Gee.
graemenAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

sunray_2003Commented:
After these try repairing IE

Description of the Internet Explorer Repair Tool
http://support.microsoft.com/default.aspx?scid=http://support.microsoft.com:80/support/kb/articles/Q194/1/77.asp&NoWebContent=1

How to Reinstall or Repair Internet Explorer and Outlook Express in Windows XP
http://support.microsoft.com/?kbid=318378

Repair Internet Explorer 6
http://www.theeldergeek.com/repair_ie6.htm

http://support.microsoft.com/?kbid=293907

Unable to Open Link
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q281679&sd=tech

Sunray
0
war1Commented:
Greetings, graemen!

A Porn site has downloaded something into your computer.

1. If you have Windows Messenger Service, disable it.  The Messenger service is typically not needed for home users.

Right-click My Computer and click Manage.
Fold out the Services and Applications option and click Services.
Right-click the Messenger entry, select Properties, and choose Disable under Startup Type.
Click OK.

You should no longer receive messages sent via the messenger service.

2. Use the following scanners to find and remove the website.  Sunray has mentioned these scanners.

SpyBot S&D searches your harddisk for so-called spy- or adbots;
http://security.kolla.de/
or
Adaware
http://www.lavasoftusa.com/software/adaware/

Download the latest updates and run the scanner.

3. Some porn websites redirects links to their websites using your HOSTS file. Do a search for the HOSTS (without extension) file and remove the entry.

4. If still no joy, download HijackThis from Spywareinfo download page

http://www.spywareinfo.com/downloads.php

Run the program and you will find many entries. Most are OK. Post the log. I will find the problem for you.

5. For future preventive maintenance, make sure programs cannot just download on your computer without your permission.  From the Internet Toolbar, go to Tools > Internet Options > Advanced.  Make sure "Enable Install On Demand (Internet Explorer)" and "Enable Install On Demand (Other)" are unchecked.

Best wishes, war1
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Cloud Class® Course: Microsoft Exchange Server

The MCTS: Microsoft Exchange Server 2010 certification validates your skills in supporting the maintenance and administration of the Exchange servers in an enterprise environment. Learn everything you need to know with this course.

VincentPugliaCommented:
Hi,

  Did you try changing your browser's default home page?  

windows:
settings-->control panel-->internet options-->General-->default home page.

  IE:  tools-->internet options-->general-->default home page

NN6: edit-->preferences-->navigator-->home page

Firebird: Tools-->General-->home page

Vinny

Vinny
0
cubolaheadCommented:
Just to ad my experiences:

BHO Demon - deals very effectively with your problem, if it is done with Browser Helper Objects. Many browser hijackers go to this category. And it's freeware.

Cheers,
Cubolahead
0
war1Commented:
Check these items in HijackThis log and let HT remove them.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.radiometer.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.radiometer.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.puh.ru/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://acc.count-all.com/--/?riqrq (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://acc.count-all.com/--/?riqrq (obfuscated)

O17 - HKLM\System\CCS\Services\Tcpip\..\{55E917B6-4227-496B-84DB-C4F6BB30F41F}: NameServer = 194.168.4.100 194.168.8.100

The above are search files.  No obivous sign of naked ladies except maybe the last one. If the above does not work, check your HOSTS (without extention) file.
0
sunray_2003Commented:
Is this the one

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.puh.ru/search.html

Try deleting it

Sunray

0
sunray_2003Commented:
just go to start --> run --> regedit

it will open registry .


You can delete the entries  there ..should not affect other files if you know what you are deleting


Sunray
0
sunray_2003Commented:
Sorry for posting in different areas. I should have acted prior to posting the comments

Sunray
0
graemenAuthor Commented:
Thx to all that helped. This is a top class site.

Regards.

Gee.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Web Browsers

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.