HELP - BROWSER HIJ ACK!

  • Thread starter Thread starter Nelson
  • Start date Start date
N

Nelson

I have been hijaked by a trojan called:

res://pgcrj.dll/index.html#96676 It has taken over my
browser and will not let me have it back. is there free
ware out there that can remove this thing?
 
I have a client with same problem! I have tried AdAware,
Norton AV 2004, Spybot S&D, CWShredder, HiJackThis,
Noadware...none of them have fixed it!

Once you delete it, it will come back as soon as you
launch IE.

We are tinkering with the Registry now...

Another Hijacked computer has had the WINDOWS UPDATE
option removed from the IE Toolbar...looking for a fix for
that one too!!!
 
I was HIJACKED! I got the problem fixed (I am back to a
real homepage) but my WINDOWS UPDATE option has been
removed from TOOLS and replaced by a link to a shopping
site.

Where do I find/fix the file responsible for my IE toolbar?
 
First, Read Here:

Sandi Hardmeiers Site (an MVP who knows her stuff)
http://inetexplorer.mvps.org/Darnit.htm
Homepage Hijackings
http://inetexplorer.mvps.org/answers.htm#home_page
Search Engine Hijackings
http://inetexplorer.mvps.org/answers4.htm#search_engine

Sandi's site is chock full of info. She "invites" baddies into her machines
just to test, and see how to fix it. A truly wonderful person who is
extremely knowledgeable and generous. So give her site a good reading (it'll
take *days* to read it all; possibly weeks if you do other things with your
life.) and keep it for future reference.

Another excellent site from Mike Burgess MVP
A Troubleshooting Guide to Windows XP (and things which also apply to Win9.x
systems)
http://www.mvps.org/winhelp2002/
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Now, you can try to install SpywareGuard (freeware). SpywareGuard is a
program by Javacool (also the Author of SpywareBlaster) which is designed to
notify you of changes to Homepage, search bar, new BHO's, and things of that
nature. So you might download it -presently at version 2.2- and then
afterwards, change your homepage in Control Panel> IE Options to your
desired homepage. Then when SpywareGuard notifies of a change in Homepage to
whatever from whatever you can have it deal with whether you want to permit
that change. I'm just thinking this may be a way to defeat it from returning
once you've changed it to your choice of homepage.

SpywareGuard
http://www.javacoolsoftware.com/spywareguard.html
SpywareGuard Tutorial
http://www.bleepingcomputer.com/forums/index.php?showtutorial=50

You can also install HijackThis. Warning: Hijack this requires help if you
don't know what you are doing. Hijack this is a very powerful, last resort
type of program which is generally best used in conjunction with help from
those who deal with the findings of the log created by the HijackThis scan.
It does nothing in the scan itself; it merely says what is in and running on
your PC. The items must be checked-marked to be "cleaned". Therein is the
issue; you must know *exactly* what you are checking-off before you proceed.
If you don't, you can quite possibly disable many useful and vital functions
of your PC. Remember; read the Tutorials, and seek help at SpywareInfo
Forums, Net-Integration, or TomCoyote forums for safety's sake.

HijackThis
http://www.spywareinfo.com/~merijn/downloads.html
If the preceding site is down, you may get HijackThis from Major Geeks
(amongst other sites as well)
Hijack This (from Major Geeks)
http://www.majorgeeks.com/download3155.html

HijackThis Tutorials **(MUST READ)**
http://www.spywareinfo.com/~merijn/htlogtutorial.html
http://www.bleepingcomputer.com/forums/index.php?showtutorial=42
http://hjt.wizardsofwebsites.com/

Where to seek help with your HijackThis scan log
SpywareInfo Forums
http://forums.spywareinfo.com/
other help forums for HijackThis:
Net-Integration
http://forums.net-integration.net/index.php?c=19
TomCoyote
http://forums.tomcoyote.com/index.php?showforum=27

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Another possibility is to change it in the Registry. That is located in
HKCU\Software\Microsoft\Internet Explorer\Main

I have two listed in mine: Start Page and Start Page _bak. I haven't any
Default listing. If you had one (a default start page), it would be in the
same Registry Key location. You could change it there by a Right-Click on
the appropriate Start Page and /or Default Page and/or bak
Page>Modify>Value Data> enter your *Full* preferred start page URL>OK out.

