Forum Moderators: phranque

Message Too Old, No Replies

browser hijacking

I can't track down the program, thus I can't kill it.

         

D_Blackwell

10:14 pm on Sep 18, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



My browser is getting randomly (but frequently) hijacked and I'm being redirected to:

[xml.overture.com...]

My first guesss is that I let it in when I downloaded an icon creator program to test, although I can't say for certain. I try to run a pretty tight ship here. There is now (randomly) text in my address bar that was not there before. Something about 'entering address here'. (It's not there right now, but it will be back soon I know.

I've removed the program and re-run Norton, Adaware and Spybot to no avail. Im still being randomly hijacked, and always to Overture. How do I find it so that I may kill it?

Ally_Cat

10:20 pm on Sep 18, 2003 (gmt 0)

10+ Year Member



Did it change your default home page in IE? Check your options.

Have you downloaded the latest updates for AdAware and SpyBot? (AdAware I know you have to tell it to update - not sure about SpyBot)

henry0

10:28 pm on Sep 18, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



the only tool you will need is HijackThis as spelled
I also maintain a PC/security tech forum
where we support it

I use it
It saved me many times

regards

Henry

D_Blackwell

12:36 am on Sep 19, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



henry0,

My subscription pays for itself again! I downloaded and ran HighjackThis and am POSITIVE that one of the log entries is the evil I'm after. There are a few others that make me suspicious. I've posted the complete log on what I hope is the correct forum because I'm afraid to do anything without knowledgeable advice. It looks as though mistakes could be catastrophic.

I had done what little I knew to do. Looks like this could work out for me and hope to add it to the arsenal.

henry0

12:54 am on Sep 19, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



beware the application is powerful
I send you a link
to post the log
if you are not comfortalbe with the results
wait to read moderator suggestions about the log
please do not delete anything before unless you are very much knowledgeable about any registry entries and key