OT: cleaning a browser hijacker?

M

Mike

Over the past two days, whenever I go on to the Internet my computer tries
to connect to the following sites:

www.teenpicseries.com/
www.superclicker.com/
www.seventhteen.com/cgi-bin/s2/
teens-lovers.com/
prices.goldnewsweekly.com/_images/
www.livegoldprices.com/
rape.hotporncollection.com/
pics4all.net/
www.freeadultgalleries.com/paysite/

The browser doesn't open -- these attempts happen in the background. The
only reason I know it's happening is because We-Blocker (a free web filter
program) says "Blocked" every few minutes.

I'm running ZoneAlarm 3.1.395, but it clearly isn't blocking whatever it is
that's getting in.

I've run AVG and Ad-Aware several times (fully updated) in the last 24
hours. AVG says the system is clean. Ad-Aware sometimes picks up a Data
Miner in the registry (Software\Microsoft\Internet Explorer\Main);
but after it's removed, the problem persists the next time I connect. (I've
just run it again, and it says the computer is clean.)

Is this a trojan at work? Or is it possibly the A.Sasser worm? A
recommendation for a freebie fix would be helpful. Thanks!
 
B

bloned

Mike said:
Over the past two days, whenever I go on to the Internet my computer tries
to connect to the following sites:

www.teenpicseries.com/
www.superclicker.com/
www.seventhteen.com/cgi-bin/s2/
teens-lovers.com/
prices.goldnewsweekly.com/_images/
www.livegoldprices.com/
rape.hotporncollection.com/
pics4all.net/
www.freeadultgalleries.com/paysite/

The browser doesn't open -- these attempts happen in the background. The
only reason I know it's happening is because We-Blocker (a free web filter
program) says "Blocked" every few minutes.

I'm running ZoneAlarm 3.1.395, but it clearly isn't blocking whatever it is
that's getting in.

I've run AVG and Ad-Aware several times (fully updated) in the last 24
hours. AVG says the system is clean. Ad-Aware sometimes picks up a Data
Miner in the registry (Software\Microsoft\Internet Explorer\Main);
but after it's removed, the problem persists the next time I connect. (I've
just run it again, and it says the computer is clean.)

Is this a trojan at work? Or is it possibly the A.Sasser worm? A
recommendation for a freebie fix would be helpful. Thanks!

Hi Mike, you might want to check out this page:

http://209.133.47.200/~merijn/downloads.html

CWShredder and Hijackthis are 2 excellente free programs for problems
like yours. Be sure to check out
http://209.133.47.200/~merijn/htlogtutorial.html for some help with
the use of Hijackthis

HIH
 
B

bassbag

mcbloem@ said:
Over the past two days, whenever I go on to the Internet my computer tries
to connect to the following sites:

www.teenpicseries.com/
www.superclicker.com/
www.seventhteen.com/cgi-bin/s2/
teens-lovers.com/
prices.goldnewsweekly.com/_images/
www.livegoldprices.com/
rape.hotporncollection.com/
pics4all.net/
www.freeadultgalleries.com/paysite/

The browser doesn't open -- these attempts happen in the background. The
only reason I know it's happening is because We-Blocker (a free web filter
program) says "Blocked" every few minutes.

I'm running ZoneAlarm 3.1.395, but it clearly isn't blocking whatever it is
that's getting in.

I've run AVG and Ad-Aware several times (fully updated) in the last 24
hours. AVG says the system is clean. Ad-Aware sometimes picks up a Data
Miner in the registry (Software\Microsoft\Internet Explorer\Main);
but after it's removed, the problem persists the next time I connect. (I've
just run it again, and it says the computer is clean.)

Is this a trojan at work? Or is it possibly the A.Sasser worm? A
recommendation for a freebie fix would be helpful. Thanks!
AS well as advice for spybot hijack this etc , i would check your add/remove
programmes for any ad/spyware that may have inadvertently been installed .
me
 
B

Bob Adkins

Over the past two days, whenever I go on to the Internet my computer tries
to connect to the following sites:

Look up BHODemon. It can quickly and simply switch off Browser Helper
Objects that are usually responsible for such hijackers. Be sure to leave
your Adobe Acrobat Reader and Spybot S&D BHO's turned on.

Bob

Remove "kins" to reply by e-mail.
 
M

Mike

Look up BHODemon. It can quickly and simply switch off Browser Helper
Objects that are usually responsible for such hijackers. Be sure to leave
your Adobe Acrobat Reader and Spybot S&D BHO's turned on.

Bob

Thanks, folks!
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top