I E SEARCH BUTTON HI JACKED !

  [DELETED] 17:22 02 Oct 2003
Locked

Hi my IE search button has been hi jacked by an unsavoury site. Every time I press it. while I was innocenntly browsing (honest!)Ive tried spy bot Norton anti virus but to no avail . Help please ...



[email protected]

  [DELETED] 17:38 02 Oct 2003
  [DELETED] 17:40 02 Oct 2003

Hi, this site has a lot of information that may be able to help you click here

  [DELETED] 17:41 02 Oct 2003

Try hereclick here

Not a good idea to put your email address in a open forum.

  [DELETED] 18:42 02 Oct 2003

Try SpywareInfo as mentioned by Gongoozler, they specialise in the removal of spyware including your registry. They normally ask you to run HijackThis click here and copy and paste the results on their forum. Bear in mind the time difference in the States. You might not get any answers until the're up and about. HTH TR

  [DELETED] 19:57 02 Oct 2003

yeah thanks i tried all the above spy bot spy ware
but still nothing anybody suggest anything else?
it feels really embedded!

  [DELETED] 19:57 02 Oct 2003

yeah thanks i tried all the above spy bot spy ware
but still nothing anybody suggest anything else?
it feels really embedded!

  [DELETED] 20:51 02 Oct 2003

i tried hi jack this it removed the offending article but now my home page default settings button is greyed out!

  [DELETED] 20:51 02 Oct 2003

Try running CWS shreddder which may help.
click here

  [DELETED] 20:58 02 Oct 2003

frankzappa, did you go to the SpywareInfo site and post your problem there, my toolbars were hijacked and they sorted it out. It took a few visits but everythings sorted now. TR

  [DELETED] 05:13 05 Oct 2003

did spybopt semmed to do the trick I think but when i switch on zone alarm alerts me that
SVCINIT.EXE is trying to get in
dont know what that is also Hi jack this file is this
O4 - HKLM\..\Run: [HPSCANMonitor] C:\WINDOWS\SYSTEM\hpsjvxd.exe
O4 - HKLM\..\Run: [NPROTECT] C:\Program Files\Norton SystemWorks\Norton Utilities\nprotect.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [Norton CrashGuard Monitor] "C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CRASHGUARD\CGMenu.EXE"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb05.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [MiniLog] C:\WINDOWS\SYSTEM\ZONELABS\MINILOG.EXE -service
O4 - HKLM\..\RunServices: [CSINJECT.EXE] C:\Program Files\Norton SystemWorks\Norton CleanSweep\CSINJECT.EXE
O4 - HKLM\..\RunServices: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"
O4 - HKLM\..\RunServices: [SVC Service] C:\WINDOWS\SYSTEM\svcinit.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [MemoryZipperPlus] C:\Program Files\MemzipP\MEMZIPR.EXE
O4 - HKCU\..\RunServices: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\RunServices: [MemoryZipperPlus] C:\Program Files\MemzipP\MEMZIPR.EXE
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\Winzip\WZQKPICK.EXE
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - click here
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - click here
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - click here
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - click here
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - click here
O16 - DPF: {E522120B-0CF2-4C26-A8EA-50A7591F10F1} (blueyonder Game Launcher Control) - click here
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - click here
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - click here
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - click here
O16 - DPF: {CA797B15-445F-4AA9-9828-8A88502F560F} (Uninstall Control) - click here
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - click here
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - click here
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - click here
O16 - DPF: {1F996EAE-3D97-4862-AA0E-27F257C089DE} (blueyonder Game Launcher Control) - click here
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - click here
O16 - DPF: Yahoo! Chat - click here
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = demon.co.uk
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 158.152.1.58,158.152.1.43

any body help?

This thread is now locked and can not be replied to.

Elsewhere on IDG sites

How to watch the World Cup for free on TV and online

Meet Superfiction, the little design studio with a load of character

Best Mac music-production software

Comment savoir si votre message a été lu sur Facebook & WhatsApp ?