Quantcast
browser hi-jack help - Beyond.ca - Car Forums
Results 1 to 17 of 17

Thread: browser hi-jack help

  1. #1
    Join Date
    Apr 2005
    Location
    calgary
    Posts
    727
    Rep Power
    20

    Default browser hi-jack help

    I have some kind of hi-jack that when I try to go to google.ca it redirects to google.ca and redirects back to .com in a never ending loop.

    also cannot update my antivirus it has got that page not working, along with the update for adaware is blocked.

    and I wasn't downloading porn is the odd thing, I havent downloaded much at all on this laptop, I put a 2nd hardrive in the desktop for that to keep the laptop clean

  2. #2
    Join Date
    Jul 2005
    Location
    Calgary
    Posts
    2,201
    Rep Power
    21

    Default

    When there is a virus like that, usually you can't do much but to reformat unless you're willing to put many hours into the current setup to try and clean it all out.
    Originally posted by rage2
    #1: don't ever question me.

  3. #3
    Join Date
    Apr 2005
    Location
    calgary
    Posts
    727
    Rep Power
    20

    Default

    I have already put in about 6 hours in my regedit and have fixed all my issues except the browsing one, spybot search and destroy and adaware can't cut it.

    I will do a re-install if I need to, just means I have to back up all my kids pictures from halloween and christmas concert video and pics

  4. #4
    Join Date
    Nov 2007
    Location
    Cowgary
    My Ride
    AWOL
    Posts
    972
    Rep Power
    17

    Default

    Originally posted by 88jbody
    I will do a re-install if I need to, just means I have to back up all my kids pictures from halloween and christmas concert video and pics
    You mean you don't have backups of those already?

  5. #5
    Join Date
    Jul 2005
    Location
    Calgary
    Posts
    2,201
    Rep Power
    21

    Default

    Originally posted by 88jbody
    I have already put in about 6 hours in my regedit and have fixed all my issues except the browsing one, spybot search and destroy and adaware can't cut it.

    I will do a re-install if I need to, just means I have to back up all my kids pictures from halloween and christmas concert video and pics
    Ah I see, I would still always reformat my computer if I ever got a virus, but it is a real pain in the ass, you are right. I am not sure how to help you anymore sorry, but just as a reminder, be sure to scan and clean the files you backup. (I'm sure you knew that though.)
    Originally posted by rage2
    #1: don't ever question me.

  6. #6
    Join Date
    Jan 2006
    Location
    Calgary
    My Ride
    Axis powers
    Posts
    2,486
    Rep Power
    24

    Default

    or you can always pick up a U2 drive that has avast on it

    run the antivirus from the U2
    Sig nuked by mod.

  7. #7
    Join Date
    Jul 2004
    Location
    Calgary
    My Ride
    FB6
    Posts
    718
    Rep Power
    20

    Default

    Use safemode and try?

    Or use safemode with networking and do an online scan? All of the big antivirus websites have those.

  8. #8
    Join Date
    Jul 2004
    Location
    Calgary
    My Ride
    **SEQUOIA**
    Posts
    561
    Rep Power
    20

    Default

    ^

    What he said. Safemode is your best bet
    f8 during bootup (if you have XP)

    good luck

  9. #9
    Join Date
    Jul 2005
    Location
    Calgary
    My Ride
    Integra Type R
    Posts
    171
    Rep Power
    0

    Default

    safe mode w/ networking
    then do online scan with bitdefender.com or trendmicro
    wh...?

  10. #10
    Join Date
    Jul 2005
    Location
    Calgary
    My Ride
    Integra Type R
    Posts
    171
    Rep Power
    0

    Default

    i also forgot to mention to turn off system restore before scanning/removing...hijackers tend to keep coming back even after you "remove" them
    wh...?

  11. #11
    Join Date
    Jul 2004
    Location
    Calgary
    Posts
    58
    Rep Power
    0

    Default

    Sounds like you have TDSS.

    http://www.myantispyware.com/2008/11...rojan-tdsserv/
    http://www.troublefixers.com/remove-...l-for-windows/

    To fix it, I did this:
    Go to Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.

    Scroll down to “Non-plug and Play Drivers” and click the plus icon to open those drivers.

    Then search for “TDSSserv.sys”

    Right click on it, and select “Disable”

    Note: If you select Uninstall, it will install itself again when you reboot the system, so DON’T select Uninstall.

    Restart your pc.

    You can now update your Antirus/Malware/Rootkit softwares and the go.google rubbish will stop.
    Then I installed MalwareBytes and removed the trojan.

    I suspect the instructions at either of the above links would work fine as well (basically say the same thing).

    edit: the fun thing about this trojan is that it runs in Safe Mode with Networking, and it prevents any online scanning because it redirects urls.

  12. #12
    Join Date
    Aug 2004
    Location
    Beyond
    Posts
    2,010
    Rep Power
    24

    Default

    Has this been solved yet?
    Was the #1 Forum Warrior

  13. #13
    Join Date
    Apr 2005
    Location
    calgary
    Posts
    727
    Rep Power
    20

    Default

    no. I have my computer working well enough untill I get a memory stick or something to back up my files.

