Spyware & Browser Hijack removal & links
![]() ![]() ![]() ![]() |
Spyware & Browser Hijack removal & links
|
|
Oct 1 2003, 10:45 PM
Show posts by this member only |
Post
#1
|
|
Water Cooled Group: VIP Posts: 5,045 Joined: January 2003 From: Kuala Lumpur |
Source: http://www.neowin.net/articles.php?action=more&id=81
Guide to Removing Spyware This article is more of a preventive measure than a fix and will harden internet explorers security but at the same time retaining the functionality that IE has. First in tools, internet options, advanced uncheck "Enable Install On Demand (Internet Explorer)" and "Enable Install On Demand (Other)" and "Enable Third-Party Browser Extensions (Requires Restart)" and choose apply and ok. Also ensure your internet security setting is at least medium (unless you know what you are doing and have made it custom). Goto http://www.windowsupdate.com and make sure you have all the latest updates. Then download Suns Java JRE from http://java.com/en/index.jsp (the link you want to hit is the "get it now" in the top right). Running Suns Java protects you because it has less exploited vulnerabilities than microsofts Java. Lots of spyware use holes in Microsofts java to install thier spyware so switching to Sun's closes a lot of holes. >> Download: Sun Java Then download Spybot Search and Destroy from http://www.safer-networking.org/ run it and make sure to let it download the newest updates. Now goto Spybots immunize function and under "permanent internet explorer immunity" choose immunize, then under "permanently running bad download blocker for internet explorer" select "ask for blocking confermation and choose install. >> Download: Spybot S&D Next, download spyware blaster from http://www.javacoolsoftware.com/spywareblaster.html run it and ensure it's fully updated. Now choose "select all" and then hit "Protect Against Checked Items". Just for reference all the items that are in red are items that Spybots immunize doesn't protect you against that's why you should use both programs. >> Download: Spyware Blaster Both Spybot search and destroy's immunize function and spyware blaster are one time set things, these programs no longer have to be running to keep you from getting infected with the stuff they block against. What they do is disallow any activeX program that's was known to them at the time you immunized from even running. With both Spybot and Spyware Blaster it is important that you check for updates every two weeks or so and re-immunize yourself when new updates are released to stay current. Spybot's other immunize function ("permanently running bad download blocker for internet explorer") installs a BHO that will ask you for permission to block other known bad BHO's from installing. BHO's are really not needed and fairly rare and most people only have the adobe acrobat BHO. You could have set this option to always block but I chose "ask for blocking confirmation" for those people that use something that I do not that uses a BHO. Now download both DSOstop2 and HTAstop2003 from http://www.nsclean.com/freebies.html and run both of those. >> Download: DSOstop2. HTAstop2003 In addition there's another great free utility that you can run but unlike everything above it has to always be open just like an antivirus called spywareguard from javacool. You can download it and run it as well to further increase your security against spyware if you choose. It's available here: http://www.wilderssecurity.net/spywareguard.html >> Download: Spyware Guard That should beef things up considerably. Having a good antivirus is also helpful because many of them are starting to add spyware to thier definitions, for instance my McAfee 8 caught that spyware trying to install. I hope this helps you guys because these settings are pretty solid but at the same time loose enough that you can still have active scripting enabled and activeX. Granted you could disable those as well but at that point you might as well go download an old version of Mosiac browser because it isn't worth using IE with everything disabled. |
|
|
Oct 1 2003, 10:46 PM
Show posts by this member only |
Post
#2
|
|
::: Cheers to this someone I do not know ::: Group: VIP Posts: 1,930 Joined: January 2003 From: A place where good food is available 24/7 |
Ad-Aware Personal: freeware adware removal tool
Trojan Defense Suite >> discontinued Pest Patrol Free Online Spyware Scanner and Cleaner Bazooka Adware and Spyware Scanner HijackThis A general homepage hijackers detector and remover. Initially based on the article Hijacked!, but expanded with almost a dozen other checks against hijacker tricks. It is continually updated to detect and remove new hijacks. It does not target specific programs/URLs, just the methods used by hijackers to force you onto their sites. As a result, false positives are imminent and unless you are sure what you're doing, you should always consult with knowledgable folks (e.g. the forums) before deleting anything. Download: Hijackthis View: Homepage View: Tutorial CWShredder A small utility for removing CoolWebSearch (aka CoolWwwSearch, YouFindAll, White-Pages.ws and a dozen other names). Spybot S&D and Ad-aware tend to forget essential parts of the hijack, so until they update, you can use this to completely remove the hijack. This program is updated to remove the new variants once they come out. Download: http://www.trendmicro.com/ftp/products/onl.../cwshredder.exe This post has been edited by sUBs: Sep 1 2005, 12:04 PM |
|
|
Oct 2 2003, 03:19 AM
Show posts by this member only |
Post
#3
|
|
The intrepid coward Group: Forum Admin Posts: 3,744 Joined: January 2003 From: Sydney, Australia |
You should scan for spywares about once a week..also use the immunity function in spybot search & destroy, its useful.
Pop-ups can be caused by spyware, but more often then not it is just the websites you are surfing offering them. You can use opera and ditch the 3rd party software to disable nagging pop-ups, you have an option to only open requested pop-ups. Spyware normally consists of dialers, or just trackers that track your internet usage, and then offer your advertisements on their page tailored by checking your usage statistics. I doubt you'll need a resident scanner, spyware doesn't pop-up that often now does it? and spyware blaster doesn't and can't be resident because it merely makes your pc "immune" to certain types of spyware. Remember to always update the software definitions though... |
|
|
Jul 1 2004, 03:54 AM
Show posts by this member only |
Post
#4
|
|
Regular ![]() ![]() ![]() Group: Junior Member Posts: 365 Joined: January 2003 From: anywhere in the world |
Browser Hijacking
Hijacking browser is a common problem for Internet Explorer users. The browser had certain bug that allow people to modified the registry so that it will direct to some other page. Hijacking browser is a serious matter.. But i learn a few tricks on how to fight no hijacking in no time at all. Note: Hijacking browser only happen 99% in most cases for IE users. How do you fall prey to a browser hijacking? There are numerous ways. Here are some common ones: 1. By installing software which changes your browser settings. This may happen with commercial software, but is much more common with freeware or adware. 2. By visiting a site which exploits a browser bug to change settings without your permission. 3. By visiting a site which persuades you to allow your settings to be changed, usually by offering freebies. When you accept the offer, your browser settings are changed or software installed. While such sites may tell you of their intentions, usually it's in the fine print or couched in deceptive terms And to the worst thing is spyware removal such as Spybot S&D won`t help much in repairing your hijack browser.. Reclaming hijack browser These instructions involve editing the registry and other advanced techniques. Do not attempt these procedures without making proper backups (read Backing Up and Restoring the Windows Registry to learn how) and don't attempt them at all if you're not familiar with registry editing. 1. If you've been hijacked, you can reclaim your browser with a bit of work. If your Control Panel's Internet Options have been disabled, get them back by locating the file control.ini (use Start -> Find/Search to locate it). Open control.ini in Notepad and look for the lines: [don't load] inetcpl.cpl=yes Delete the second of these two lines, close and save the file and reboot your computer. ![]() 2. Close any open Internet Explorer windows. a. Click Start -> Run, type regedit and click OK to open the Registry Editor. b. Navigate to: HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer If you find sub-folders called restricted or control panel, delete them. Check for the same sub-folders in:HKEY_LOCAL_MACHINE\ Software\Policies\Microsoft\Internet Explorer and delete them, too, if they exist. Then close Regedit. 3. If your search pages have been redirected, re-establish the defaults: a. Open the Registry Editor and navigate to: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main Change the Search Page value to: http://home.microsoft.com/access/allinone.asp and, if it exists, change the Search Bar value to: http://search.msn.com/spbasic.htm b. Navigate to: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL and change the default value to: http://home.microsoft.com/access/autosearch.asp?p=%s c. Navigate to: HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search Change the SearchAssistant value to: http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm and change the CustomizeSearch value to: http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm 4. Reset your home page to your chosen page: a. In Internet Explorer, choose Internet Options from the Tools Menu and, on the General tab, type in your preferred home page. b. Do a search for any files with the extension HTA. If you find any such files, open each in turn in Notepad and see whether they contain a reference to the site which has hijacked your browser. Delete any HTA files which contain such a reference. c. Locate the file HOSTS (it has no file extension) and open it in Notepad. Once again, look for any reference to the hijacking site. If you find any references, delete the lines containing those references. 