Tuesday, September 21, 2004

When you get hijacked...

Your machine may be suffering the effects of a BHO or Browser Helper/Hijack Object which may conceal more troublesome malware as well.

The removal sequence is fairly lengthy but should work for most BHOs:

*** BHOs - Detection & Removal ***

FIRST: BACKUP YOUR REGISTRY & any important data - 'cause you just never know.

SECOND: In WinME and WINXP - TURN OFF SYSTEM RESTORE!

THIRD: Enable viewing all system and hidden files.

1) Obtain HijackThis & CWShredder.

Get the latest CWShredder and yet more info on parasites and hijackers, here or here.

2) Get a registry cleaner. I use EasyCleaner v2.0 or later by Toniarts.

3) If you have not already, download anti-spyware/malware software like AdAware & SpyBot.

4) Boot to Safe Mode.

5) Run Hijack This. If confident, perform the deletions on your own. If not comfortable, post your HJT log to an appropriate forum for help.

6) Run CWShredder. Check for updates before you do. Make sure you have v1.56.0.1 or later before you try to fix anything.

(If CWShredder and Hijack This won't run to completion, download and run CoolWWWSearch.SmartKiller and then go back to step 5.)

7) Repeat steps 5) and 6) until everything is removed.

8) Run anti-spyware if desired (Recommended): AdAware v6 or Adaware Pro SE v. 1.05 and Spybot Search & Destroy 1.3. Make sure you have the latest dat files updated for both programs before scanning anything. Some folks also use Bazooka Spyware Detector,

9) Now run the registry cleaner. I used EasyCleaner v2.0 (Windows Help bug fixed).

That should allow you to set your home page to whatever you want, speed up your machine and generally improve your life and disposition.

If that doesn't work (rare but possible) see discussion here or an entire forum devoted to this topic.

HTH

When I'm not doing important stuff like opining on thiser and thater, I'm generally charging people to do the stuff I've just told you how to do for free. As always, if by incompetently following these detailed and highly reliable instructions (or even if you follow them to the letter, in your dreams), your computer or the computer of your friend or loved one melts, blows up real good or transports you into another dimension, I disavow any and all responsibility. In other words, this works, but proceed at your own risk.

32 Comments:

Anonymous Anonymous said...

Hey, you have a great blog here! I'm definitely going to bookmark you!
I have a computer virus site/blog. It pretty much covers ##KEYWORD## related stuff.

Come and check it out if you get time :-)

4:56 AM  
Anonymous Anonymous said...

What Is Wrong with so many Spy-Ware Tools that promise to do the job?

After installing you find out they use so much memory! They have to run in

the systems tray and always have to be run on a regular weekly bases!

And if thats not enough we find out we have to pay for the upgrade

so it will run in the background,But it still sucks up the memory!

Simple Solution you want a software that will kill that Spyware

and all the Gremlins on contact use the least memory and be a

Set & Forget Tool!

Grab it Now Free plus a how to Video w/ Xp Mini Course !

I have a 98 defrag free window

9:12 PM  
Anonymous Anonymous said...

Internet. SpyWare reports your activities to the advertising providers' web

7:47 PM  
Anonymous Anonymous said...

Hey, what a really good eradication of computer viruses in the workplace blog you got here!. I too have a eradication of computer viruses in the workplace related site that I think would be of interest to your readers. Would love your feedback

9:41 PM  
Anonymous Anonymous said...

I like the page you have here. Check mine out health club gyms

9:39 PM  
Anonymous Anonymous said...

Hi there adaplant, I’m out surfing for the latest
information on spybot and found your great site.
Although this post wasn’t exactly what I was looking
for it certainly peaked my interest. Now I see why I
found your page when I was looking for spybot
related information and I’m happy I found your wine
blog even though this isn’t a perfect match. Great
Post, thanks for the read, I will leave you with one
of my favorite quotes from Andy Rooney: " Computers
make it easier to do a lot of things, but most of the
things they make it easier to do don't need to be
done.." Andy Rooney

4:16 PM  
Anonymous Anonymous said...