NOTE: You should first export that Key(s) before making any changes so you
can re-import and restore it if anything goes wrong. Changes in the Registry
are usually *instantaneous* and may cause your PC to be rendered inoperable
if you would make even the simplest mistake in the wrong place.

Description of the Microsoft Windows registry (XP Home Edition, XP
Professional, 2000, ME, 98se, 98, NT, 95)
Microsoft Knowledge Base Article - 256986 (**MUST READ if you are even
considering a Registry fix**)
http://support.microsoft.com/default.aspx?scid=kb;EN-US;256986

HOW TO: Backup, Edit, and Restore the Registry in Windows 95, Windows 98,
(98se), and Windows Me
Microsoft Knowledge Base Article - 322754 (**MUST READ - as above**)
http://support.microsoft.com/default.aspx?scid=kb;EN-US;322754

How to back up, edit, and restore the registry in Windows XP and Windows
Server 2003
Microsoft Knowledge Base Article - 322756 (**MUST READ - as above**)
http://support.microsoft.com/default.aspx?kbid=322756

How to Back Up the Registry in Windows 98, (98se), and Windows Millennium
Edition
Microsoft Knowledge Base Article - 256419
http://support.microsoft.com/defaul...port/kb/articles/Q256/4/19.ASP&NoWebContent=1

How to Manually Restore the Windows 98/Me Registry
Microsoft Knowledge Base Article - 221512
http://support.microsoft.com/defaul...port/kb/articles/Q221/5/12.ASP&NoWebContent=1

Again, *Note Well*, that improper and incorrect changes in the registry can
cause your PC to stop working and/or be rendered inoperable. If you are
unsure of what to do, don't even try. Get help from someone who can do this
for you. You have been warned.
 
Another thing about the Registry and the Start and Search Pages: They may
also be listed in
HKLM\Software\Microsoft\Internet\Explorer\Main. Look for any which may be
located there, such as Default_Page_URL; Default_Search_URL; Search Page;
and Start Page.
 
*Look here*:
http://forums.spywareinfo.com/index.php?showtopic=8847
<paste>
In the last few days ... This infection:
res://<random>.dll/<random>.html#<random> has spread like wildfire and we
are inundated with requests to help clear it. Sometimes the fixes that have
been created work, sometimes not - Unfortunately.

There has been some reported fixes by ensuring that you have a firewall
installed like Zonealarm and having it block the calls out to the Internet.
That, with a complete scan using the latest version of Ad-aware seems to
clear it up - Somewhat.

Ad-Aware should be file : v6.0 Build 6.181 and you should have reference
file: 01R324 22.06.2004 installed. Please update your copy of ad-aware and
boot into safe mode and run it, before posting a request for help. (How do I
boot into "Safe" mode?)

It appears that ad-aware is cleaning the files etc but not deleting the
registry entries associated with the clean so they may still show up in the
HijackThis log. If you still get the entries after booting into normal mode
and are not sure what to delete, post your log in the forum but mention what
version of ad-aware you run as well as the reference file version - This
will help in the resolution.

Also - If you request help, DO NOT reboot your computer until you receive a
response as the files change as soon as you reboot. If you receive no
response and you have rebooted - Post a new HijackThis log into your current
message - DO NOT start a new message again as we cannot keep up with all the
calls.
<paste/>

HTH -
 
I am with you on this one. I just got Spy Subtract and
you are right. it keeps coming back. The Firms name is
Internet Search Technologies. Shouls I track them down
and get the local DA's office on them. It iwll take time
though the BBB. I may be able to contact the FBI, but I
don't know if that will do much good. I am going to
bookmark this, but please email me your answer at
(e-mail address removed).

Thanks,
 
Back
Top