Off-topic Talk Where overpaid, underworked S2000 owners waste the worst part of their days before the drive home. This forum is for general chit chat and discussions not covered by the other off-topic forums.

Browser hijacking...help?

Thread Tools
 
Old Apr 22, 2005 | 05:36 PM
  #1  
Mindcore's Avatar
Thread Starter
Former Moderator
25 Year Member
Former Moderator
 
Joined: Oct 2000
Posts: 16,175
Likes: 0
From: Erock is da shizzle
Default Browser hijacking...help?

My Dad's IE is hijacked, I tried adaware, s&d, MS, avast, panda, and Hijack this..

Nada, it keeps coming back, I wasted 4 hours today messing with it, and it still taunts me.. any ideas?

thanks

PS, I know most of you will say mozilla etc, I don't want to avoid the problem, I want to correct it.. thanks
Reply
Old Apr 22, 2005 | 06:16 PM
  #2  
ninethreeeleven's Avatar
Registered User
 
Joined: Jul 2003
Posts: 1,395
Likes: 0
From: The Empire State
Default

have you check the processes in the task manager?

I run firefox so I dont have these problems (harmless harassment right there) but I know of most of them, but forget the exact names and ways to fix each.

Anyway, check your processes out. I usually copy and paste them into google and see what pops up. The ones that are spyware or adaware show up with a million results, one or two of which will solve your problem. If you were to search for say (9311 looks in processes tab) csrss.exe you might not get many results, which usually means its not talked about and usually not harmful (which csrss.exe isn't).

Good luck, if this is a brand spanking new virus then give it a weak and all will go bye bye.

Also, while this isn't really a virus, I recommend AVG anti virus (free) if he isn't already running anything. Make sure he gets the windows up dates (I assume this is XP) and try and tell him to switch to FireFox once the problem is fixed.
Reply
Old Apr 22, 2005 | 06:54 PM
  #3  
Mindcore's Avatar
Thread Starter
Former Moderator
25 Year Member
Former Moderator
 
Joined: Oct 2000
Posts: 16,175
Likes: 0
From: Erock is da shizzle
Default

Tried it, nothing suspicious.. for what it's worth, I loaded Firefox for the night, I'll tackle it again over the weekend.

Thanks
Reply
Old Apr 23, 2005 | 06:43 PM
  #4  
THEOLDMAN's Avatar
Former Moderator
 
Joined: Jul 2002
Posts: 7,449
Likes: 0
From: Between Hell/Ann Arbor
Default

That's what happened to my computer just before it fried itself. Some bugaboo came in as an auto .exe file and then it just started to overload itself to the point where you couldn't even get into the windows setup.
Reply
Old Apr 24, 2005 | 05:17 PM
  #5  
Saki GT's Avatar
Moderator
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jul 2004
Posts: 36,017
Likes: 226
From: Queen City, NC
Default

Why I love my Mac....

Go into Spybot S&D's prefs and have it run before Windows starts so It can kill off any self-replicating bugs you've picked up on the Net. See if that helps.
Reply
Old Apr 24, 2005 | 07:09 PM
  #6  
Mindcore's Avatar
Thread Starter
Former Moderator
25 Year Member
Former Moderator
 
Joined: Oct 2000
Posts: 16,175
Likes: 0
From: Erock is da shizzle
Default

heh, tried that too, I finally gave up and wiped it.. I've never seen anything like it before.. these people should be strung up
Reply
Old Apr 25, 2005 | 02:01 PM
  #7  
Saki GT's Avatar
Moderator
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jul 2004
Posts: 36,017
Likes: 226
From: Queen City, NC
Default

these people should be strung up
Are you talking about the people who wrote Windows or the people who broke it completely?
Reply
Old Apr 25, 2005 | 02:24 PM
  #8  
Mindcore's Avatar
Thread Starter
Former Moderator
25 Year Member
Former Moderator
 
Joined: Oct 2000
Posts: 16,175
Likes: 0
From: Erock is da shizzle
Default

They're all on my list!
Reply
Old Apr 25, 2005 | 03:16 PM
  #9  
S2KANDRE's Avatar
Registered User
 
Joined: Jun 2004
Posts: 4,088
Likes: 0
From: Los Angeles
Default

Reply
Old Apr 25, 2005 | 05:12 PM
  #10  
flitcroft's Avatar
Registered User
20 Year Member
 
Joined: Sep 2003
Posts: 3,802
Likes: 0
From: Los Angeles
Default

I'll bet you got Shopping Assistant. A client of mine got it and I tried for 7 hours and ended up wiping the hard drive as well. I couldn't get the machine to run one of the steps on its compressed disk and the virus (188 copies in c:\windows) just kept coming back, even in safe mode. Tens of thousands of people have gotten it now.

Removal instructions. They take about two hours per pass:
http://www.short-media.com/forum/sho...d.php?p=172774
Reply



All times are GMT -8. The time now is 12:36 PM.