Some very devious hijacking "system performance advisory"

  • Thread starter Thread starter Quandon
  • Start date Start date
Q

Quandon

I suffered a major attack of hijacking yesterday, with a whole heap of problems,
and masses of files appearing.

I've run ad-aware, and some other spybot searches, and have cleaned everthing
up.

There is one remaining problem: Every five miniutes, an IExplorer window opens
with a fake dialog box headed "System Performance Advisory" it appears to have
three buttons and some links, but the whole image points to the same ad-server
address.

Each time I run ad-aware, I find a new ad-server cookie, and two registry
entries.

All running processes seem to be valid.

This happens all the time I'm connected, whether of not IExplore is running.

Since I don't suppose they went to all the trouble of writing this just for me,
I presume that others are affected as well.

Anyone here suffering, or know where the initiator is buried?

Quandon
 
Start>Run msconfig and look at Startup (and Services) items and disable. If
found, ALT+CTL+Del and end that process so it cannot add back to startup.

-Kent
 
Hi Quandon,

Be careful with these utilities, if you are unsure about an item,
consult the experts.

Download the utility CWshredder:
http://www.spywareinfo.com/~merijn/files/cwshredder.zip

Unzip - close *all* instances of IE & OE, hit the executable and
follow
the prompts.

You can also download Hijack This from here:

http://www.mjc1.com/files/merijn/hijackthis.exe

Go here:
http://mjc1.com/mirror/hjt/

For instructions on how to use it; you have to post the log it
produces so experts tell you what is good and what is malware


Try downloading, installing and updating the
spyware removers from the links below. Run both of them.

Ad-aware
http://www.lavasoftusa.com/support/download/

Spybot S&D
http://www.safer-networking.org/index.php?lang=en&page=download


If these don't correct the problem, then get yourself a copy of
BHODemon, available at
http://www.definitivesolutions.com/bhodemon.htm .

It does not need installing - simply unzip and run the EXE program. It
is easy to use. It will find the hijackware DLL files, and give you
the ability to disable them.

Hope this helps.
 
Back
Top