Hi there adaplant, I’m out surfing for the latest
information on addaware and found your great site.
Although When you get hijacked... wasn’t exactly what I was looking
for it certainly peaked my interest. Now I see why I
found your page when I was looking for addaware
related information and I’m happy I found your wine
blog even though this isn’t a perfect match. Great
Post, thanks for the read, I will leave you with one
of my favorite quotes from Andy Rooney: " Computers
make it easier to do a lot of things, but most of the
things they make it easier to do don't need to be
done.." Andy Rooney

1:54 AM  
Anonymous Anonymous said...

Hi adaplant, today I’m surfing for a good blog
experience on spybot search and destroy and I found your great site.
Well When you get hijacked... wasn’t exactly what I was looking for
it did receive my attention and interest. I see now
why I found your resourceful web-site when I was
searching for spybot search and destroy related information and I am
glad I found your site even though its not an exact
find. Let me contribute to this site by leaving you
with my favorite quote from Nicholas Negroponte! -
"Computing is not about computers any more. It is
about living." --- Nicholas Negroponte ---

10:56 AM  
Anonymous Anonymous said...

Hello adaplant, I’m out surfing the web for the latest
information on addaware download and noticed your nice site.
Although this post wasn’t exactly what I was looking
for it certainly got my attention. Now I see why I
found your page when I was looking for addaware download
related information and I’m thrilled I found your web
site even though its not a perfect match. Great Post,
thanks for your informative site, I’ll leave you with
my favorite quote from Isaac Asimov: "I do not fear
computers. I fear the lack of them.” Isaac Asimov

10:29 AM  
Anonymous Anonymous said...

adaplant, today I was looking for a nice blog
experience on spybot search and destroy and I found your website.
this post wasn’t exactly what I was looking for but it
did get my attention and interest. I see why I arrived
on your excellent blog when I was searching for
spybot search and destroy related information and I’m glad I did
even though its not an exact fit. Well let me contribute
to your website by leaving you with one of my favorite
quote from Robert Orben: "To err is human - and to
blame it on a computer is even more so. - Robert Orben
Informative Post, thanks for the read and nice
experience.

12:19 PM  
Anonymous Anonymous said...

Hello adaplant, I’m out surfing the web for the latest
information on addaware se and noticed your nice site.
Although When you get hijacked... wasn’t exactly what I was looking
for it certainly got my attention. Now I see why I
found your page when I was looking for addaware se
related information and I’m thrilled I found your web
site even though its not a perfect match. Great Post,
thanks for your informative site, I’ll leave you with
my favorite quote from Isaac Asimov: "I do not fear
computers. I fear the lack of them.” Isaac Asimov

9:59 PM  
Anonymous Anonymous said...

adaplant, today I was looking for a nice blog
experience on spybot search and destroy and I found your website.
When you get hijacked... wasn’t exactly what I was looking for but it
did get my attention and interest. I see why I arrived
on your excellent website when I was searching for
spybot search and destroy related information and I’m glad I did
even though its not an exact fit. I’ll contribute to
your website by leaving you with one of my favorite
quote from Walter Mossberg:: "Why shouldn't a PC work
like a refrigerator or a toaster? " -- Walter
Mossberg

4:51 AM  
Anonymous Anonymous said...

Hello there adaplant, I’m out surfing for a good blog
experience on addaware se and found your great site.
Although When you get hijacked... wasn’t exactly what I’m looking for
it certainly got my attention and interest. I see now
why I found your excellent blog-site when I was
searching for addaware se related web sites and I’m
glad I found your site even though its not an exact
match. I’ll leave you with a good quote from Walter F.
Mondale - "What do we want our kids to do? Sweep up
around Japanese computers? " -- Walter F. Mondale
Excellent Post, thank you for the read.

4:25 AM  
Anonymous Anonymous said...

