I've Been Hijacked, Again
|
So, after 4 years or so of being error free and thinking I was protected (I do, after all run a web site devoted to teaching people how to protect themselves against Identity Theft), my laptop has been hijacked. I thought other people might be interested in my process for getting rid of stuff from my computer. So I've included helpful links to the free software I use in this post. Here's how my computer got hijacked: Well, I wanted to check out their site first (otherwise I'd be sending you along to junk that could infect your computer...) So I clicked... landed on the web site, and WHAMMO! Spybot Resident (free software I use in the background on my computer) starts going CRAZY and blocking tons of stuff that's trying to change my system registry. I couldn't believe how quickly it happened, but with all the stuff hitting my computer at the same time, something got through. (Actually, a lot of stuff got through.) So, I've run: I've run ComboFix in SafeMode and Spybot in SafeMode. Every program has gotten rid of a variety of stuff running on my laptop, which is a good thing. However, there's still something running. I finally resulted to HiJackThis (NOTE: do not use unless you know what you're doing or will post to a web site where someone does know what they're doing), which I ran in normal mode, and then in safe mode. There is a process I can't block or stop from running which I can't figure out. The reason I know something is still running is because Internet Explorer and Firefox both take a LONG time to open, and about every 6th click on a search result from Google lands me on a page that's not actually what Google is showing. I posted the HJT log to www.BleepingComputer.com, but so far no response to my post. Here's what I've got: 4/15/2009 9:53:14 AM Denied (based on user blacklist) value "Qbihasamoqixate" (new data: "rundll32.exe "C:\WINDOWS\ifizuhifucize.dll",e") added in System Startup global entry! I denied the process for ifizuhifucize.dll, but it's running and I don't know how to block/remove it (or what it's doing). Anyone have any suggestions? This is a highly basic and mildly boring, but good overview of how spyware ends up on your computer.
|
Comments on I've Been Hijacked, Again
« Spend a Few Minutes at Government Registry.org, Not Hours at the Courthouse | Main | We Want Your Opinion »


