(#1)
|
|
Registered User
![]() Posts: 2
Join Date: Dec 2003
Location: Canada
Age: 21
Reputation Power: 0
|
I've recently contracted a spyware on my winxp computer. It hijacked my IE home page and set the home page to something like http://fadfg.outhost.info
it didn't work when i tried to restore my browser settings. I googled the URL and found that it didn't exist, so i suspect the page was cached on my computer. I have no idea how it got into my computer, because i have zone alarm, norton antivirus 2004, and i run ad-aware scans every so often. I made 10 complete scans with up-to-date ad-aware and found no problem. my browser was still hijacked. What shocked me was the detail the programmer went into, to prevent me from removing the spyware. Firstly, it simply closes my browser if i visit any sites containing words such as "spyware", "spybot" etc. It closes my Opera browser too. I had to use my other operating system on the computer just to come into this forum. Secondly, since i couldn't visit the spybot homepage i went on download.com to try and download it. My fast clicking skills actually let me download the file before the browser closed, however when the file reachs 100% and starts to transfer from the temp folder to the designated folder, windows gives me an error saying the file is not found. I tried using the open file option when downloading and it doesn't opens. Frustrated, i used my other computer to download hijackthis and try to unhijack the browser. i saved hijackthis on a floppy and put it into the infected computer. the spyware prevented me from seeing the file in windows explorer. So i went to start->run A:\hijackthis.exe, and it closed the .exe the second it opened. Then i went into safe mode, and actually got hijackthis to work, but it didn't fix anything, my browser was still hijacked when i restarted in normal mode. I went and downloaded spy sweeper and scanned my system twice, it found nothing. I then went into a different OS, win2k, and downloaded spybot and installed it on win2k and scanned my system, found no problem. I had to rename the spybot setup file in order to see it in XP. I switched back to XP, ran the setup file, as usual it closed. I tried it in safe mode, i actually got it to install but after install finishes i cannot find spybot anywhere. Not on the desktop, not in the start menu, not in program files and not even in the registry. I tried using malwhere, in normal mode, it detected a process called zlclient.exe or dll i don't remember. It was the only suspicious process on the list. I could not end it, it gave me an access denied message. In safemode, the zlclient process didn't exist but i still couldn't get spybot to work. Looks like who ever made this spyware took every measure to prevent me from using spybot. I gave up after spending my entire day trying to get rid of it. I am still looking for a solution to my problem, i would be grateful if anyone would give me suggestions or advice on removing this dreaded spyware. I am absolutely shocked and disgusted that someone would spend so much time on the details to make my life miserable. |
|
(#2)
|
(#3)
|
(#4)
|
(#5)
|
(#6)
|
|
Jay Leno Geek
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 4,236
Join Date: Nov 2002
Location: Lacrosse, Wi.
Age: 23
Reputation Power: 306
|
May 5th, 2004, 11:18 PM
I'm pretty sure I heard of a virus that did something like this. I know you've scanned with spyware programs, but have you done a simple antivirus scan with the latest detections?
Also, when in windows, bring up the task manager (ctrl + alt + del), and tell us EVERY singe process running. Close any you know you don't need also, you may have better luck after the program is killed. |
|
(#7)
|
(#8)
|
|
Vote John Kerry!
![]() Posts: 661
Join Date: Oct 2002
Reputation Power: 121
|
May 6th, 2004, 02:58 AM
I don't think dabbling in the registry will work because as soon as you reboot it will reset the homepage. Don't you think whoever designed the hijack program would have thought about that?
http://cexx.org/adware.htm Scroll about half way down this page and it will give you a list of known homepage hijackers around at the moment and what to do with them. |
|
|
|
(#9)
|
(#10)
|
(#11)
|
|
_
![]() Posts: 125
Join Date: Mar 2004
Reputation Power: 76
|
May 6th, 2004, 07:30 AM
Ironically, http://fadfg.outhost.info/ has link labeled "Spyware Removal" at the bottom of the page, under the copyright.
|
|
|
|
(#12)
|
(#13)
|
(#14)
|
(#15)
|
![]() |
| Bookmarks |
«
Previous Thread
|
Next Thread
»
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| File-Sharing Is, Like, Totally Uncool | Miniver | General Discussion | 22 | August 20th, 2004 02:27 PM |














Linear Mode
