|
|
|
 |

July 5th, 2004, 06:34 PM
|
General
|
|
Join Date: Aug 2000
Location: Ohio, USA
Posts: 4,323
Thanks: 0
Thanked 0 Times in 0 Posts
|
|
Re: OT: about:blank homepage hijacker..
The stories about how persistant and ingenious these spyware/adware/hijackware programs can be are getting quite amazing. I've heard about how they install processes to watch themselves and re-install, or hide 'bombs' all over your system in hopes of causing re-infection. I'm glad I've always surfed in 'paranoid' mode with a browser filter/proxy between me and the net. Now with Mozilla instead of IE I'm a bit safer, but being Online is still getting scarier every day. I'm very much afraid that this chaos will provide an excuse for the government to step in and regulate everything, ruining our nice 'free' Internet.
[ July 05, 2004, 17:35: Message edited by: Baron Munchausen ]
|

July 5th, 2004, 06:46 PM
|
 |
Sergeant
|
|
Join Date: Dec 2003
Posts: 251
Thanks: 0
Thanked 0 Times in 0 Posts
|
|
Re: OT: about:blank homepage hijacker..
Quote:
Mozilla is proving to be a very nice browser, I doubt that I will ever return to IE.
|
Another convert! Chalk yet another up to the Gecko
You will be quite happy to know that the primary vector for spyware installation is closed when you use Mozilla. Mozilla will NOT install anything without your ok.
Now all you have to worry about are dubious "free" programs... and I think you should update your antivirus.
|

July 7th, 2004, 12:17 AM
|
 |
Lieutenant Colonel
|
|
Join Date: Mar 2001
Location: Emeryville, CA
Posts: 1,412
Thanks: 0
Thanked 0 Times in 0 Posts
|
|
Re: OT: about:blank homepage hijacker..
DEG, you probably already knew about this, but be sure to run the update feature on both AdAware and Spybot. The installers, IIRC, come with definitions that are over a year old.
__________________
GEEK CODE V.3.12: GCS/E d-- s: a-- C++ US+ P+ L++ E--- W+++ N+ !o? K- w-- !O M++ V? PS+ PE Y+ PGP t- 5++ X R !tv-- b+++ DI++ D+ G+ e+++ h !r*-- y?
SE4 CODE: A-- Se+++* GdY $?/++ Fr! C++* Css Sf Ai Au- M+ MpN S Ss- RV Pw- Fq-- Nd Rp+ G- Mm++ Bb@ Tcp- L+
|

July 7th, 2004, 12:24 AM
|
 |
Shrapnel Fanatic
|
|
Join Date: Dec 2000
Location: USA
Posts: 15,630
Thanks: 0
Thanked 30 Times in 18 Posts
|
|
Re: OT: about:blank homepage hijacker..
can someone post a link to mozilla?
__________________
Creator of the Star Trek Mod - AST Mod - 78 Ship Sets - Conquest Mod - Atrocities Star Wars Mod - Galaxy Reborn Mod - and Subterfuge Mod.
|

July 7th, 2004, 12:55 AM
|
Corporal
|
|
Join Date: Dec 2002
Posts: 137
Thanks: 0
Thanked 0 Times in 0 Posts
|
|
Re: OT: about:blank homepage hijacker..
__________________
As always, comments and suggestions are welcome.
Get my Runesword II tomes from my website
|

July 7th, 2004, 04:04 AM
|
 |
Lieutenant Colonel
|
|
Join Date: Dec 2000
Location: DC Burbs USA
Posts: 1,460
Thanks: 0
Thanked 1 Time in 1 Post
|
|
Re: OT: about:blank homepage hijacker..
Link to kill it:
http://www.securiteam.com/securityre...RP0L0UD5U.html
And as the others have said Mozilla or Firefox to prevent it. If you have to keep IE6, then Firefox is a little more IE friendly. If you work with SQL web apps or Frontpage, then you will want to keep IE around.
__________________
Think about it
|

July 7th, 2004, 12:57 PM
|
 |
General
|
|
Join Date: May 2002
Location: Canada
Posts: 3,227
Thanks: 7
Thanked 44 Times in 28 Posts
|
|
Re: OT: about:blank homepage hijacker..
Quote:
Originally posted by Thermodyne:
Link to kill it:
http://www.securiteam.com/securityre...RP0L0UD5U.html
And as the others have said Mozilla or Firefox to prevent it. If you have to keep IE6, then Firefox is a little more IE friendly. If you work with SQL web apps or Frontpage, then you will want to keep IE around.
|
Interesting link Thermodyne. Especially the note at the bottom of tyhe page, Aparently my suspicions were right, it is indeed an spyware/hijacker removal service that has been spreading this piece of malware. They should be sued into bankrupsy and given life prison terms fo their maliscious act.
btw: following this kind of procedure does not always work, and it did not work for me. I still had the problem after running through the procedure. But I found a workaround.. I viewed all the files in my ..\windows, \system and \system32 folders and sorted by date. I then deleted all suspicious files and made special notes of the ones that said 'unable to delete' and removed them in dos. When I rebooted the system complained but was nice enough to let me know what it was looking for. I searched the registry and removed any references to these files. it seems fine now.
BTW I wouldn't reccomend this type of drastic procedure unless you have a good knowledge of what is what in the windows folder. It would be easy to delete a 'needed' file and cause windows to die.
One good indication that it's a bad file is when it has a very obscure name, like snxyfc.dll or mxtargoo.dll etc.
Anyway, the problem seems to be solved, and now that my primary browser is Mozilla I should be safer.
Cheers!
P.S. Thermo, I'm approaching 100 folds for the sharky team. Man I hat getting these ***/400 folds, they take several days to complete.
[ July 07, 2004, 11:57: Message edited by: David E. Gervais ]
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is On
|
|
|
|
|