nowfind.net hijacker

  • Thread starter Thread starter Duke Merc Atreides
  • Start date Start date
D

Duke Merc Atreides

hi, my ie has been hijacked by nowfind.net, and it will not go away no
matter what i try, i change the hompage, it changes back, i have removed the
registry entries, and they come back, anyone know what the host file is?
 
Duke said:
hi, my ie has been hijacked by nowfind.net, and it will not go away no
matter what i try, i change the hompage, it changes back, i have removed the
registry entries, and they come back, anyone know what the host file is?
Beginning of standard canned reply.

Update Windows. Use a firewall.
Use an Anti-Virus of your choice and keep it updated.
In Windows Explorer, set Folder Options to “show all files”.
Clean out all temp, cache, ect. files.
Download BeClean here:
http://boozet.xepher.net/beclean/

Download Sysclean from here:
http://www.trendmicro.com/ftp/products/tsc/sysclean.com
Read this(it tells you how to use it!):
http://www.trendmicro.com/ftp/products/tsc/readme.txt
Reboot into safe mode and run Sysclean, write down results, then reboot
normally.
If offending file is in “restore” read this:
http://service1.symantec.com/SUPPOR...2001111912274039?OpenDocument&src=sec_doc_nam

Download AdAware from here:
http://www.majorgeeks.com/download506.html
Read the help files,download the winsock fix, and then Update and run
AdAware.
If you lose your Internet connection after running AdAware run the fix.
Winsock Fix here:
http://www.tacktech.com/display.cfm?ttid=257

Download Spybot Search+Destroy here:
http://www.safer-networking.org/en/download/index.html
Read this:
http://www.safer-networking.org/en/tutorial/index.html
Update and run Spybot (enable all protection).

Download Spyware Blaster here: (enable all protection)
http://www.javacoolsoftware.com/spywareblaster.html

Run a couple of online scanners (pick a different one than your main AV):

BitDefender:
http://www.bitdefender.com/scan/licence.php

Norton:
http://security.symantec.com/sscv6/...d=sym&plfid=23&pkj=XHPGJRSOMVZGYYTZXPE&bhcp=1

Panda:
http://www.pandasoftware.com/activescan/com/activescan_principal.htm

eTrust:
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx

House Call:
http://housecall.trendmicro.com/housecall/start_corp.asp

If the previous do not solve your problems:
Download Bazooka here:
http://www.kephyr.com/spywarescanner/

Download SwatIt here:
http://swatit.org/

Download KL-Detector here
http://dewasoft.com/privacy/kldetector.htm

Download CWShredder here
http://www.intermute.com/spysubtract/cwshredder_download.html

Download HijackThis here:
http://www.majorgeeks.com/download3155.html
Install, run and save the log that is created. Don’t let it fix anything
yet!
You can find forums to post the log to have it analyzed here:
http://tomcoyote.org/hjt/

Download Stinger here:
http://vil.nai.com/vil/stinger/

Download eScan here:
http://www.mwti.net/antivirus/free_utilities.asp
Rename the downloaded file escan.zip and extract (with a zip program) to
C:\Downloads, which you will have to create. Run the updater
(kavupd.exe) and then run eScan (mwavscan.exe).

End of standard canned reply.
-max

--
Keeping Windows Clean: http://www.geocities.com/maxpro4u/madmax.html
Virus Cleaning+Fixes: http://www.geocities.com/maxpro4u/TechPros
Change nomail.afraid.org to neo.rr.com so you can reply by e-mail
(nomail.afraid.org has been set up specifically for
use in Usenet. Feel free to use it yourself.)
 
Frank said:
Try being helpful instead a smug smart@ss.

You must be an IE user.

Why do you think my link to a description of the HOSTS file was not
helpful?
 
Try being helpful instead a smug smart@ss.

Frank
BSN
[ top posting corrected ]

Curious:
1. Which part did you find unhelpful?
2. Which part deserves the "smart@ss" wisecrack?

J
 
Try being helpful instead a smug smart@ss.

Frank
BSN
[ top posting corrected ] ........NO comment, grin.

Curious:
1. Which part did you find unhelpful?
2. Which part deserves the "smart@ss" wisecrack?

1. The part that needed a tad more of a gnat's IQ to figure out.
2. None.....but he is one of those 'drive by' loudmouths.....sigh.

HF
 
i know what a host file is, i meant what the virus host file is so i can
delete it!
 
On Tue, 28 Dec 2004 10:09:49 GMT, ["Duke Merc Atreides"
i know what a host file is, i meant what the virus host file is so i can
delete it!

There is _no_ virus host file, or do you actually mean the program
file (.exe for example) or ".dll" file that recreates the hijack ?

Did you actually run down the list and try the stuff from Max ?

What OS are you running ? (e.g. win98, winxp etc ?)

Have you checked task manager and see what is running that may be
"unusual" ? Have you tried Start/run msconfig, and see what stuff is
in startup/services ?
 
Heather said:
1. The part that needed a tad more of a gnat's IQ to figure out.

<consults gnat>
I could have posted several paragraphs about how a box-stock Internet
Explorer is a security risk, I suppose. Consider that it could be
easier for most who come here for help to switch to a secure browser,
rather than deal with all those cryptic, hidden settings that _could_
make IE less susceptible to a hijacking.
2. None.....but he is one of those 'drive by' loudmouths.....sigh.

<whisper>
Perhaps concise and to the point, but loudmouth? Nah.
</whisper>
 
Heather said:
<whisper back>
sorry.....just my usual Grinch-like Xmas growl, grin!!
</whisper>

Heather the Grinch? Are you green? ;-) [pictures, please...]
 
Beauregard T. Shagnasty said:
Heather said:
<whisper back>
sorry.....just my usual Grinch-like Xmas growl, grin!!
</whisper>

Heather the Grinch? Are you green? ;-) [pictures, please...]

Just my eyes, lol. Did you want an autographed one? Or a more casual
candid one.......rofl!!
 
ROFL!! Joanie......I haven't had the latest ones *retouched* by my resident
graphic artist as of yet......don't want to scare the heck out of Shaggy.
(G)

I will send YOU that one with Noel only if you send me a Xmas one with your
bunny slippers and tousled hair, lol.

Heather

Joan Archer said:
Get a picture of Heather, you'll be lucky <vbg>
Joan

Beauregard T. Shagnasty said:
Heather the Grinch? Are you green? ;-) [pictures, please...]

--
 
Heather said:
Beauregard T. Shagnasty said:
Heather the Grinch? Are you green? ;-) [pictures, please...]

Just my eyes, lol. Did you want an autographed one? Or a more
casual candid one.......rofl!!

Casual ... candid .. umm, yes please!

And I'll send you one of me.
 
Oh damn......now I have to send you mine.....chubby cheeks and all, sigh.
Hey, that is not a bad one of you.....better than the one with Noel. Maybe
he brings out the "worst" in us.....bwa ha ha.

Rushing to find Paintshop Pro and airbrush that sucker.......grin.

XX Heather
 
Beauregard T. Shagnasty said:
Heather said:
Beauregard T. Shagnasty said:
Heather the Grinch? Are you green? ;-) [pictures, please...]

Just my eyes, lol. Did you want an autographed one? Or a more
casual candid one.......rofl!!

Casual ... candid .. umm, yes please!

And I'll send you one of me.

Done.....I sent it to the *intentionally left blank space*......LOL.

Not on your life, sweet cheeks.......I take a horrible picture!! Maybe I
will send you one of our daughter......Slim Hips (aka Elayne) instead, grin.

HF
 
Back
Top