Hijacked Browser Help

Status
Not open for further replies.
I can access some internet web pages but not many and many of my settings have been altered. Assuming its been hijacked although cant be certain. Norton, Adaware and CWshredder all turning out nothing and im begining to get a little frustrated. I realise im not supposed to post my log in the thread but im struggling to upload and "aaaaahhhhh!", Is there anyone out there that can help please.

Thanx Bex xxx
 
Hello and welcome to Techspot.

Boot into safe mode. See how HERE. http://www.bleepingcomputer.com/forums/tutorial61.html

Turn off system restore.(XP/ME only) See how HERE. http://www.bleepingcomputer.com/forums/tutorial56.html

In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE. http://www.bleepingcomputer.com/forums/tutorial62.html

Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

Click on processes tab and end process for(if there).

VTAgentReboot.exe

Close task manager.

Run HJT with no other programmes open. Have HJT fix the following, by placing a tick in the little box next to(if there).

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

O4 - Global Startup: VTAgentReboot.exe

Fix all 016-DPF entries, no matter what they are.

Click on the fix checked button.

Close HJT.

Locate and delete the following bold file(if there).

VTAgentReboot.exe

Reboot into normal mode and turn system restore back on.

Regards Howard :wave: :wave:
 
Thanx a lot Howard... it all seems a bit "technical" and im getting a lot of "are you sure you want to do this" messages. Whats going to happen if just 'fix' the files without rebooting etc? also do you need a wife? lol probably not as much as i need someone to fix all this :)
 
Can you be specific, about what "are you sure messages" you are getting?

The instructions I gave you are perfectly safe.

Regards Howard :)
 
Status
Not open for further replies.
Back