Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Internet Explorer 6 Hijacked

  • Please log in to reply
3 replies to this topic

#1 NoSkillzAndy


  • Members
  • 2 posts
  • Local time:04:49 AM

Posted 29 December 2007 - 08:54 PM

I just got back from a brief vacation to find that my Internet Explorer has been hijacked. I usually have very tight browser settings (ie. ActiveX completely off). I suspect one of my roommates changed the settings and accidentily downloaded some malware while I was gone, but that is besides the point. Here are the facts:

Running Windows XP Pro Service Pack 2 with Internet Explorer 6.029 (didn't like the new features of IE7)

When browsing in IE many otherwise legit links are now redirected to random shady sites. Finefinder.com seems to be a common theme.

I couldn't find any processes or programs that seemed out of the ordinary. Please help, I haven't had any problems like this before so I don't know which removal programs to use or what other methods to use.

Here's a list of processes that are running right now:

System Idle Process

BC AdBot (Login to Remove)


#2 boopme


    To Insanity and Beyond

  • Global Moderator
  • 73,416 posts
  • Gender:Male
  • Location:NJ USA
  • Local time:06:49 AM

Posted 29 December 2007 - 11:04 PM

Hello and welcome. What ANtivirus and Spyware tools do you have ? Have updated and scanned with them from safe Mode?
How to enter safe mode(XP)
Using the F8 Method

Restart your computer.
When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with a Windows XP Advanced Options menu.
Select the option for Safe Mode using the arrow keys.
Then press enter on your keyboard to boot into Safe Mode.

Please download and install SUPERAntiSypware Free Home Version
Double-click SUPERAntiSypware.exe and use the default settings for installation.
An icon will be created on your desktop. Double-click that icon to launch the program.
If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download them from HERE and unzip into the program's folder.)
Under the "Configuration and Preferences", click the Preferences... button.
Click the "General and Startup" tab, and under Start-up Options, make sure "Start SUPERAntiSpyware when Windows starts" box is unchecked.
Click the "Scanning Control" tab, and under Scanner Options, make sure the following are checked (leave all others unchecked):
Close browsers before scanning.
Scan for tracking cookies.
Terminate memory threats before quarantining.

Click the "Close" button to leave the control center screen and exit the program.
Do not run a scan just yet.
Reboot your computer in "Safe Mode"

Launch the program and back on the main screen, under "Scan for Harmful Software" click Scan your computer.
On the left, make sure you check C:\Fixed Drive.
On the right, under "Complete Scan", choose Perform Complete Scan and click "Next".
After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
Make sure everything has a checkmark next to it and click "Next".
A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
If asked if you want to reboot, click "Yes" and reboot normally.

To retrieve the removal information after reboot, launch SUPERAntispyware again.
Click Preferences, then click the Statistics/Logs tab.
Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
If there are several logs, click the current dated log and press View log.
A text file will open in your default text editor.
Please copy and paste the Scan Log results in your next reply.
Click Close to exit the program.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 NoSkillzAndy

  • Topic Starter

  • Members
  • 2 posts
  • Local time:04:49 AM

Posted 30 December 2007 - 03:11 PM

Thanks for the quick reply. I resolved the problem last night by using System Restore to go back to a point before I went on vacation. Everything works fine now. I'm going to have to give my roommate a hard time about messing with my computer though!

#4 quietman7


    Bleepin' Janitor

  • Global Moderator
  • 51,595 posts
  • Gender:Male
  • Location:Virginia, USA
  • Local time:06:49 AM

Posted 30 December 2007 - 05:05 PM

To protect yourself against malware and reduce the potential for re-infection, be sure to read:
"Simple and easy ways to keep your computer safe".
"How did I get infected?, With steps so it does not happen again!".
"Hardening Windows Security - Part 1" and "Hardening Windows Security - Part 2".
"IE Recommended Minimal Security Settings".

Safe surfing and have a malware free day.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users