Hello there adaplant, I’m out surfing for a good blog
experience on adaware and found your great site.
Although this post wasn’t exactly what I’m looking for
it certainly got my attention and interest. I see now
why I found your excellent blog-site when I was
searching for adaware related web sites and I’m
glad I found your site even though its not an exact
match. I’ll leave you with a good quote from Walter F.
Mondale - "What do we want our kids to do? Sweep up
around Japanese computers? " -- Walter F. Mondale
Excellent Post, thank you for the read.

5:00 PM  
Anonymous Anonymous said...

Hello there adaplant, I’m out surfing for a good blog
experience on spybot and found your great site.
Although this post wasn’t exactly what I’m looking for
it certainly got my attention and interest. I see now
why I found your excellent blog-site when I was
searching for spybot related web sites and I’m
glad I found your site even though its not an exact
match. I’ll leave you with a good quote from Walter F.
Mondale - "What do we want our kids to do? Sweep up
around Japanese computers? " -- Walter F. Mondale
Excellent Post, thank you for the read.

8:10 AM  
Anonymous Anonymous said...

Hi there adaplant, I’m out surfing for the latest
information on addaware download and found your great site.
Although When you get hijacked... wasn’t exactly what I was looking
for it certainly peaked my interest. Now I see why I
found your page when I was looking for addaware download
related information and I’m happy I found your wine
blog even though this isn’t a perfect match. Great
Post, thanks for the read, I will leave you with one
of my favorite quotes from Andy Rooney: " Computers
make it easier to do a lot of things, but most of the
things they make it easier to do don't need to be
done.." Andy Rooney

5:45 PM  
Anonymous Anonymous said...

Hey there adaplant, I was looking for an educational
blog experience on adaware and I found your
blog-site. When you get hijacked... isn’t exactly what I was
searching for but it did get my and interest. Now I
know why I found your excellent blog-site when I was
looking for adaware related information and I’m
glad I did even though its not an exact find. Great
Informative Post, thanks for the read and educational
experience. Well let me contribute to your blog-site
by leaving you with my all time favorite quote from
Clifford Stoll: " Treat your password like your
toothbrush. Don't let anybody else use it, and get a
new one every six months. Clifford Stoll

9:09 PM  
Anonymous Anonymous said...

Hello adaplant, I’m just searching the web for the
next big thing on adaware and noticed your great
site. Although When you get hijacked... wasn’t actually what I was
looking for it DID get my attention and interest. I
see now why I found your great website when I was
searching for adaware related information and I’m
thankful I found your blogsite even though its not an
exact match. Excellent Post, thanks for the read
(It’s a keeper), One last thing, here’s a great quote
from Doug Larson - "Home computers are being called
upon to perform many new functions, including the
consumption of homework formerly eaten by the dog." -
Doug Larson

12:38 AM  
Anonymous Anonymous said...

adaplant, today I was looking for a nice blog
experience on adware scan and I found your website.
When you get hijacked... wasn’t exactly what I was looking for but it
did get my attention and interest. I see why I arrived
on your excellent website when I was searching for
adware scan related information and I’m glad I did
even though its not an exact fit. Let me contribute
to your website by leaving you with one of my favorite
quote from Thomas Jefferson: "To err is human - and to
blame it on a computer is even more so. - Robert Orben
Informative Post, thanks for the read and nice
experience.

11:52 PM  
Anonymous Anonymous said...

Hi blogger:)

My visitors need some other information cause my blog is very new with few posts. So I shall place your blog URL on mine. Hope you appreciate this:)

Regards,
spyware detect

5:21 PM  
Anonymous Anonymous said...

Hello,

Your blog is the nicest one I have seen for a long time.. I would be interested if could you send me a newsletter or some more info..

Regards,
Remove Adware

9:09 AM  
Anonymous Anonymous said...

Hello,

I found the ideas on your site to be original and very well thought out. I will continue to visit your site regularly.

Regards,
cleaner spyware

6:14 AM  
Anonymous Anonymous said...