5. a. Click Start -> Run -> msconfig and check the programs under the Startup tab. If you find an entry which contains regedit.exe /s disable it, and disable other programs you know to be suspicious. b. Still in msconfig, click the System.Ini tab and click the + beside [boot] to expand the section. Look for a line reading shell=explorer.exe. The line should read exactly that; delete any following commands, but make sure you leave shell=explorer.exe intact. Note: If you're using Windows NT, 2000 or XP, this information is contained in the registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell which should contain the value explorer.exe. c. Click OK to exit from msconfig and reboot your system. This post has been edited by acedriver: Jul 1 2004, 12:12 PM |
|
|
Sep 2 2004, 12:42 PM
Show posts by this member only |
Post
#5
|
|
Kelab Tag Merah Group: Staff Posts: 12,136 Joined: January 2003 From: Siberia |
|
|
|
Sep 4 2004, 05:54 AM
Show posts by this member only |
Post
#6
|
|
The alternate person ![]() ![]() ![]() ![]() ![]() ![]() Group: Senior Member Posts: 1,521 Joined: January 2003 From: Toilet Helping Staff |
OK guys... There are alot of pop ups when you access certain says which says:-
Your Computer is not safe from Adwares or Spyware! Click here to download Warning - if your computer has been running slower than usual, it maybe infected with adware or spyware. Dun believe these links there are must probably adware or spyware itself. Just Ignore these popup and just close it. One example is the attached picture This post has been edited by benlye: Oct 4 2004, 09:26 AM Attached thumbnail(s) |
|
|
Sep 11 2004, 09:17 AM
Show posts by this member only |
Post
#7
|
|
The alternate person ![]() ![]() ![]() ![]() ![]() ![]() Group: Senior Member Posts: 1,521 Joined: January 2003 From: Toilet Helping Staff |
Ever wonder why everytime you clean your PC using SpyBot and you always get infected by DSO Exploit?
This is because there is a hole in Internet Explorer. This vurneribility involves with editing windows registry to alter values contained within Internet Explorer's Internet Zones configurations. And microsoft is not doing anything about it. Attach here is an application to help protect your computer from these attacks. For more infomation please visit DSO Stop by Ns Clean How it looks like ![]() CLICK THE LINK BELOW TO DOWNLOAD http://www.nsclean.com/dsostop2.exe This post has been edited by benlye: Sep 25 2004, 12:52 PM |
|
|
Sep 27 2004, 01:43 AM
Show posts by this member only |
Post
#8
|
|
Regular ![]() ![]() Group: Junior Member Posts: 108 Joined: January 2003 From: Colorado |
when all else fails you can install a trial of
Process Guard it will then intercept each and every process that tries to start (generally its installed on a known clean box and you just approve all these processes) you can then allow, allow once, disallow or disallow once each process this is enough to interrupt the most serious infection of not only spyware but truely serious malware infections of course you need a clean or at least functional box to research which process is which and then manually root them out (from the GUI, Safemode and sometime the commandline of the recovery console) a list of potential startup processes > http://www.aros.net/~zaphod/startups.htm#A Pest Patrol Research Library > http://www.pestpatrol.com/pestinfo/ googling individual processes is generally perferable however Default Processes in W2K How to manually unregister dlls (from Pest Patrol) UnRegister DLLs You can use the Regsvr32 tool (Regsvr32.exe) to register and unregister object linking and embedding (OLE) controls such as dynamic-link library (DLL) or ActiveX