Cannot kill my browser

  • Thread starter Thread starter Franco
  • Start date Start date
F

Franco

Hello all,

During my net surfing, a browser window started on its
own. It appears on the taskbar as "Inbox", but i can't
maximise it to see what the page was. I tried to kill it
with the task manager to no avail. Finally, i was able to
stop it by stopping my internet connection. The URL
appears to be:

www.uchase.com/exit/sticky/stay.html.

Pls tell me what's going on and how can i better cope
with this sort of thing in the future...Someone may want
to look into this site, it seems to be doing funny
business...

Thanx in advance
 
Hi Franco :-)

It is likely you have parasites, spyware, adware, malware, or hijackware on
your system causing the problem, which your antivirus will not detect, as it
does not have the same definitions.

(Unexplained computer behavior may be caused by deceptive software
http://support.microsoft.com/default.aspx?kbid=827315)

Try this and see if it helps.

Tools > Internet Options > Advanced > Browsing
Uncheck the Enable 3rd party browser extensions

Then do the following to clean the cause from your system:

Download and install, then you *MUST* update the programs prior to running
to be sure they have the latest definitions, then run the programs below.
They are free and very effective. Be sure to run both SpyBot and Adaware,
as what one does not detect the other may. It is important that you do all
the steps and follow all directions carefully:

IMPORTANT:
Before trying to remove spyware using the programs below, download a copy of
LSPFIX from the URL below - some malware may kill your internet connection
when it is removed, this program will enable you to regain your connection.
http://www.cexx.org/lspfix.htm

It is important that you run the programs in the order that they are listed
here. The first three programs will clear your machine of all other items so
that you can have a clear HiJackThis Log for the experts to read and analyze
for you.

(NOTE: If you can not download these programs from the Internet, if your PC
has CD read capabilities, go to another computer with CD-ROM burning
capabilities. Create a folder on the hard drive of the other computer called
HOLD, download the programs to that folder, then burn that folder to a CD.
Copy the HOLD folder to your HD and then install the programs from there
and run them. After you have IE access again, update all programs where
possible to get the latest definitions and run them again to be sure there
are no lingering items on the system.

CWShredder: Free
http://tinyurl.com/2l9kl

SpyBot Search & Destroy: Free
http://download.com.com/3000-8022-10289035.html?tag=lst-0-2

AdAware: Free
http://www.lavasoftusa.com/support/download/

HiJackThis: - Free

Go to
http://computercops.biz/downloads-cat-14.html ,
or
http://www.aumha.org/a/parasite.php#hjt
and download HiJackThis. Unzip to a folder other than your Desktop or the
Temp folder, doubleclick HiJackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log"
button. Press that, save the log some place you remember where it is.
Most of what it lists will be harmless or even required, so DO NOT fix
anything yet.

Open the copy of your log in NotePad and make a copy. Then you can go here
to post you log:

Jim Eshelman's site here:
AumHa Forums - HiJackThis section:
http://forum.aumha.org/

Spyware and Hijackware Removal Support, here:
http://216.180.233.162/~swicom/forums/

or Net-Integration here:
http://www.net-integration.net/cgi-...86d536d57b5f65b6e40c55365e;act=ST;f=27;t=6949

or Tom Coyote here: http://forums.tomcoyote.org/index.php?act=idx

<<DO NOT POST YOUR LOG FILE TO THIS NEWSGROUP>>

You will need to register to open a new thread to post you log. It is free,
and no one will Spam you, it is one of many that provides this service. Once
registered, go to the HiJackThis section on the forum list and click to
open. Then start a new post and post your log. The experts there will
analyze the log and report back the results. Please allow at least a few
hours or a days time for a response, depending on when you post the log

Remember, you must return to the HJT site to get your answer. It is a good
idea to click the "Notify" box so that you will get an electronic
notification by e-mail to let you know when a response has been posted.
But, you must still return to the site of your answer

HJT Tutorial
http://www.bleepingcomputer.com/forums/index.php?showtutorial=42


Hope this helps.

Jan :)

Smiles are meant to be shared,
that's why they're so contagious.

Please reply to the newsgroup so others may benefit.
 
Thanks for the warning, but I'm not about to click on it. ;-D

OK...follow the procedures that were presented to you by Jan. I will add
some additional stuff, but she has covered most of the bases. I've only
included links for *Tutorials* for the respective programs inasmuch as Jan
will have provided the main Links. I have included one or two which she may
not have written about.
Quick and basic scans (hardly definitive, but a start)
Doxdesk parasite scan
http://doxdesk.com/parasite/
Jim Eshelmans WSC on-line quick scan
http://www.aumha.org/a/noads.htm
Bugs Glitches and Stuff-ups (Sandi Hardmeiers site...First rate all the
way)
http://inetexplorer.mvps.org/Darnit.htm

More In-Depth on-line scanners for parasites and Trojans:
GFI free on-line Trojan scanner
http://www.windowsecurity.com/trojanscan/
Sygate Technologies Trojanscan
http://scan.sygatetech.com/pretrojanscan.html
PestPatrol on-line scan
http://www.pestscan.com/home.asp
SpywareChecker on-line scan
http://www.spywareguide.com/txt_onlinescan.html

Parasites, spyware malware basics:
http://aumha.org/a/parasite.htm
http://aumha.org/a/quickfix.htm

Another thing to consider doing is to run a program (only run one program
at a time) a few times consecutively. The reason for this is that the first
pass may kill certain Spyware programs, but may not be able to terminate
and kill all files and programs which may be running at the time.
That is why a second pass > may be necessary to be thoroughly effective.

Also, under the most stubborn cases, running the programs in Safe-Mode
will allow for the best cleaning conditions, as there will be a minimum of
interference from processes running in the background.

I'll also add that you should scan and re-scan under all conditions *several
times* until your PC comes up clean. Also, you should try re-booting in
between scans as well. AND, you should do this by what is referred to as a
"clean-boot" environment *in addition* to the conventional methods, until
you come up clean.

"Clean Boot -What it is and why you need it." - Authored by Gary S.
Terhune - MS MVP for Win9x
http://snipurl.com/7hwt

How to Perform Clean-Boot Troubleshooting for Windows 98
http://support.microsoft.com/default.aspx?scid=kb;[LN];192926
This one takes the former "Clean-boot" just one degree deeper than necessary
for most purposes, but thought you should be aware of it.
Ad-Aware Tutorial (might help if you look through this)
http://www.bleepingcomputer.com/forums/index.php?showtutorial=48

CWShredder Tutorial
http://www.bleepingcomputer.com/forums/index.php?showtutorial=47

Coolwebsearch Smartkiller
http://www.safer-networking.org/files/delcwssk.zip

The above item is sometimes necessary if CWShredder detects a SmartSearch2
variant on your PC.

Spybot Tutorial (Must Read)
http://www.safer-networking.org/index.php?page=tutorial
Other tutorials for Spybot S&D (Also must read)
http://www.bleepingcomputer.com/forums/index.php?showtutorial=43
http://tomcoyote.com/SPYBOT/index1.php
http://tomcoyote.com/SPYBOT/index2.php

This item below is designed to *prevent* installation of malware and the
like by comparing known CLSID's of these "bad guys" with what is in its
definitions. By enabling a *Kill Bit* it prevents known malignant ActiveX
from being installed or run on your machine. It doesn't remove anything,
nor will it fix anything that is already in your PC. Rather, it will prevent
installation or re-installation of the item once it has been removed
either > manually, or by the use of another program which will perform
the duty of removing the spyware.
 
Back
Top