Results 1 to 14 of 14

Thread: Homepage Hijack

  1. #1
    Wats ur tale mothergoose?
    Join Date
    Jul 2003
    Location
    Glasgow
    Posts
    882
    Thanks
    1
    Thanked
    3 times in 3 posts
    • Korky's system
      • Motherboard:
      • Abit IP35-Pro
      • CPU:
      • Intel Q6600
      • Memory:
      • 4GB Crucial Ballistix DDR2
      • Storage:
      • 2 x 160GB WD RE2 RAID0
      • Graphics card(s):
      • HD 4870x2
      • PSU:
      • XFX 850W
      • Case:
      • Cheapo
      • Operating System:
      • Windows Vista 32bit
      • Monitor(s):
      • 18" Hanns.G / 42" Panasonic G20
      • Internet:
      • 10Mbit Cable

    Homepage Hijack

    My homepage was taken over last night along with bargain buddy being ingraved in the system. Ive removed bargain buddy but CANNOT get this f**king www.i-lookup.com off my homepage, u change it - it changes it back, you change regedit values and lock them - it changes it, i used several programs including adaware - no help.

    IS it possible to get rid of this scum?

  2. #2
    If your 5555... Swafe's Avatar
    Join Date
    Jul 2003
    Location
    Then I'm...
    Posts
    6,666
    Thanks
    0
    Thanked
    0 times in 0 posts
    mine goes to indredifind

    or some other rubbish site when i type in a wrong url - or get page ant be displayed, proper annoying
    Quote Originally Posted by Knoxville
    As I find big muff's to be a bit of an aquired taste
    AMD Athlon 4400X2 @ 2.565PenisextentionMhz
    Dual Layer, Gold Plated, LED Power,Dual Golden OMG IT MAKES MY CodPiece BIGGER 1-1-1-1 DDR62.3 @ 1222.3433Mhz
    5 X 400GB Porn Array
    X1800XT Dildo enchanged 3D Version, 512MegaLongJohn
    Oh, did I mention.....I like sheep.....


    WWW.MrsBurley.CO.UK
    now updated

  3. #3
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    have you run a copy of spybot - search & destroy ?

    its good at getting rid of browser hijacks.



    http://security.kolla.de/
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  4. #4
    Wats ur tale mothergoose?
    Join Date
    Jul 2003
    Location
    Glasgow
    Posts
    882
    Thanks
    1
    Thanked
    3 times in 3 posts
    • Korky's system
      • Motherboard:
      • Abit IP35-Pro
      • CPU:
      • Intel Q6600
      • Memory:
      • 4GB Crucial Ballistix DDR2
      • Storage:
      • 2 x 160GB WD RE2 RAID0
      • Graphics card(s):
      • HD 4870x2
      • PSU:
      • XFX 850W
      • Case:
      • Cheapo
      • Operating System:
      • Windows Vista 32bit
      • Monitor(s):
      • 18" Hanns.G / 42" Panasonic G20
      • Internet:
      • 10Mbit Cable
    yep moby - adaware, spybot, pestpatrol, startpage guard nothing can stop it.

    every second time i start iexplorer it resets it all to i-lookup, these programs are absolutely useless.
    3D Mark 2k1 - 20661

    If you get a customer, or an employee, who thinks he's Charles Bronson, take the butt of your gun and smash their nose in.

  5. #5
    G4Z
    G4Z is offline
    I'dlikesomebuuuurgazzzzzz G4Z's Avatar
    Join Date
    Sep 2003
    Location
    geordieland
    Posts
    3,172
    Thanks
    225
    Thanked
    141 times in 93 posts
    • G4Z's system
      • Motherboard:
      • Gigabyte GA 965P-DS3
      • CPU:
      • Intel Core 2 Quad Q6600
      • Memory:
      • 4gb DDR2 5300
      • Storage:
      • 2.5Tb
      • Graphics card(s):
      • Gigabyte HD4870 512mb
      • PSU:
      • Tagan 470W
      • Case:
      • Thermaltake Tsunami Dream
      • Operating System:
      • Vista 64bit
      • Monitor(s):
      • Dual Acer 24" TFT's
      • Internet:
      • 16mb sky ADSL2
    consider a switch to opera perhaps..?