Controls (OCX) files that are self-registerable. RegSvr32.exe has the following command-line options: Regsvr32 [/u] [/n] [/i[:cmdline]] dllname /u - Unregister server<BR/> /i - Call DllInstall passing it an optional [cmdline]; when used with /u calls dll uninstall /n - do not call DllRegisterServer; this option must be used with /i When you use Regsvr32.exe, it attempts to load the component and call its DLLSelfRegister function. If this attempt is successful, Regsvr32.exe displays a dialog indicating success. If the attempt is unsuccessful, Regsvr32.exe returns an error message, which may include a Win32 error code. Example: To unregister Winshow's winshow.dll: 1. Click the Start button, and select Run 2. Enter this command line: regsvr32 /u [systemroot]\winshow.dll For example, in a Windows XP machine in which your systemroot was at c:\winnt, you would enter: regsvr32 /u c:\winnt\winshow.dll ---------------------------------------------------------------------------------------------- from the commandline you can also generally use %systemroot% Good Luck, if a reinstall is the alternative, be not afraid, and ruthlessly cull registry entries the worse you can do is bork the registry but its Ideal for you to have multiple backups of your registry from a known good state, dig out the current infection and then replace %systemroot%\WINNT\system32\config with your backup This post has been edited by Ice Czar: Sep 27 2004, 01:55 AM |
|
|
Apr 12 2005, 08:33 PM
Show posts by this member only |
Post
#9
|
|
Old Am I? Group: Moderator Posts: 4,347 Joined: January 2005 |
QUOTE(seecs @ Mar 30 2005, 11:21 PM) I need help here...my pc is infected by CnsMin and I can't delete/rename the cnshook.dll and cnsmin.dll file in windows\downloaded program files\. I had try to clean it but it restore itself in the registry key even before i reboot. I follow the removal instruction from www.spywareguide.com also fail to clean the CnsMin. Dirty bugger that CNS.DLL.. I'm one of the several people have always advocate the use of alternative browsers, but many stubborn people around anyway.. so let it be! In the Command Prompt line, type the following commands: CD \WINDOWS\DOWNLO~1 ATTRIB *.* -H -S DIR/P This displays all hidden files in your "Downloaded Program Files" folder. You CANNOT see them under Explorer! You will see files CnsMin.dll, CnsHook.dll, keepMain.dll and keepmain.cab in there. Those are stubborn files to kill. These cannot be deleted under Safe Mode either because they make use of RUNDLL32 service which locks them from deletion (even in Safe Mode with Command Prompt only!). You have to boot from your WinXP CD to delete these files (use the "Repair" function). This post has been edited by lex: Apr 12 2005, 09:20 PM |
|
|
Apr 23 2005, 01:54 PM
|
|
Kelab Tag Merah Group: Staff Posts: 12,136 Joined: January 2003 From: Siberia |
QUOTE FYI Virus Spread by sending to MSN Messenger contacts. Message shows up as: /13/2005 8:03:45 PM Someguy its you! 4/13/2005 8:03:45 PM Someguy XXXXXX.malignancy.us/gallery/pictures.php?email=myemail@email.com Where: XXXXXX = Http://www, but you DON'T WANT TO FOLLOW THAT LINK CAUSE THAT'S HOW IT SPREADS... and Someguy = the name of the person sending you the link and myemail@email.com = your MSN-linked Email address If you click on the link, it asks to run a file. If you select RUN it installs itself. It instantly starts sending that same message to each of your contacts. Trying to infect them... http://castlecops.com/postt116415.html |
|
|
Apr 23 2005, 11:17 PM
|
|
Old Am I? Group: Moderator Posts: 4,347 Joined: January 2005 |
QUOTE(Darkmage12 @ Apr 23 2005, 11:07 PM) ei bout that wengs adware if its so stuborn how u remove it? How else... please read my previous post... like this one: QUOTE(lex @ Apr 23 2005, 10:55 PM) Boot from WinXP install CD, and in the recovery console... delete that file. FYI |
|
|
Apr 30 2005, 11:03 PM
|
|
Old Am I? Group: Moderator Posts: 4,347 Joined: January 2005 |
Anyway, I would like to inform all that a NEW VARIANT of this CNS spyware has been found locally! This one is a BIG cause of CONCERN because....
