Home General Discussion

Browser Hi-jacking

pogonip
polycounter lvl 18
Offline / Send Message
pogonip polycounter lvl 18
My browser is being hi-jacked and redirected when ever I do a search and sometimes when I click a link . I have tried all I know for finding the ad-ware-trojan-spyware-malware but I can't seem to find what is doing it . I use Internet explorer because Firefox has several issues I don't like at least on my computer . What I would like to know is if anyone else has had this problem and what they did about it ?

I have used
Microsoft Anti-spyware beta
Ewido ( which found a bunch of spyware but not the problem causer )
Bazooka
Adaware...
nothing seems to be able to find anything and I have a program called winpatrol that monitors any changes to my computers settings and it also has not popped up anything . If you know of a program that is not mentioned and works well let me know ..or maybe another way to track it down ? I'll use Firefox until I figure out what is wrong .

Replies

  • Scott Ruggels
    Options
    Offline / Send Message
    Scott Ruggels polycounter lvl 18
    Use Spybot Search and Sestroy, and Microsoft Anti-spyware Beta those help.

    Scott
  • malcolm
    Options
    Offline / Send Message
    malcolm polycount sponsor
    What page is it redirecting you to? When I get this shit after looking at too much porn it's usually a particular site that's hijacking the web browser then I just google for the removal tool. The problem is probably in your registry that where I usually find all the hijacked web page junk is.
  • aesir
    Options
    Offline / Send Message
    aesir polycounter lvl 18
    spybot search a destroy is a definite must.

    norton might be nice too if you can get your hands on it
  • pogonip
    Options
    Offline / Send Message
    pogonip polycounter lvl 18
    Thanks scott i'll try Spybot but as of now Microsoft anti-spyware is finding nothing . Ewido found stuff Microsoft ASW did'nt find FYI it's a very good progam I just found while trying to get this fixed .

    Malcolm it varies depending on search query . I forgot to mention that while I was surfing around "certain" pages I went to a page and IE flipped out and my Winpatrol let me know several changes were being made and zonealarm let me know several programs were trying to acess the internet . I went through and found those and thought I removed everything but turns out I was wrong something is still here . All of the prgrams scanned the registry but did not come up with anything ? frown.gif
  • KDR_11k
    Options
    Offline / Send Message
    KDR_11k polycounter lvl 18
    Played a Sony-made music CD on that PC lately?
  • JonMurphy
    Options
    Offline / Send Message
    JonMurphy polycounter lvl 18
    http://mywebpages.comcast.net/SupportCD/SecureXP.html

    Had a good guide and links to tools which helped a lot when trying to get rid of a browser hi-jack on the in-laws machine.

    Wasn't porn that aused that infection though. Free knitting patterns. Damn those scamps!
  • sal_manilla
    Options
    Offline / Send Message
    sal_manilla polycounter lvl 18
    Mine got hijacked too but Spybot S&D didn't find it. I got Spyware Terminator and it got rid of the hijacker and found some stuff Spybot missed. :/
  • Rick Stirling
    Options
    Offline / Send Message
    Rick Stirling polycounter lvl 18
    Try CoolWebShredder

    http://www.snapfiles.com/get/coolwebshredder.html

    It's for removing a nasty redirection browser infection.

    And STOP using IE. What don't you like about Firefox?
  • hawken
    Options
    Offline / Send Message
    hawken polycounter lvl 19
    stop using IE... it's like leaving the front door of you house open on a busy highstreet during the january sales
  • KDR_11k
    Options
    Offline / Send Message
    KDR_11k polycounter lvl 18
    If you absolutely don't want to use Firefox use Opera or something.

    Also, careful with downloading random anti-spyware tools from the net, many infect your system with malware.
  • Dukester
  • Downsizer
    Options
    Offline / Send Message
    Downsizer polycounter lvl 18
  • pogonip
    Options
    Offline / Send Message
    pogonip polycounter lvl 18
    Used Spybot and it found a bunch more spyware ...jesus I cant believe I had so much spyware I thought I was careful . It still did'nt fix the redirect-hi-jackiing though so im gonna try the other solutions you all recommended thanks smile.gif . I don't use Firefox because well , Flash simply won't work , Quicktime movies won't work . It downloads stuff and sometimes the downloads disappear , sometimes websites look funny or have errors . My friends don't have this problem so im thinking it's my cheap walmart computer . I don't like using IE either . Thanks again for the help smile.gif
  • bearkub
    Options
    Offline / Send Message
    bearkub polycounter lvl 18
    you need to check out that CWS that Rick posted. I think it was CoolWebSearch that was pretty devious to hiding itself from Spyware/Adware removal tools. If it wasn't that, it was one of them and it required a special tool or add-on to AdAware that would detect and remove it.

    Good luck getting rid of it, man. That stuff is nasty.
  • Rick Stirling
    Options
    Offline / Send Message
    Rick Stirling polycounter lvl 18
    [ QUOTE ]
    I don't use Firefox because well , Flash simply won't work , Quicktime movies won't work . It downloads stuff and sometimes the downloads disappear

    [/ QUOTE ]

    I've had this - it was Windows, my PC was knacked. A reinstall and Firefox worked like a dream.
  • Ruz
    Options
    Online / Send Message
    Ruz polycount lvl 666
    when you start up your browser, and it redirects, check out which if any programs start up. i did this and found an exe which was repsonsible for the problem. none of the spyware worked, tried all of the above.
    worst thing was , when I deleted the exe , it came straight back .

    took me days to sort it out and it left IE crippled anyway. I am now using firefox.

    check u this link,http://www.pcstats.com/articleview.cfm?articleid=1579&page=6
    It might help, but just google browser hijack and aside fro all the anti spyware stuff, you will find good advice how to fix it manually
  • Dravalen
    Options
    Offline / Send Message
    Dravalen polycounter lvl 18
    Have you cheched the Host file? Sounds like that might be the problem since the spyware stuff isn't finding it.

    [edit]
    Check C:\Windows\System32\drivers\etc folder for a "hosts" file, if you see anything other than 127.0.0.1 that's your problem.
  • ElysiumGX
    Options
    Offline / Send Message
    ElysiumGX polycounter lvl 18
    [ QUOTE ]
    I don't use Firefox because well , Flash simply won't work , Quicktime movies won't work.

    [/ QUOTE ]

    Yeah, that's normally a user error. Flash and Quicktime work perfect for me after some tweaking. It's windows media files I have problems with.

    I install AVG, Spybot, Sygate, and Winpatrol, and use a good updated HOST file, then uninstall IE (even tho it doesn't completely) before I connect my PC to the internet after a new build or reformat. I keep a close watch on programs I find running after I close them, or don't recognize, and keep my startup programs minimal. Then I lock the doors, batten down the hatches, and hide the children.

    I haven't had a virus or spyware in a long time.

    I mostly use Firefox by habit now, but I also switch to Opera sometimes, and it's awesome.
  • JonMurphy
    Options
    Offline / Send Message
    JonMurphy polycounter lvl 18
    /aside - I had the same problem with flash on Firefox 1.5, it was caused by the AdBlock extension in my case.

    http://www.sysinternals.com/Utilities/Autoruns.html

    Autoruns utility lets you look at what is loading with windows, and has an integrated google searcg so you can query which processes should be there, and which shouldn't.

    And don't be affraid of safe mode wink.gif
  • Striff
    Options
    Offline / Send Message
    Striff polycounter lvl 18
    I second Hijack this. The programs works every time, but you can severly screw up your computer if you don't know what your doing.

    Best thing to do is run it and copy+paste the report it gives on a forum where people know what they are doing. They should be able to tell you what you need to delete.

    That stinks you can't get Flash and QT to work with Mozilla. I'm sure others have had problems like you, just do a search and I'm sure youll be able to figure it out. <3 Mozilla.
  • Dukester
    Options
    Offline / Send Message
    Dukester polycounter lvl 18
    Striff is absolutely correct.
    The link I posted above is for one of those forums that walks you through hijack-this.
    I've had a lot of success using security-forums cleaning up screwed up computers here at work. But yeah hijack-this can screw you up if you don't know what to look for.
  • pogonip
    Options
    Offline / Send Message
    pogonip polycounter lvl 18
    Thanks for the advice guys ! However nothing seems to be working so im gonna try and get some more expert advice at other forums . Nasty little bug whatever it is ..
  • KDR_11k
    Options
    Offline / Send Message
    KDR_11k polycounter lvl 18
    If Hijack This doesn't find it all that's left is a rootkit. Did you use any Sony music CDs on that computer?

    Anyway, check with Rootkit Revealer, if neither that nor Hijack This finds anything then your OS is beyond all hope.
  • pogonip
    Options
    Offline / Send Message
    pogonip polycounter lvl 18
    It isn't a rootkit . I did'nt play a sony CD . It was maleware/trojan of some type I know the exact time it started because winpatrol instantly told me changes were being made to my start up and my browser settings were being changed . Ewido removed most of the components at the time . Im gonna try some stuff recd in another techy forum and i'll let you guys know because maybe it might help at some point .
  • KDR_11k
    Options
    Offline / Send Message
    KDR_11k polycounter lvl 18
    I meant perhaps there's a rootkit hiding part of the problem.
Sign In or Register to comment.