    I have run av and adaware and spy bot in safe mode.
    I will try a few more of these tips. I just need to get a xp pro cd my laptop never came with one when I got it used

    TDSSserv was not in the device manager

    but found a vgasave in there I disabled from the sound of it I suspect it may be the cause of some of my pop-ups

    but oh well I'll re-install windows

  14. #14
    Join Date
    Apr 2005
    Location
    calgary
    Posts
    727
    Rep Power
    20

    Default

    up date. disabling that avgsave got rid of my browser hijack and all my pop-ups!!!!!

    I should be able to get by now untill I get a external storage of some kind to copy all my crap onto

    my avg still isn't updating but I can now at least google and fix that

  15. #15
    Join Date
    Mar 2003
    Location
    Left Coast
    My Ride
    Audi
    Posts
    1,348
    Rep Power
    24

    Default

    I just went thru the same thing - I wish I saw gaijin's instructions - would've been easier!

    here's what i ended up doing:

    I downloaded Malware bytes and installed it from this link:

    http://www.download.com/Malwarebytes...dlPid=10984636

    Before I ran the install, I renamed the setup file to setup.exe

    During the install, I renamed the folder it installed to to MBM
    During the install, I renamed the program group name to MBM
    Do not start the program when completed

    Go to the folder you installed it at, rename the program name (mbam.exe) to mbm.exe (or whatever else you want).

    I wasn't able to run the update as the damn Trojan prevented that.

    Run the scan (without updates) and remove all. Close Malwarebytes, do not reboot. Go back to the folder, rename the file back to mbam.exe.

    Reboot, you should now be able to update. After the update, run the scan again. Reboot, you should be in the clear now.

  16. #16
    Join Date
    Apr 2005
    Location
    calgary
    Posts
    727
    Rep Power
    20

    Default

    I guess it didn't fix the pop- ups but oh well it needs a fresh install anyway

  17. #17
    Join Date
    Jul 2008
    Location
    Calgary, Alberta
    Posts
    98
    Rep Power
    0

    Default

    The VgaSave device is actually a legitimate device used in Safe Mode or VGA mode. It's recommended you enable it again, in case you need to load Safe Mode.

    Unfortunately the Spyware/Adware industry plays a constant game of cat and mouse. If detection definitions for that particular malware hasn't been released, it can be very difficult to manually track it down and remove it.

    With difficult to remove adware it's often faster to just backup the data and reformat. If you deal with sensitive information, such as bank records, or business documents it's a necessity. Even if your scanner "removes" the malware there's no way to be sure you've completely eliminated it, even if the popups stop. Once your system has been compromised to allow the malware to run on the machine, there's no telling what code could have been implanted.

    If you're not that concerned about the security of your data there are still a few tricks you use to track down the offending adware program. The first step is to run HijackThis. This will take a quick inventory of all known load points for malicious software. If you post this log we might be able to identify how the adware is loading.

    If that finds nothing the next step is to run RootkitRevealer. A lot of malware is able to hide from virus scanners and spyware scanners by patching core system files. This will hopefully detect that.

    The final step is to run Process Monitor. Close all browser windows, start the monitor and wait for the adware to load a popup. Once a browser window pops up, stop Process Monitor and go through the log. Right before the popup opened you should see registry requests looking for the default URL handler. The offending process will lookup "HKEY_Current_User\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http". Record the process name and PID. This will at least tell you through which program the adware is operating. Most times the adware is loaded as a DLL in this process, and is not the process itself. Using another tool called Process Explorer, you can view all DLLs and objects loaded by the process. You should then check these files for anything out of the ordinary, such as random names, no file description, product name, or copyright information.

    Some malware programs run several copies of itself called "watcher processes," and can change it's names every few minutes or every time it's started. Usually this makes it easy to detect exactly what DLL or process is malware, but it can complicate the removal. In this case it's necessary to locate the load point of the malware and remove it using an offline registry editing tool (such as Offline NT Password & Registry Editor).

    Even after exhausting this list of options, there are many malware programs which remain undetectable. Even if you successfully removed the process, the malware may have added several "back door" like security vulnerabilities allowing itself to reinfect your computer with ease. A common example of this is malware that adds its certificates to your trusted certificate stores.

Similar Threads

  1. browser-x help

    By Intent_Fire in forum General
    Replies: 0
    Latest Threads: 05-01-2007, 09:46 PM
  2. Jack / Jack Stand Points on 2002 Accord

    By koopkoop2 in forum General Car/Bike Talk
    Replies: 4
    Latest Threads: 11-13-2006, 11:41 AM
  3. FS : 2ton Jack and pair of 2ton jack stands

    By vincent-h in forum Automotive Parts
    Replies: 0
    Latest Threads: 08-29-2005, 12:42 PM
  4. Quick help with browser refreshing on a website

    By Ekliptix in forum Computers, Consoles, and other Electronics
    Replies: 4
    Latest Threads: 08-26-2005, 08:52 AM
  5. MY Ps2 Memory Card Won't Show Up On Browser Screen, I NEED SOME HELP!

    By 2jzgte in forum Computers, Consoles, and other Electronics
    Replies: 4
    Latest Threads: 12-12-2004, 02:56 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •