Sharesmagazine
 Home   Log In   Register   Our Services   My Account   Contact   Help 
 Stockwatch   Level 2   Portfolio   Charts   Share Price   Awards   Market Scan   Videos   Broker Notes   Director Deals   Traders' Room 
 Funds   Trades   Terminal   Alerts   Heatmaps   News   Indices   Forward Diary   Forex Prices   Shares Magazine   Investors' Room 
 CFDs   Shares   SIPPs   ISAs   Forex   ETFs   Comparison Tables   Spread Betting 
You are NOT currently logged in
 
Register now or login to post to this thread.

PC & MAC CLINIC - On line problem solving. (CPU)     

Crocodile - 16 Dec 2002 03:59

Mega Bucks - 06 Jun 2004 16:05 - 1785 of 11003

afternoon campers,

have a trojan virus thingy in C:\windows\system32\config\services.exe

norton antivurus picked it up but cannot do any thing because access is denied :-( have tried renaming but still no joy has anyone any ideas please!!!!

do i delete the file if so how???

Rick...

Spaceman - 06 Jun 2004 17:19 - 1786 of 11003

MB, more details please. What virus is it, what Operating System. There is probably a stinger that will clean it and/or you might have to start in safe mode.

Mega Bucks - 06 Jun 2004 22:17 - 1787 of 11003

Tim i think i may have sorted it,if there are problems still will get back to you!!

Many thanks...

Mega...

dotel - 07 Jun 2004 16:08 - 1788 of 11003

Got a new XP jobbie here at work - and since the bank holiday weekend, something seems to have installed itself - no matter how many times I re-set the homepage and delete the porn sites which have also plonked themselves in my favs, they all just keep coming back..

When I log into IE I get Search Everything, but in the address bar a funny square (i.e. not explorer) and C:\WINDOWS\system32\hp.uti

Checked the gateway thingy and firewall and firewall monitor are both active.

Oh 'eck

Spaceman - 07 Jun 2004 16:14 - 1789 of 11003

dotel, sounds likea a hijack, have you got adaware or Spybot Search and Destroy?
if so run them if not get the, both free !

dotel - 07 Jun 2004 16:20 - 1790 of 11003

not on here, Space..how did it get past the firewall then?

Spaceman - 07 Jun 2004 16:26 - 1791 of 11003

dotel,
firewall doesnt stop stuff being downloaded, its stops (or tries to stop)poeple and things trying to access your machine.

Symptopms are definately hijack, what page is homepage getting set to? most common hijack is coolwebsearch.

dotel - 07 Jun 2004 16:28 - 1792 of 11003

well it was supposed to be msn.co.uk, but it keeps defaulting to Search Everything - Microsoft Internet Explorer and then with that odd C windows thingy

Spaceman - 07 Jun 2004 16:30 - 1793 of 11003

d, can you post the actual url eg www.zzzz.com. Shoudl be fairly easy to get rid of? are you dial up? have you got any teenage male kids?

dotel - 07 Jun 2004 16:38 - 1794 of 11003

only 3 users here - and 2 of them claim innocence (I'm no 3!) address is as per post 1787 - can't say what the funny square in front of the C: bit is though, just not the explorer logo...it's really odd - it isn't a proper address is it?

The favs, however are gotosex4all.com, webanalsex.com, allcrazyporn.com, thestas.com and spyorgy.net

Spaceman - 07 Jun 2004 16:43 - 1795 of 11003

dotel,

OK I suspect one of them isnt being completely truthful ;-) and its probably a man ;-)

But who knows these hijacks keep trying to worm their way into PCs, however in my experience they are nearly always caused by surfing porn sites to warez etc sites (sites containg software keys etc).

Does the info in the following link look familiar?http://forums.spywareinfo.com/index.php?showtopic=3795&st=0entry16637

Kayak - 07 Jun 2004 16:43 - 1796 of 11003

dotel, thanks for the links :-)

These hijacks are pretty lethal. I got one the other night just searching for something. Some web pages are loaded with them, and you don't have to be browsing for sex sites to get one. Unfortunately they are loaded into your browser as a "browser helper object" without even a warning box, so you won't know you've loaded one until the next time you start up IE. No doubt that will be fixed in a subsequent update of IE but for the moment there is no protection. Some of them even disable anti-hijack software. The only ideas I found were to disable Java and Javascript, the only problem with that being that half the pages on the Web would stop working, including AM of course.

dotel - 07 Jun 2004 16:46 - 1797 of 11003

Just went to options, space - sorry for being so thick - here's the homepage address


http://solongas.com/hp.htm?id=9

dotel - 07 Jun 2004 16:50 - 1798 of 11003

Funny you should say that, space - I know who contracted this...by doing just what K suggests - it's him indoors, he only uses my computer to search for stuff. Also, at the top of the page is a spyware removal thingy, like you say, K

Spaceman - 07 Jun 2004 16:52 - 1799 of 11003

dotel, the link I posted contains info about removing this hijack, its not one I have seen before so I cant vouch for the instructions but the site they are on is very good.

Does that help ??

dotel - 07 Jun 2004 16:55 - 1800 of 11003

Still can't get it up

dotel - 07 Jun 2004 17:02 - 1801 of 11003

It took ages - threw exlporer off - but now I get *this page cannot be displayed*, space

Ah success! Thanks space, will have a play

dotel - 07 Jun 2004 17:13 - 1802 of 11003

Is it a coincidence when I went to put it into favs that it's come up as SWI Forums - CWS removal-http--solongas.com ?

Spaceman - 07 Jun 2004 17:18 - 1803 of 11003

Sorry, dotel, I was speaking to my nephew on the phone. That link comes from a site with a lot of info about hijacks. CWS (coolwebsearch was the first major hijack and many others are derived from it).

I didnt understand 1799 and 1800 above???

dotel - 07 Jun 2004 17:21 - 1804 of 11003

Couldn't get the page up to begin with, Space
Register now or login to post to this thread.