Hello there adaplant, I’m out surfing for a good blog
experience on remove spyware and found your great site.
Although When you get hijacked... wasn’t exactly what I’m looking for
it certainly got my attention and interest. I see now
why I found your excellent blog-site when I was
searching for remove spyware related web sites and I’m
glad I found your site even though its not an exact
match. I’ll leave you with a good quote from Walter F.
Mondale - "What do we want our kids to do? Sweep up
around Japanese computers? " -- Walter F. Mondale
Excellent Post, thank you for the read.

4:57 PM  
Anonymous Anonymous said...

Hi i was searching for ##keyword##, i found your blog. Great Blog,
Congratualtion for your great blog. i will keep on reading.
thanks
##link##

12:02 AM  
Anonymous Anonymous said...

I was searching blogspots on Google and found yours. Good blogsite with some intersting comments!

Message is from http://www.spyware-beware.com/Spyware/Spyware_Detection.html which is refers to trojan horse protection

8:55 AM  
Anonymous Anonymous said...

I was searching blogs on Google and came across yours. Nice keep up the good work.

Message from http://www.spyware-beware.com/Spyware/Spyware_Detection.html my site is about spyware blockers

9:31 AM  
Anonymous Anonymous said...

Hey there adaplant, I was looking for an educational
blog experience on free adware and I found your
blog-site. When you get hijacked... isn’t exactly what I was
searching for but it did get my and interest. Now I
know why I found your excellent blog-site when I was
looking for free adware related information and I’m
glad I did even though its not an exact find. Great
Informative Post, thanks for the read and educational
experience. Well let me contribute to your blog-site
by leaving you with my all time favorite quote from
Clifford Stoll: " Treat your password like your
toothbrush. Don't let anybody else use it, and get a
new one every six months. Clifford Stoll

12:41 AM  
Anonymous Anonymous said...

Addware is advertising supported software. It is software that can be downloaded free from the web, but contains banner advertisements that create revenue for the company. Instead of you having to pay for the software, the company creates revenue by selling advertising space in the software product. Addware will usually, like Spyware, install components on your computer that will send marketing information whenever you are online and may exchange statistical data with a remote location over the internet. Unlike Spyware, addware contains a disclosure telling you that they will be using your information. Other programs expand beyond this definition by running continuously and by showing advertisements specifically tailored to the web sites that users visit. It is important to read the privacy policy when downloading and installing addware. addware free removal scan spyware

8:42 AM  
Anonymous Anonymous said...

Hello there adaplant, I’m out surfing for a good blog
experience on remove adware and found your great site.
Although When you get hijacked... wasn’t exactly what I’m looking for
it certainly got my attention and interest. I see now
why I found your excellent blog-site when I was
searching for remove adware related web sites and I’m
glad I found your site even though its not an exact
match. I’ll leave you with a good quote from Walter F.
Mondale - "What do we want our kids to do? Sweep up
around Japanese computers? " -- Walter F. Mondale
Excellent Post, thank you for the read.

11:00 PM  
Anonymous Anonymous said...

adaplant, today I was looking for a nice blog
experience on free adware download and I found your website.
When you get hijacked... wasn’t exactly what I was looking for but it
did get my attention and interest. I see why I arrived
on your excellent website when I was searching for
free adware download related information and I’m glad I did
even though its not an exact fit. Let me contribute
to your website by leaving you with one of my favorite
quote from Thomas Jefferson: "To err is human - and to
blame it on a computer is even more so. - Robert Orben
Informative Post, thanks for the read and nice
experience.

9:22 PM  
Anonymous Anonymous said...

Hi adaplant, today I’m surfing for a good blog
experience on remove spyware and I found your great site.
Well When you get hijacked... wasn’t exactly what I was looking for
it did receive my attention and interest. I see now
why I found your resourceful web-site when I was
searching for remove spyware related information and I am
glad I found your site even though its not an exact
find. Let me contribute to this site by leaving you
with my favorite quote from Nicholas Negroponte! -
"Computing is not about computers any more. It is
about living." --- Nicholas Negroponte ---

4:04 PM  
Anonymous James said...

Nice post. You explained the steps really well. It will definitely resolve the problem but the steps are quite lengthy and confusing. Anyway great job. Keep it up!

11:20 AM  

Post a Comment

<< Home