Forum Moderators: open

Message Too Old, No Replies

Some kinda trojan

Help needed

         

Maxiim

12:21 pm on Jan 3, 2002 (gmt 0)



My Internet Explorer started acting strangely after a visit to some kind of adult site. Computer chnages the opening page for IE every time after restart and I find myself looking at p*rn again :)
Can anybody help?

chiyo

2:03 pm on Jan 3, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Go to options under Tools and replace the home page that the other website probably changed for you without your knowledge! I think they use javascript to do this. Adu*t (ie childish) sites are the main offenders, though it is not beyond other spammers as well.

Maxiim

2:50 pm on Jan 3, 2002 (gmt 0)



Thanx for replying Chiyo, but you didn't exactly understand my problem: I DID replace the home page, but it keeps reappearing after ever boot or shutdown. Is it a trojan? Which file did it affect or which lines should I change to get rid of it?

click watcher

3:00 pm on Jan 3, 2002 (gmt 0)



have you looked in your startup folder to see if there is a new .exe file there which will execute each time you reboot??

Maxiim

3:16 pm on Jan 3, 2002 (gmt 0)



Yes, Click Watcher, I did look it up. There's nothing that shouldn't be there... What else? System registry files? Systray? ...?

msgraph

3:24 pm on Jan 3, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Click Start --> Run

Type msconfig and click OK and click on the Startup Tab

Scroll down and check for something out of the ordinary. Like something that would run a command on your browser.

[added]Opps posted really late[/added]

Maxiim

4:57 pm on Jan 3, 2002 (gmt 0)



Nope, this ain't gonna do nothing, I run Windows 2000... :) So, what else could be wrong?

bobriggs

5:11 pm on Jan 3, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



If you want to look in your registry, try here:

Run regedit (Start, Run, regedit, enter)

Click these plus signs:
HKEY_LOCAL_MACHINE
SOFTWARE
Microsoft
Windows
Current Version

Then click on the word RUN

Anything funny there?

You can also check in
HKEY_CURRENT_USER
Software
Microsoft
Windows
Current Version

See what is in RUN. Especially look for some .VBS

Also, anything running in the task manager (Alt-Ctrl-Delete)?

Just some guesses.
Disable Active scripting in internet options (security)?

Brett_Tabke

5:53 pm on Jan 3, 2002 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



So that it doesn't happen again, read:
[microsoft.com...]

Tapolyai

6:32 pm on Jan 3, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



You could just search your whole machine for the URL or portion of the URL. Both in files and in your registry.

Maxiim

6:53 am on Jan 4, 2002 (gmt 0)



Hey Bobbrigs! Thanks. I did it your way and found a peculiar key named OPQFile in HCU/Software/Microsoft/windows/Run. It seems to be running some kind of .tmp file. What is it and is it supposed to be there?

Maxiim

7:19 am on Jan 4, 2002 (gmt 0)



Hey everybody! Thanks a lot, especially Bobriggs, 'cos I found it. There was a bad .tmp file on the HCU/.../Windows/CurrentVersion/Run registry. I first removed it without deleting and then rebooted. And IE worked properly again! Then I deleted the file permanently and also the registry key. And everything is functioning again. So, thank you all for helping!

Sincerely yours, Maxiim.

meannate

10:57 pm on Jan 11, 2002 (gmt 0)

10+ Year Member



I smell trouble... I'm wondering if there are any legal implications involved... Changing a user's computer without implicit consent is a major deal. I'm not saying "Lawyer" neccesarily... just I would threaten these bastards. I have nothing against p0rno sites, but one should be able to visit them (or any site) indescriminatly and not be forced to view them every time you get to want to use your damn browser. what a joke...

Marcia

11:09 pm on Jan 11, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



meannate, it's probably a legal issue because of the age factor. What if a child of 11 uses that same computer? There is supposed to be a statement to sign that a person is 18 before getting to content, if I'm not mistaken.

A lot of "legit" changes to systems happen, like programs setting themselves as default automatically when installing. And those can also be annoying, though not like this.

idiotgirl

11:15 pm on Jan 11, 2002 (gmt 0)

10+ Year Member Top Contributors Of The Month



Same thing happened to my folks. They typed in a domain that had expired and was purchased by an adult site. Couldn't get rid of the home page or the ads for anything, even though they backpeddled in a hurry. I think my dad did something with Norton to finally kill it. It was like that for a couple of months. They were traumatized!