It is TOTALLY INVISIBLE to all anti-spyware, trojan detectors, rootkitrevealer and HijackThis detection!! It does NOT show up as an NT process, totally hidden... Must be using more advanced rootkit techniques. It does not show any signs of infection either (startups look normal).. everything looks normal. It does not install into folders that I expect CNS would install.. I did noticed CNS.EXE under Windows system folder. The tip balloon appeared saying it belongs to "Microsoft", checking its properties also says owner "Microsoft" but what was suspicious is that all TRUE Microsoft files shows "Microsoft Corporation", and not "Microsoft"! It cannot be deleted (even under Safe Mode!). Using WinXP CD boot-up didn't clean it either (it came back! Just beware! These malware stuff are getting more sophisticated all the time.. |
|
|
May 2 2005, 02:42 PM
|
|
Retired - DoNotDisturb Group: Moderator Posts: 3,837 Joined: January 2005 |
|
|
|
Jun 6 2005, 03:29 PM
|
|
Old Am I? Group: Moderator Posts: 4,347 Joined: January 2005 |
Adware lop.com is pretty old but also pretty nasty as it causes random Explorer crashes. Quite difficult (and tricky) to kill, also resides in the desktop whenver the system starts (even in Safe Mode!).
|
|
|
Jun 22 2005, 02:32 PM
|
|
Retired - DoNotDisturb Group: Moderator Posts: 3,837 Joined: January 2005 |
QUOTE(jimmylim85 @ Jun 22 2005, 07:51 AM) Im struck with 2 diffrent POP up Ads... very hard to removed as it can self regenerated even after removal. one of the ads came from www.chauxn.com.cn and the other from www.myip.com Please guide me how to remove it. Here's what you can do.... AdAware SE v1.06 Download, install, update, configure and run a scan with Ad-aware SE v1.06:
~~~~~~~~~~~~~~~ Download, Install & Run Spybot S&D. Click on the "Search for Updates" button. Install any updates that are available. Go to the Mode menu and choose "Advanced Mode". Next click on Immunize to your left. Click the Immunize button (green cross) on top to Immunize your computer - you should do this each time there is an update. Now click on the 'Spybot-S&D' option on the top left to go back to the main screen. Next click on the 'Check for Problems' button. Let it run the scan. If it finds something, Select all those in RED and hit the 'Fix Selected Problems' button. Exit Spybot. If you keep getting the DSO Exploit entries, even after you updated Windows and fixed them, then download the Spybot DSO Exploit Fix and install it over the current Spybot installation. ~~~~~~~~~~~~~~~ After running the above programs, download HiJackThis - this program will help us determine if there are any spyware/malware on your computer. Create a folder at C:\HJT and move HiJackThis.exe there. Double click on the program to run it. 1. If it gives you an intro screen, just choose 'Do a system scan and save a logfile'. 2. If you don't get the intro screen, just hit "Scan" and then click on "Save log". 3. Post the HiJackThis.log file in a new thread. Click here >> http://forum.lowyat.net/index.php?act=Post&CODE=00&f=25 . Do not fix anything in HiJackThis since they may be harmless. |
|
|
Jul 12 2005, 01:16 PM
|
|
Retired - DoNotDisturb Group: Moderator Posts: 3,837 Joined: January 2005 |
QUOTE(benlye @ Jul 12 2005, 10:37 AM) Here is something intresting. A site which has information on all known spyware and adware.. --------------------- http://www.spywareinfo.com/ ![]() SpywareInfo is a member of ASAP ASAP stands for the Alliance of Security Analysis Professionals. ASAP started out as a small band of security sites under seige, and is rapidly expanding to include the "Best of the Best" the Internet Security Community has to offer. ASAP is made up of website and forum owners and administrators, forum and site staff, individuals, companies and various organizations dedicated to providing security related support to computer end users. ASAP is a joint effort designed to assist helping end users with as seamless a process as possible by using methods such as cross-referrals, multiple