Computer Hijack

Computer Hijack

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Computer Hijack Buster 06-28-2006
Posted by =?Utf-8?B?QnVzdGVy?= on June 28, 2006, 3:41 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Somehow I have managed to get hijacked. When I open up IE it now goes to the
following:
http://www.syssecuritysite.com/
Even if I change it to my normal default page it keeps coming back.
Also, I have a virus alert in my system box flashing and when I click on it
it says there is virus activity and it directs me to another virus software
detection site.
I run XP SP2 and I have run defender and spybot with no luck.
Can anyone hlep me please.
Thanks in advance
Buster

Posted by B. Nice on June 28, 2006, 4:10 am
If you were  Registered and logged in, you could reply and use other advanced thread options
On Wed, 28 Jun 2006 00:41:01 -0700, Buster

>Somehow I have managed to get hijacked. When I open up IE it now goes to the
>following:
>http://www.syssecuritysite.com/
>Even if I change it to my normal default page it keeps coming back.
>Also, I have a virus alert in my system box flashing and when I click on it
>it says there is virus activity and it directs me to another virus software
>detection site.
>I run XP SP2 and I have run defender and spybot with no luck.
>Can anyone hlep me please.
>Thanks in advance
>Buster

Have You tried HiJackThis ?

Let us know if You have done that already or if You don't have any
experience using it.

Posted by =?Utf-8?B?QnVzdGVy?= on June 28, 2006, 9:29 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks for the quick response and I'll try hijackthis tomorrow although I
have never used it before.
Cheers

"B. Nice" wrote:

> On Wed, 28 Jun 2006 00:41:01 -0700, Buster
>
> >Somehow I have managed to get hijacked. When I open up IE it now goes to the
> >following:
> >http://www.syssecuritysite.com/
> >Even if I change it to my normal default page it keeps coming back.
> >Also, I have a virus alert in my system box flashing and when I click on it
> >it says there is virus activity and it directs me to another virus software
> >detection site.
> >I run XP SP2 and I have run defender and spybot with no luck.
> >Can anyone hlep me please.
> >Thanks in advance
> >Buster
>
> Have You tried HiJackThis ?
>
> Let us know if You have done that already or if You don't have any
> experience using it.
>

Posted by Malke on June 28, 2006, 8:53 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Buster wrote:

> Somehow I have managed to get hijacked. When I open up IE it now goes
> to the following:
> http://xxx.syssecuritysite.xxx/
> Even if I change it to my normal default page it keeps coming back.
> Also, I have a virus alert in my system box flashing and when I click
> on it it says there is virus activity and it directs me to another
> virus software detection site.
> I run XP SP2 and I have run defender and spybot with no luck.
> Can anyone hlep me please.
> Thanks in advance
> Buster

Do not post unmunged urls of malicious websites.

Go through these general malware removal steps systematically -
http://www.elephantboycomputers.com/page2.html#Removing_Malware

Make sure you do the preparatory work. You may need to run HijackThis
and post your log to one of the specialty forums listed at the above
link (not here, please).

If the procedures look too complex - and there is no shame in admitting
this isn't your cup of tea - take the machine to a professional
computer repair shop (not your local version of BigStoreUSA).

Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User

Posted by David H. Lipman on June 28, 2006, 5:22 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Somehow I have managed to get hijacked. When I open up IE it now goes to the
| following:
| http://www.syssecuritysite.com/
| Even if I change it to my normal default page it keeps coming back.
| Also, I have a virus alert in my system box flashing and when I click on it
| it says there is virus activity and it directs me to another virus software
| detection site.
| I run XP SP2 and I have run defender and spybot with no luck.
| Can anyone hlep me please.
| Thanks in advance
| Buster



Two part reply..

Perform Part 1 then perform Part 2.

If the first two parts don't work, perform the alternate section.

It is suggested that you execute each tool in Normal Mode then in Safe Mode.

If you are using any version of Sun Java that is prior to JRE Version 5.0,
then you are strongly urged to remove any/all versions that are prior to JRE/JSE
Version 5.0. There are vulnerabilities in them and they are actively being
exploited.
This is most likely why you got infected with malware.

Therefore, it is highly suggested that if there are any prior versions of Sun
Java
to Version 5 on the PC that they be removed and Sun Java JRE/JSE Version 5.0
Update 7
be installed ASAP.

Simple check, look under...
C:\Program Files\Java

The only folder under that folder should be the latest version...

C:\Program Files\Java\jre1.5.0_07


http://www.java.com/en/download/manual.jsp



Part 1
-----------

Use noahdfear's SmitFraud, SpyAxe, SpyFalcon, et. al., removal tool --
SmitRem.exe
http://noahdfear.geekstogo.com/click%20counter/click.php?id=1

http://www.bleepingcomputer.com/forums/topic43659.html


Part 2
-----------

Download SmitFraud.exe from the URL --
http://www.ik-cs.com/programs/virtools/SmitFraud.exe

Execute; SmitFraud.exe { Note: You must accept the default of C:\McAfee }
Choose; Unzip
Choose; Close

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
FireWall to enable WGET.EXE to download the needed McAfee related files.

Execute; c:\mcafee\clean.bat
{ or Double-click on 'Clean Link' in c:\mcafee }

A final report in HTML format called C:\mcafee\Normal_ScanReport.HTML or
C:\mcafee\Safe_ScanReport.HTML will be generated. At the end of the scan, it
will be
displayed in your browser (Opera, FireFox or Internet Explorer). However, if
you are using
WinXP, Win2K or Win2003 your system will be left in a state where you will have
to manually
shutdown/reboot the PC. On Win9x/ME platforms the report will not be shown in
your bowser
but your PC will automatically be shutdown. It is suggested that you move the
report out of
c:\mcafee before performing another scan.

It would be best to scan in both Safe Mode and in Normal Mode and save a copy of
the HTML
report for each session.


ALTERNATE:

Part 1
-----------

Secured2K's SpyAxe, PSGuard, Smitfraud, Sinnaka and Alemod removal tool.

http://secured2k.home.comcast.net/tools/AntiPuper.exe

http://forums.mcafeehelp.com/viewtopic.php?t=65072


Part 2
-----------

S!ri's SmitfraudFix
http://siri.urz.free.fr/Fix/SmitfraudFix_En.php


Please Copy and Paste the contents of the HTML Log files;
C:\mcafee\Normal_ScanReport.HTML & C:\mcafee\Safe_ScanReport.HTML in your reply.

* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Similar ThreadsPosted
posting log of Hijack This December 31, 2005, 6:19 pm
Browser Hijack? February 21, 2007, 9:10 am
Download.Trojan (aka Desktop HiJack) April 25, 2006, 11:13 pm
Google Gmail E-mail Hijack September 26, 2007, 3:37 pm
Browser hijack attempt resulting in lost favorites (= no bookmarks) October 11, 2005, 8:51 pm
Computer Hacker is illegally creating a new logon on my computer November 10, 2007, 9:32 pm
User Permissions Differ from Computer to Computer October 24, 2005, 7:16 pm
Computer to Computer NtLmSsp authentication errors ? October 6, 2006, 5:25 pm
Did someone take over my computer? November 24, 2006, 1:23 pm
policy for one computer July 26, 2005, 10:35 am

The site map in XML format XML site map

Contact Us | Privacy Policy