phantomdesign
Tank
- Joined
- Sep 19, 2003
- Messages
- 2,863
- Reaction score
- 0
There appears that one of the advertisements at www.scifience.net/hl2 does some nasty work on your computer.
It modifies your registry so that...
It may do something else, but I cannot be sure. Basically it automatically sends you to that link, which has a crapload of popups. Easy fix? When you try to change your homepage, amazingly that feature has been disabled (woohoo!!!).
Have you been infected already?
Well, to alleviate some stress, download this simple 2mb file & the rest should be fairly easy to do.
ftp://ftp.download.com/pub/win95/utilities/aaw6181.exe
Here's what you need to mostly be concerned with:
Note to Moderators: You can move this thread if you must (I prefer you wait a day), but please leave a shadow in the HL2 discussion section.
It modifies your registry so that...
- It prevents you from changing your homepage
- It changes your homepage to http://default-homepage-network.com/start.cgi?new-hkcu (DO NOT CLICK LINK!!!)
It may do something else, but I cannot be sure. Basically it automatically sends you to that link, which has a crapload of popups. Easy fix? When you try to change your homepage, amazingly that feature has been disabled (woohoo!!!).
Have you been infected already?
Well, to alleviate some stress, download this simple 2mb file & the rest should be fairly easy to do.
ftp://ftp.download.com/pub/win95/utilities/aaw6181.exe
Here's what you need to mostly be concerned with:
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Bar.smartbotpro.net
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://server224.smartbotpro.net/7search/?new-hkcu"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Bar
Data : "http://server224.smartbotpro.net/7search/?new-hkcu"
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Bar.smartbotpro.net
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://server224.smartbotpro.net/7search/?new-hklm"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Bar
Data : "http://server224.smartbotpro.net/7search/?new-hklm"
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainStart Pagedefault-homepage-network.com
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://default-homepage-network.com/start.cgi?new-hklm"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "http://default-homepage-network.com/start.cgi?new-hklm"
Note to Moderators: You can move this thread if you must (I prefer you wait a day), but please leave a shadow in the HL2 discussion section.