    I used to deal with these calls all of the time when I worked on an ISP tech desk. Usually you can uninstall this stuff in add/remove programs. Im surprised ad-aware didnt crack it it usually is very good.

    but if you run a quick search on google you will find....

    http://www.doxdesk.com/parasite/ILookup.html

    http://www.pchell.com/support/click2findnow.shtml
    HEXUS FOLDING TEAM It's EASY

  6. #6
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    have you updated the spybot definitions - that sometimes helps
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  7. #7
    Senior Member
    Join Date
    Sep 2003
    Location
    Perth&London
    Posts
    242
    Thanks
    0
    Thanked
    0 times in 0 posts
    The way it works, those fu**ers save a webpage at your Windows directory, find that one and delete it, should work, did work for me.

  8. #8
    Wats ur tale mothergoose?
    Join Date
    Jul 2003
    Location
    Glasgow
    Posts
    882
    Thanks
    1
    Thanked
    3 times in 3 posts
    • Korky's system
      • Motherboard:
      • Abit IP35-Pro
      • CPU:
      • Intel Q6600
      • Memory:
      • 4GB Crucial Ballistix DDR2
      • Storage:
      • 2 x 160GB WD RE2 RAID0
      • Graphics card(s):
      • HD 4870x2
      • PSU:
      • XFX 850W
      • Case:
      • Cheapo
      • Operating System:
      • Windows Vista 32bit
      • Monitor(s):
      • 18" Hanns.G / 42" Panasonic G20
      • Internet:
      • 10Mbit Cable
    can u gimme more specific directory roots plz pyro, thnx.
    3D Mark 2k1 - 20661

    If you get a customer, or an employee, who thinks he's Charles Bronson, take the butt of your gun and smash their nose in.

  9. #9
    Member
    Join Date
    Jul 2003
    Posts
    120
    Thanks
    0
    Thanked
    0 times in 0 posts
    is it the cookies folder your looking for?

    or maybe the hidden temp file on c: try that

  10. #10
    www.5lab.co.uk
    Join Date
    Sep 2003
    Posts
    6,406
    Thanks
    1
    Thanked
    0 times in 0 posts
    theres normally a process running from c:\documents and settings\all users\something - delete it
    hughlunnon@yahoo.com | I have sigs turned off..

  11. #11
    Spirit of Vengeance
    Join Date
    Jul 2003
    Location
    Accrington, Lancashire
    Posts
    295
    Thanks
    0
    Thanked
    0 times in 0 posts
    i had one of these buggers.. it was just displaying a file from the system32 directory (I think) in my browser.. it looked like a page cannot be displayed page but with advert links etc.. after looking in the address window it showed a filename like "thhtaopsd.htm"

    so I searched for the file and deleted it.. I've had it once after that but it may have been from a site id visited.. not had any trouble recently.

  12. #12
    Oh no!I've re-dorkalated! Jiff Lemon's Avatar
    Join Date
    Jul 2003
    Location
    Sunny MK
    Posts
    2,504
    Thanks
    80
    Thanked
    44 times in 41 posts
    I'm with Moby - Update SpyBot, and run it again.

    http://spybot.eon.net.au/

    The updates are on the right hand side, about 3/4 of the way down.

  13. #13
    Member
    Join Date
    Aug 2003
    Posts
    69
    Thanks
    0
    Thanked
    0 times in 0 posts
    try hijack this! http://mjc1.com/mirror/hjt/
    works wonders

  14. #14
    Senior Member
    Join Date
    Jul 2003
    Location
    Sheffield
    Posts
    529
    Thanks
    1
    Thanked
    0 times in 0 posts
    Originally posted by pyro
    The way it works, those fu**ers save a webpage at your Windows directory, find that one and delete it, should work, did work for me.
    c:\program files\IE\Signup

    The official place for putting isp signup pages that take over IE is in the signup folder.... no idea if you are likely to find it in there.

    Edit: Just delete the whole signup folder and retry.
    consider a switch to opera perhaps..?
    Its a superb suggestion, but we all know we end up having to revert back to IE for 5% of web sites (secure bank sites etc - autotrader since their update 2 weeks ago )


    Edit2: Lovely 'tar Auron
    Last edited by Trickle; 29-10-2003 at 12:36 PM.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •