Default Browser web page Hijack

G

Guest

Could anyone give me any advice on how I can retsore my browser default web
page, it keeps getting take over by the following:

Recommended Anti-Spyware Software: Spy Trooper, Malware Wipe, Spy Guard
Online Security

Attention! Your system is under control of remote computer with IP address
227.4.167.118. The remote computer has access to the following folders on
your PC:
- \WINDOWS\System32
- \Program Files\Internet Explorer
- \My Documents
- Drive C:\ files
Click here to download official anti-spyware software

The site tries to redirect you to http://www.needupdate.com/

Does anyone know how I can get rid of this problem.

I have run Microsoft spyware.
I have also run Nortons anti virus.
I have tried various ways of resetting the bowser default setting.
 
G

Guest

Follow Pluns Advise in the post above, SmitRem will remove the smitfraud
trojan files if they exist, reset your IE Homepage then clear temp files and
Ewido to check for any more junk that may exist. Smitrem will reset your
desktop wallpaper after it has finished as some variants add a spyware
warning that cannot be removed, To reload your wallpaper right click desktop
and choose properties then use the desktop tab,

All The Best

Andy
 
P

plun

Hi Andy

A little more about this to get more knowledge.

I cannot see the reason to run smitrem.exe as first step ?

Ccleaner removes the junk, then Ewido removes the trojan and carrier,
often more then one. Smitrem.exe then cleans the smitfraud infection in
safe mode, mostly a lot of registry removals.

But maybe it´s necessary to first clean out Smitfraud ???

Strange that MS hasn´t include any removals for Smitfraud anyway ?!
I cannot see it as complicated.

Merry Christmas
--
plun



AndyManchesta wrote :
 
G

Guest

Hi Plun

Hope your well, I agree the tools you recommended are exactly whats needed
for this infection, Smitrem is excellent for repairing the damage caused by
these trojans and resetting IE value's back to Microsoft's default, It also
removes temp and prefetch files as part of the fix then runs disk cleanup at
the end so it will take care of any junk in the temp folders. If its PSGuard
related then some scanners were having problems removing the ShudderLTD &
PSGuard registry keys but Smitrem also makes this look simple as it replaces
them with a dummy entry first then removes them as well as removing all the
rogue Antispy programs related to these trojans, checking the wininet.dll
file for infection, repairing the desktop restrictions and Task Manager if it
has been disabled.

As you say its strange Microsoft's scanner isnt capable of detecting and
repairing any damage caused by these Smitfraud variants especially as this
has been around for many months, It is a never ending battle trying to keep
up with this junk as they are forever releasing new files such as the latest
SpyAxe variants which SmitRem also removes but hopefully once Microsoft
finish the development of the Antispyware program they can put more time into
adding signatures and keeping up with the malware.

I experienced this last week by running the 'loadadv' files which are stored
on at least 5 different sites, The sites are based in Russia and use security
holes and exploit scripts to load various files on the pc without any
warning.

I had Microsoft Antispyware updated and enabled and watched all the junk
load onto the system without any being blocked then the desktop changed and I
had look2me, Spysheriff, various Password Stealers, Qoologic, cmdService,
Target Saver, CWS, Trojan Delf, Proxy variants & various Kill AV Trojans
installed which eventually shut down the protection and turned the machine
into a zombie sending out hundreds of spam mails every minute which were
hidden from view but obvious using a packet sniffer. Once Id rebooted and
re-enabled Microsoft Antispyware it then detected some of the files like
Target Saver, cmdService & Nameshifter but they were already installed then
and the antispy showed it removed them but there was still many files left
after the scan plus the spam mails being sent out and other infections like
Qoologic regenerated probably due to the scanner missing some of the infected
files,

I did receive a email from an MVP about getting more samples to Microsoft so
thats nice to hear they are trying to keep up with the junk which I
appreciate isnt a easy task, I have hundreds of files saved from testing so
thats not a problem and I also have links to all the exploit scripts and
files coming from these sites and all the affiliate sites the trojans contact
to download more junk so Im more than happy to pass the information on if
there is a way to do that.

For free its a great program to protect the system but Im hoping by the time
beta2 is released they have all the signatures updated and removal issues
fixed so then its will be alot easier for them to just add new signatures
when infections are released and be able to block all the junk before it can
get onto the system rather than letting it install then detecting parts of it
in the scan and the users having to find alternative tools to repair the
damage.

I'm confident it will be a excellent Antispyware solution by the time its
released so we just have to be patient and use these other tools as and when
required untill the beta is closer to completion.

Merry Christmas to you as well Plun and best wishes for the New Year

Andy
 
G

Guest

AndyManchesta/Plun/Engel,

Thanks for all your help.

I have loaded and ran all of the programs you all recommended successfully.

I can confirm that I have now taken contol of my web browser now and removed
more bugs etc than I new I had.

Let's hope that Microsoft upgrade their antispyware and up dates to save
others having to go through this process.

I hope you all have a happy and prosperous New Year.

Regards,
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top