product support services, easy information access, and cross referencing/verification. ASAP's goals are: To ensure a high standard and quality of security support no matter where you seek help. To promote the products used to keep your computer clean and safe in an equal and fair manner. To ensure that end users are not affected by so called "product wars" and unfair marketing tactics which have plagued several industries in recent years. ASAP ensures that quality support and assistance will be freely available - knock one of the support networks out and another will pick it up immediately. In addition, pooled resources permit the ability to provide support redundancy, thereby adding an additional layer of protection against Internet based threats. If you see the ASAP logo or banner used by a site, bulletin board, or person, you can be assured that you're getting the best support and assistance possible, as the combined efforts of all ASAP members are involved in helping everyone, and ASAP won't give up until your important investment is safe and clean. ASAP is a non-profit volunteer network. Member Sites of ASAP AmazingTechs Anti Spyware Offensief Assiste.com Atribune.org BestTechie BleepingComputer Bluetack Internet Security Solutions Calendar of Updates CARMA Common Sense Security CPASecurity CyberAnswers.org Freedomlist Geeks to Go Gladiator Security hpHosts InfoSpyware Infotex JSKYs XP Support Linha Defensiva Lockergnome MalwareBytes MalWare Removal ManageYourPC MickeyTheMan NeoPlanet NetworkTechSupport PCdistress PCHelper PC Pitstop PCtorium Pipex Support RescueME Short-Media.com SpywareAid SpyWare BeWare! Spywarefri SpywareInfo Spyware Warrior Subratam.org Tankweb Tech Support Forum Tech Support Guy TeMerc Internet Countermeasures That Computer Guy The Spykiller TomCoyote UBCD4Win Vital Security.org |
|
|
Jul 21 2005, 11:43 AM
|
|
Retired - DoNotDisturb Group: Moderator Posts: 3,837 Joined: January 2005 |
@servonet.
If you want something to be done about your malware problems, you have to furnish us with a HiJackThis log. If unsure how to do it, here are some instructions... Download HiJackThis - this program will help us determine if there are any spyware/malware on your computer. Create a folder at C:\HJT and move HiJackThis.exe there. Double click on the program to run it. 1. If it gives you an intro screen, just choose [Do a system scan and save a logfile]. 2. If you don't get the intro screen, just hit [Scan] and then click on [Save log]. 3. Post the HiJackThis.log file here. Do not fix anything in HiJackThis since most of the entries may be harmless When you have a log, start a new thread by clicking here I shall help you when I see your new thread. sUBs |
|
|
Jul 21 2005, 10:08 PM
|
|
Retired - DoNotDisturb Group: Moderator Posts: 3,837 Joined: January 2005 |
QUOTE(gestapo @ Jul 21 2005, 03:49 PM) a noob question. when i installed warez does it means than i allow them to enable pop up on my pc??..bcoz i notice that my yahoo pop up blocker is gone. and the windows antispyware alway giving warning about warez trying to install sum stuff..help pls I have a simple way for you to find out on your own. Download Trend Micro(tm) Anti-Spyware for the Web Utility (by clicking the "Scan and Clean your PC" button).
If you wish, you may share the details with other LYF members by pasting the entire contents of that log here. |
|
|
Jul 24 2005, 08:49 AM
|
|
Retired - DoNotDisturb Group: Moderator Posts: 3,837 Joined: January 2005 |
QUOTE(Jayken @ Jul 24 2005, 08:35 AM) I'm sorry if i post something wrong here. But i really need some help on this problem What actually happens? Getting Spyware? Download & Run Shoot the Messenger. Disable Messenger service & that should be the end of your woes |
|
|
Jul 24 2005, 08:57 AM
|
|
Newbie ![]() Group: Junior Member Posts: 31 Joined: July 2005 From: Malaysia |
QUOTE(sUBs @ Jul 24 2005, 08:49 AM) hmm. can i ask more? what possible reason i may cause that messenger popup? windows problem? or? |
![]() ![]() ![]() ![]() |