Solved

Browser Hijack ??

Posted on 2004-10-26
643 Views
Last Modified: 2010-04-11
I am working with a customer ( on Windows ME, using Internet Explorer) who is having recurring spyware issues.

I have run SpySweeper, AdAware & SpyBot repeatedly to eliminate numerous issues, but it appears the root cause has not been detected yet.

2 programs I noticed running are highly suspicious.  However, I can find nothing that talks about how to remove them.

Anyone familiar with the programs..........Wbzfyq or Jqhkmu ?

Thanks
#4
0
Question by:BrettFavre4
    5 Comments
     
    LVL 65

    Accepted Solution

    by:
    Hello BrettFavre4 =)

    U are running WinME, so are u disabling System Restore >> http://www.pchell.com/virus/systemrestore.shtml
    Also Download these tools and install them:
    ========================================================
    AdAware ==> http://www.spychecker.com/program/adaware.html
    SpyBot  ==> http://www.spychecker.com/program/spybot.html
    CoolWebShredder ==> http://www.spychecker.com/program/coolwebshredder.html
    ========================================================

    Then Run all of them one by one in safemode and delete everything they detect.
    Then delete the temporary internet files and history of IE
    and run Disk Cleanup on ur hard drive to delete those temp and junk files.
    Restart back in Normal Mode to check for the problems now ??

    If still no luck then Download HijackThis v1.98.2 from here, run it and Save the LOG file:
    http://tools.radiosplace.com/HijackThis.exe

    Then Post that log at this site >> http://www.hijackthis.de/index.php?langselect=english
    and it will automatically analyse it for u,,, Fix the entries which it labels as Nasty :)
    To Fix, check the lines and click on Fix Checked !!

    HJT Log Tutoriol >> http://aumha.org/a/hjttutor.php

    CAUTION: Before fixing the entries in hijackthis, make sure that they are really Nasty and can be deleted, better u first research for it on Google and then when u will confirm that they shud be deleted, Fix them. And whenever u run Hijackthis, run it from a New folder on ur desktop, so that in case of any problem, u can take advantages of its created backups of fixed items. And in case if u still face problems in dealing with it, just analyse ur log at the above site, and then scroll down where u will see a Save Analyse button, hit it and it will save ur Log Analysation, then copy the link of that page and paste it here, and we will check it for u :)
    0
     
    LVL 18

    Assisted Solution

    by:luv2smile
    Did you update spybot and adaware before running and did you run them in both safe and normal mode? Also turn off system restore before running.

    If AFTER you do that, then I would suggest downloading and running hijackthis: http://www.spywareinfo.com/~merijn/files/hijackthis.zip

    Here is a tutorial on HijackThis

    http://www.spywareinfo.com/~merijn/htlogtutorial.html

    Post your hijackthis log file at this website:

    http://www.hijackthis.de/index.php?langselect=english


    0
     
    LVL 65

    Assisted Solution

    by:SheharyaarSaahil
    >> Anyone familiar with the programs..........Wbzfyq or Jqhkmu ?

    nopes they are just JUNK Items,,,, if u can find them on ur system, just delete them in safemode :)
    Also dont forget to use msconfig to eliminite unwanted items > http://netsquirrel.com/msconfig/
    Good Luck :)
    0
     

    Author Comment

    by:BrettFavre4
    Thanks

    The key point was making sure that I ran the tools in normal AND safe mode.

    :)

    0
     
    LVL 65

    Expert Comment

    by:SheharyaarSaahil
    =)
    0

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    IT, Stop Being Called Into Every Meeting

    Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

    As a financial services provider, your business is impacted by two of the strictest federal regulations on record: the Sarbanes-Oxley Act and the Gramm-Leach-Bliley Act. Correctly implementing faxing into your organization to provide secure, real-ti…
    Don’t let your business fall victim to the coming apocalypse – use our Survival Guide for the Fax Apocalypse to identify the risks and signs of zombie fax activities at your business.
    This video Micro Tutorial is the second in a two-part series that shows how to create and use custom scanning profiles in Nuance's PaperPort 14.5 (http://www.experts-exchange.com/articles/17490/). But the ability to create custom scanning profiles a…
    Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

    884 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    16 Experts available now in Live!

    Get 1:1 Help Now