WebProWorld Part of WebProNews.com
Page One Link To Us Edit Profile Private Messages Archives FAQ RSS Feeds  
 

Go Back   WebProWorld > Webmaster, IT and Security Discussion > Internet Security Discussion Forum
Subscribe to the Newsletter FREE!


Register FAQ Members List Calendar Arcade Chatbox Mark Forums Read

Internet Security Discussion Forum This forum is for the discussion of security related issues. If you find a new Phishing scheme, spyware, virus or malicious site - let us know about it. If any of the above found you... here's where you ask for help.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 09-23-2005, 01:38 PM
kgun's Avatar
kgun kgun is online now
WebProWorld 1,000+ Club
 

Join Date: May 2005
Location: Norway
Posts: 4,689
kgun RepRank 3kgun RepRank 3
Default Stop browser hijacking.

Browser hijacking can be very difficult to repair. In the worst cases, where links are encrypted and owerwrite good links, you may reformat your system harddrive and restore the system.

"In some cases, these changes are reversible simply by going into internet options and switching them back. Not always, however. Sometimes it's necessary to edit the windows registry (gasp!) to undo the changes made. Sometimes there is even a combination of registry setting and files clandestinely placed on your hard drive that redo your settings every time you reboot the computer.

No matter how often you change your settings back, they are changed again the next time you restart. There have even been cases where internet options have been removed from the tools menu by registry hacking to prevent you from controlling your own computer!

Even AOL has become a browser hijacker by placing their web site free.aol.com in Internet Explorer's trusted sites security zone, thereby bypassing the most frequently used security settings. This occurs after installing their AOL software, AOL Instant Messenger, Netscape 6.x and ICQ2001b has reportedly done this. AOL then exploits this by downloading ActiveX components to your computer without your consent. The CWS trojan also does this".
http://www.spywareinfo.com/articles/hijacked/

One of the best ways to prevent this type of hijacking is by using intrusion software like Abtrusion Protector that monitors your computers's registers and ask if you want to modify register keys. Abtrusion Protector is free for noncommercial use. There are also free software that is good enough.

Some links:
http://www.acelogix.com/freeware.html
http://www.abtrusion.com/
http://www.free-web-browsers.com/sup...ijackers.shtml
Reply With Quote
  #2 (permalink)  
Old 09-23-2005, 02:16 PM
kgun's Avatar
kgun kgun is online now
WebProWorld 1,000+ Club
 

Join Date: May 2005
Location: Norway
Posts: 4,689
kgun RepRank 3kgun RepRank 3
Default Forgot this important link:

"Several of these hijackers knowingly exploit an Internet Explorer / Outlook Express bug that allows them to be secretly installed on a user's system upon simply viewing the Web page. Hijackers using this bug wil plant one or more .hta files on your system which are executed on startup by Windows Scripting Host. To restore normal operation, search your system for *.hta files and rename any that are found (e.g. change file.hta to file.hta_) or move them to another directory. Then change your homepage and other browser defaults to those you prefer".
http://www.cexx.org/hphijack.htm

If you know how to clean the registers, this
http://www.cexx.org/startup.htm
may be for you.
Reply With Quote
Reply

  WebProWorld > Webmaster, IT and Security Discussion > Internet Security Discussion Forum
Tags: browser, hijacking, stop



Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Search Engine Friendly URLs by vBSEO 3.0.0