General discussion

Locked

How to tackle hijacked browser

By lmayeda ·
One of my managers left his PC unattended over the weekend and later discovered that his browser had been hijacked. Here's what I've done so far, I downloaded the latest updates for ADAWARE and ran it (3 times). I rebooted the PC into safe mode and ran ADAWARE. I searched the C: drive for any .exe files created during the weekend date and deleted those. I went into the HKLM, current version, Run and deleted all .exe's that I did not recognize. I also went into the Internet Explorer, Main and deleted the entries that was being defaulted. I went into the HKCU and deleted what I could find of the hijacking pgms, I deleted all undesired websites from the Favorite folders of all profiles (porn sites keep reappearing). Where else should I go to ferret out the hijacking programs? I would hate to have to re-format the drive. Will the approach be different depending on what software is doing the hijacking? Thanks in advance.

This conversation is currently closed to new comments.

8 total posts (Page 1 of 1)  
| Thread display: Collapse - | Expand +

All Comments

Collapse -

by lmayeda In reply to How to tackle hijacked br ...

Since I could tell that I still had not rid the PC of the offending hijacking program, I also downloaded Spybot and ran it but I still see recurrences of the hijacking site. Oh, and I also ran Task Manager to end the processes of executables that I definitely did not recognize... though I admit that I did not look up every process. This hijacking program (MYPOISK, IEENG.exe, WINLGN.exe) acts like the IST browser hijacker.

Collapse -

by LMon In reply to How to tackle hijacked br ...

Try spybot search and destroy. update it then run. If that doesn't work try highjackthis. I would run an anti-virus program make sure you update it.

Collapse -

by lmayeda In reply to

Thanks for your help.

Collapse -

by dmiles In reply to How to tackle hijacked br ...

Turn off system restore if it is used in your os.

Download, update, and run the following.

Your Antivirus Software

Spybot:
http://tinyurl.com/ziar

Ad-Aware:
http://tinyurl.com/tek5

CWshredder:
http://tinyurl.com/2bzef
Or
http://tinyurl.com/2k642
Look for the file in English CWShredder.exe

Hijack This:
http://mjc1.com/mirror/hjt/

Hijack This is useful in that it shows what is currently loading on startup. You must know what is good and what is bad. Once you check it and fix it is gone. So be sure.

Run Your Antivirus again

I have had to boot into safe mode and run these.

Collapse -

by lmayeda In reply to

I guess I will have to learn how to use HIJACK THIS

Collapse -

by pierrejamme In reply to How to tackle hijacked br ...

In addtion to dmiles comments, all good check out specifics on www.google.com. For example I found:
http://computercops.biz/print-1-40502.html
By doing a search on "MYPOISK". It is a very detailed article on this culprit. Then do the same for each villan you find.
Pest Patrol is also a very good program, I believe they have a web scanner, and trialware in addition to their excellent program.

Collapse -

by lmayeda In reply to

Thanks ... I use www.Ask.com ... may try google to see if their hits are more precise

Collapse -

by lmayeda In reply to How to tackle hijacked br ...

This question was closed by the author

Back to Windows Forum
8 total posts (Page 1 of 1)  

Related Discussions

Related Forums