Is this something new? Twice, one yesterday and again just now, my home page was automatically changed by some POS popup ad. I did a little digging around and discovered this is some BS browser hijacking.
My home page vanishes and my new home page is switched to an ad for some spyware remover. In addition, this program makes both my CD drives pop open and claims that is proof my system is not secured. WTF?
Where did this thing come from? I ran a virus scan and the PC is clean. I ran AdAware and I got this:
Started deep registry scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Bar.smartbotpro.net
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://server224.smartbotpro.net/7search/?hkcu"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Bar
Data : "http://server224.smartbotpro.net/7search/?hkcu"
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Bar.smartbotpro.net
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://server224.smartbotpro.net/7search/?hklm"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Bar
Data : "http://server224.smartbotpro.net/7search/?hklm"
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainStart Pagedefault-homepage-network.com
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://default-homepage-network.com/start.cgi?hkcu"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "http://default-homepage-network.com/start.cgi?hkcu"
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainStart Pagedefault-homepage-network.com
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://default-homepage-network.com/start.cgi?hklm"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "http://default-homepage-network.com/start.cgi?hklm"
Mean anything to anyone?
Thanks!
My home page vanishes and my new home page is switched to an ad for some spyware remover. In addition, this program makes both my CD drives pop open and claims that is proof my system is not secured. WTF?
Where did this thing come from? I ran a virus scan and the PC is clean. I ran AdAware and I got this:
Started deep registry scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Bar.smartbotpro.net
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://server224.smartbotpro.net/7search/?hkcu"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Bar
Data : "http://server224.smartbotpro.net/7search/?hkcu"
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Bar.smartbotpro.net
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://server224.smartbotpro.net/7search/?hklm"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Bar
Data : "http://server224.smartbotpro.net/7search/?hklm"
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainStart Pagedefault-homepage-network.com
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://default-homepage-network.com/start.cgi?hkcu"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "http://default-homepage-network.com/start.cgi?hkcu"
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainStart Pagedefault-homepage-network.com
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://default-homepage-network.com/start.cgi?hklm"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "http://default-homepage-network.com/start.cgi?hklm"
Mean anything to anyone?
Thanks!