Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Wanet Telecoms Ltd on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

IE ha been hijacked by c:\\windows\ 3

Status
Not open for further replies.

wackydj

IS-IT--Management
Dec 17, 2003
37
GB
IE ha been hijacked by c:\\windows\hp.html. despte running spybot and spykiller, changing reg defaults the browser defaults to hp.html on each new reboot. advice please.
 
wackydj,

Hard to tell what the hijack is from that little info. Please download the Hijack This! tool:

Open it and SCAN your machine. Don't go removing things yet. Copy and paste the scan results log (in its entirety) back here. We'll go from there.
 
google gave a pointer to thread83-717884, unlike this case, spybot fixed that one.
 
Thank's for your help. I have discovered that the problem was caused by CWS Hijacker, a trojan with lots of possible variants. A fully successful remove was achieved by downloading and running CW Shredder. Thanks to Merijin and Mike Healan (see SpywareInfo)
 
I am told that having MS Java on my PC makes it vulnerable to this sort of attack, should I revove it? advice please.
 
I wouldn't. You're going to find yourself coming up short on many sites if you remove java. I'd advise keeping up your spyware/malware defenses. Keep your AV up to date and utilize SpyBot's Immunize function. You should also look into how to "load" your HOSTS file as another line of defense:
 
wackydj
Glad you're ok again,
thanks for posting back and letting us know how the problem got fixed-that's helpful for future reference.

carrr
Thanks for comment about immunize, I've been getting that setup on my machines at home since I saw you mention it in a previous post.
 
diogenes10,
[thumbsup2] ....just one more toy for the arsenal...
 
you can replace msjava with SunMicroSystems version

I've disabled/prompt ActiveX, but have scripting still enabled to a degree....
I've removed every iota of macromedia shockwave..if you don't have you;re settings just right in the Advanced IE tab and Security Tab...you'll constantly get prompted for d/l from many sites

for java view this


TT4U

Notification:
These are just "my" thoughts....and should be carefully measured against other opinions.
Backup All Important Data/Docs..All involved shall be spared the grief.
 
Thank's everyone for your help. I will leve Java on and have taken your advice and set uo SpyBot's immunize as sugested. All remains well.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top