FINANCIAL SAVER GEOMATRYX

My random thoughts,useless and useful informations I gather, my financial thought process, investments, research, general knowledge, frugal consumerism ideas, Best deals - a mixture of all these are in my blog entries

Saturday, March 11, 2006

My Browser got Hijacked !

My bad memory- I forgot to change back my internet security levels I lowered for downloading some private files, my activeX set ups were too liberal. I learned my lesson in the hard way.

As I was browsing thru blogger.com bloggers list randomly, I ended up in a rogue blog intended for malware distribution. Before I could react to the warnings from my spywares detectors, it infected my PC with all sorts of trojans and spywares/adwares. Virus protection helped me avoid virus attacks, however the damage was already done on spyware, malware and Trojan fronts.

Next thing I know, my home page on Internet explorer was changed, my browser got hijacked and some kind of a Linkmaker Trojan created pseudo links over any webpages I access which will take me to some ad sites. There are tons of pop up's jumping out per clicks and the system slowing down with all these activity. I started using all my existing adware tools to eliminate these spywares. Adaware and Microsoft defender did very minimal cleanup, spybot clean & destroy identified and cleaned little more. But my browser was still ill.

This prompted me get into offensive against these pests, I went to download.com looking for popular spyware cleaners and I got a few - trial versions of Spyware Doctor, Spyware Blaster, Counterspy etc. I also got popular clean up and analyzer tools like ewido, hijack this,ccleaner,cwshredder etc.

Spyware Doctor and Counterspy showed me all the culprits -and I advice you to remember these pests - Purity, Elitemediagroup pop64, eZula, bargainbuddy,Bigtraffic Network,Linkmaker Hijacker, Backdoor.hackdef.bo, Ilookup are some of the lowlifes. They can hide very well, rename themselves, create, rename and alter system files, add new entries to your windows registry and are persistent and stealth. Since trial version of Spydoctor do not remove these, I had to go to the registry and manually remove most of these. ( Do not try this at home unless you really know what you are doing. There are procedures for altering and removing system files and registry entries ) CounterSpy helped in removing few of the malwares as well.
HijackThis log is the tool which really helped me to weed out all the buggers - well it took about 12 hours of hard work on a trial and error approach. On the bright side, I learned a few new tricks, I cleaned up some junk from my pc and my tech junkie ego got a lot of joy in researching and solving the problem.

May be we should all think about getting firefox as browser. Spyware's were not impacting Firefox. LinkMaker pranks and hijacking was all on Internet Explorer.

3 Comments:

  • At 3/13/2006 1:13 AM, Blogger Xindaeltal said…

    We need tombstone says it all? What you talking 'bout Willis?

     
  • At 3/13/2006 7:31 AM, Blogger KARA said…

    Interesting? Thanks.

     
  • At 3/13/2006 3:46 PM, Anonymous G. Rissin said…

    Subject: Your LINK AD has been posted

    Hi,

    Your Page Ad has been posted on our pixel ad page. We hope you get many clicks on your ad.

    Thanks for posting our link on your blog. Can you change the link text to 2MillionDollarsPage.com ?
    Since that there is one Pixel Your Page already, I think that changing mine, will be gook. They both look as they were the same page. Don't you think that?
    Thanks in advance.

    You can visit any time to view the Stats page to see how many clicks your Pixels have gotten.
    http://www.2milliondollarspage.com/stats.php

    We want to tell you also that we found a fantastic way to get thousands of hits to your page.
    It is FREE and only takes a second! All your need to do is click the link below to sign up:
    http://www.hits2u.com/?122912

    Thanks again!

    G.Rissin
    http://www.2MillionDollarsPage.com

     

Post a Comment

<< Home