Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Stop making mediocre tutorials.The best tutorials are video! Camtasia Studio makes it easy to create engaging, buzz-building screen videos at any size, in any popular format. Download the free trial!
  #1  
Old June 2nd, 2003, 05:23 AM
jdk's Avatar
jdk jdk is offline
phpkid ~~~~~~ :o)
Dev Shed Frequenter (2500 - 2999 posts)
 
Join Date: Nov 2000
Location: NJ, USA
Posts: 2,535 jdk User rank is Lance Corporal (50 - 100 Reputation Level)jdk User rank is Lance Corporal (50 - 100 Reputation Level)jdk User rank is Lance Corporal (50 - 100 Reputation Level) 
Time spent in forums: 11 m 11 sec
Reputation Power: 10
Send a message via Yahoo to jdk
Angry My browser hijacked! :(

Hi All,

I don't know how but somehow sbvr.com has hijacked my browser!
It resets my homepage/search page after every boot! Keeps opening some browser windows alternatively
And worse of it all,
It installs a ugly toolbar on my windows explorer and keeps putting XXX sites shortcuts on my desktop!

I don't know how it got in to my PC, but I am simply unable to remove it.

Searching on NET wasn't of much help. Most of the sites are asking to download some software which is paid one!

Actually I have searched for all startup options (using msconfig and registry) but I am unable to locate file which is resetting my homepage/search page.

Is there any way I can know for sure which ALL programs are starting when Windows boots up??


I have two questions to ask:
1. How do I remove this software?
2. How come it is so easy for a site to get into my PC like this?


Please help me!

Regards,
JD
__________________
_____________________________
d.k.jariwala (JD)
~ simple thought, simple act ~
I blog @ http://jdk.phpkid.org

Reply With Quote
  #2  
Old June 2nd, 2003, 05:34 AM
SilkySmooth's Avatar
SilkySmooth SilkySmooth is offline
Newbie :P
Dev Shed Frequenter (2500 - 2999 posts)
 
Join Date: Jan 2001
Location: In the PHP Engine :-)
Posts: 2,880 SilkySmooth User rank is Sergeant (500 - 2000 Reputation Level)SilkySmooth User rank is Sergeant (500 - 2000 Reputation Level)SilkySmooth User rank is Sergeant (500 - 2000 Reputation Level)SilkySmooth User rank is Sergeant (500 - 2000 Reputation Level)SilkySmooth User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 11 h 12 m 25 sec
Reputation Power: 15
I did some searching and found out it is called 'Lop' usually it gets into your PC via Porn or MP3 sites, removal instructions are at the following link. Apparently it can be setup to not prompt users which is probably how it installed itself on your machine.

http://allentech.net/parasite/lop.html

HTH
__________________
---------------------
-- SilkySmooth --
---------------------
Directory Share | Free phpLD Mods | Little Directory

Reply With Quote
  #3  
Old June 2nd, 2003, 10:59 AM
andywhitt's Avatar
andywhitt andywhitt is offline
PHP Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2002
Location: England
Posts: 163 andywhitt User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 11 h 24 m 39 sec
Reputation Power: 6
Yeah i've had that, I got it form a damn MP3 site, do a couple of ping, when i pinged Nx01 a machine on my network it was failing as it was messing with my packets, ended up ping somat like, nx01.tjaw.com or somat.

I tried all the guides but couldn't get it to go, so, i had to format.


Reply With Quote
  #4  
Old June 2nd, 2003, 11:11 AM
Ctb's Avatar
Ctb Ctb is offline
An Ominous Coward
Dev Shed Specialist (4000 - 4499 posts)
 
Join Date: Jan 2002
Posts: 4,425 Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level) 
Time spent in forums: 3 Weeks 10 h
Reputation Power: 0
Be sure to check your hosts file after you clean everything else up. Some of those damn things fiddle with that. I hadn't realized that the default on my IE browser on my brand new laptop had the Install On Demand turned on with no prompt. Some stupid thing like Lop installed while my girlfriend was clicking around (she refuses to use Mozilla just because I use it) and it put a www.google.com entry in my hosts file and pointed it to one of those stupid pay per click "web portals".

Reply With Quote
  #5  
Old June 2nd, 2003, 12:03 PM
Viper_SB's Avatar
Viper_SB Viper_SB is offline
Psycho Canadian
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Jan 2001
Location: Canada
Posts: 4,739 Viper_SB User rank is Major (30000 - 40000 Reputation Level)Viper_SB User rank is Major (30000 - 40000 Reputation Level)Viper_SB User rank is Major (30000 - 40000 Reputation Level)Viper_SB User rank is Major (30000 - 40000 Reputation Level)Viper_SB User rank is Major (30000 - 40000 Reputation Level)Viper_SB User rank is Major (30000 - 40000 Reputation Level)Viper_SB User rank is Major (30000 - 40000 Reputation Level)Viper_SB User rank is Major (30000 - 40000 Reputation Level)Viper_SB User rank is Major (30000 - 40000 Reputation Level)Viper_SB User rank is Major (30000 - 40000 Reputation Level) 
Time spent in forums: 4 Weeks 6 h 25 m 16 sec
Reputation Power: 384
Quote:
Originally posted by Ctb
Be sure to check your hosts file after you clean everything else up. Some of those damn things fiddle with that. I hadn't realized that the default on my IE browser on my brand new laptop had the Install On Demand turned on with no prompt. Some stupid thing like Lop installed while my girlfriend was clicking around (she refuses to use Mozilla just because I use it) and it put a www.google.com entry in my hosts file and pointed it to one of those stupid pay per click "web portals".


Damn that would suck seeing how much google is used now.

Reply With Quote
  #6  
Old June 2nd, 2003, 01:18 PM
macskeeball macskeeball is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2003
Posts: 65 macskeeball User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 24 m 13 sec
Reputation Power: 5
If buying a Mac (or even switching to Linux) is out of the question, try using Firebird instead of IE after you fix the problem.

Last edited by macskeeball : June 2nd, 2003 at 01:21 PM.

Reply With Quote
  #7  
Old June 2nd, 2003, 01:20 PM
macskeeball macskeeball is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2003
Posts: 65 macskeeball User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 24 m 13 sec
Reputation Power: 5
Re: My browser hijacked! :(

Quote:
Originally posted by jdk
How come it is so easy for a site to get into my PC like this?

Blame MS "security".

Reply With Quote
  #8  
Old June 2nd, 2003, 03:40 PM
Ctb's Avatar
Ctb Ctb is offline
An Ominous Coward
Dev Shed Specialist (4000 - 4499 posts)
 
Join Date: Jan 2002
Posts: 4,425 Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level) 
Time spent in forums: 3 Weeks 10 h
Reputation Power: 0
jdk -

I would suggest that if you're going to keep using IE, you make sure install on demand is off completely. Also, make sure that you're being alerted whenever you move from secure to insecure pages. Finally, NEVER download browser toolbars, dialers, etc. off a third party site if you don't know anything about it. Oh - and if it comes with an installer that has an agreement you have to OK... suffer reading through the whole thing. It'll save a lot of suffering later.

Reply With Quote
  #9  
Old June 2nd, 2003, 03:54 PM
jpenn's Avatar
jpenn jpenn is offline
Contributing User
Dev Shed Frequenter (2500 - 2999 posts)
 
Join Date: Jun 2002
Location: Washington, DC
Posts: 2,693 jpenn User rank is Sergeant (500 - 2000 Reputation Level)jpenn User rank is Sergeant (500 - 2000 Reputation Level)jpenn User rank is Sergeant (500 - 2000 Reputation Level)jpenn User rank is Sergeant (500 - 2000 Reputation Level)jpenn User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 5 h 41 m 10 sec
Reputation Power: 15
Quote:
If buying a Mac (or even switching to Linux) is out of the question, try using Firebird instead of IE after you fix the problem.

Browse the web using a database, hmmmm - maybe pheonix or moz (oh, forgot - can't use pheonix name because they ripped it off) dope! seems to be a habit by them....
__________________
~ Joe Penn

Reply With Quote
  #10  
Old June 2nd, 2003, 04:49 PM
thedude thedude is offline
The Dude Abides
Dev Shed Beginner (1000 - 1499 posts)
 
Join Date: Feb 2000
Location: grass valley,ca
Posts: 1,063 thedude User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 Day 9 h 4 m 29 sec
Reputation Power: 10
Having your browser act like that can also come from a virus. I've fixed several of these, but at the moment I can't remember which virus or the fix. Go to housecall.antivirus.com and scan your system.

If you really want to stop the problems, get mozilla. There is also a browser called Slimbrowser www.flashpeak.com . It less than a meg in size, and is pretty quick. It also has popup stopping abilities, etc.

It seems to run off of IE, but I'm not sure how.

Reply With Quote
  #11  
Old June 2nd, 2003, 08:21 PM
Ctb's Avatar
Ctb Ctb is offline
An Ominous Coward
Dev Shed Specialist (4000 - 4499 posts)
 
Join Date: Jan 2002
Posts: 4,425 Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level) 
Time spent in forums: 3 Weeks 10 h
Reputation Power: 0
Quote:
It seems to run off of IE, but I'm not sure how

I've seen a couple of products that "enhanced" IE. They usually seem to just be alterations to the basic shell, but some of them are really major gut / rebuilds of the thing. I can't remember what the one was called but it had an "integrated" (sort of) mail client, a popup blocker, completely redone set of security tools, web toolbars, skins, all sorts of stuff. It only cost something like $20.00 too.

Reply With Quote
  #12  
Old June 2nd, 2003, 08:42 PM
jpenn's Avatar
jpenn jpenn is offline
Contributing User
Dev Shed Frequenter (2500 - 2999 posts)
 
Join Date: Jun 2002
Location: Washington, DC
Posts: 2,693 jpenn User rank is Sergeant (500 - 2000 Reputation Level)jpenn User rank is Sergeant (500 - 2000 Reputation Level)jpenn User rank is Sergeant (500 - 2000 Reputation Level)jpenn User rank is Sergeant (500 - 2000 Reputation Level)jpenn User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 5 h 41 m 10 sec
Reputation Power: 15
There are hundreds of products that run off of/integrated with/developed around IE on the market. Editplus wraps IE when using the browser features, AOL wraps it also (although soon to be changing). If I am not mistaken, you can also wrap a Lingo application around IE. In the next couple of years, there will be thousands and thousands of software packages that will wrap around it.

I have been asking myself for a while now would it be better to write applications around Moz or around IE. Still have yet to come to a conclusion on it, hopefully I will soon though...

Last edited by jpenn : June 2nd, 2003 at 08:44 PM.

Reply With Quote
  #13  
Old June 2nd, 2003, 10:41 PM
jdk's Avatar
jdk jdk is offline
phpkid ~~~~~~ :o)
Dev Shed Frequenter (2500 - 2999 posts)
 
Join Date: Nov 2000
Location: NJ, USA
Posts: 2,535 jdk User rank is Lance Corporal (50 - 100 Reputation Level)jdk User rank is Lance Corporal (50 - 100 Reputation Level)jdk User rank is Lance Corporal (50 - 100 Reputation Level) 
Time spent in forums: 11 m 11 sec
Reputation Power: 10
Send a message via Yahoo to jdk
I did search on NET. Mostly it got me results where they were recommending me to buy Ad-aware software or some thing else.

Anyways, I have found the solution.

I downloaded this nifty utility to see what is running at start up. http://www.sysinternals.com/ntw2k/s....shtml#autoruns

I simply removed the naughty entries there and their corresponding files from Application data folder and I am through!

Regards,
JD

Reply With Quote
  #14  
Old June 2nd, 2003, 10:59 PM
jpenn's Avatar
jpenn jpenn is offline
Contributing User
Dev Shed Frequenter (2500 - 2999 posts)
 
Join Date: Jun 2002
Location: Washington, DC
Posts: 2,693 jpenn User rank is Sergeant (500 - 2000 Reputation Level)jpenn User rank is Sergeant (500 - 2000 Reputation Level)jpenn User rank is Sergeant (500 - 2000 Reputation Level)jpenn User rank is Sergeant (500 - 2000 Reputation Level)jpenn User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 5 h 41 m 10 sec
Reputation Power: 15
I still have this tinybar search thing embedded in my ie6 that I can't get rid of. This thing has been there for about 10 months now. It opens in the side bar whenever I click on the search button in the toolbar. I have it set for google but this thing overrides it. I have no clue how I picked it up...

Reply With Quote
  #15  
Old June 3rd, 2003, 07:54 AM