![]() |
|
|||||||
| Computer hardware, software, networking and internet Discuss JUPK Highjacker solution...Hiya all, I have come accross a rather nasty browser hijacker in the last 24 hours which not only takes ... |
|
Welcome to the Pixalo Photography Community. As a Guest you are free to browse the site, but see what extras you get as a Member here.
|
|
|
![]() |
The thread "JUPK Highjacker solution" has not received any replies for 18 months. It has been automatically closed as a result. Please start a new thread on the topic if the information in this thread is not sufficient. |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|
#1 (permalink) |
|
Rep Point Winner 07
Join Date: Apr 2005
Location: Sheffield UK
Posts: 2,248
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
JUPK Highjacker solution
Hiya all, I have come accross a rather nasty browser hijacker in the last 24 hours which not only takes over your browser but will not let you set your home page back to what you want. when you type in websites to the address bar it just goes to what it wants which are some very nasty sites. it gets all it's stuff seemingly from jupk.whatever.
I have run all the spyware malware software in safemode and emptied temp files etc but this is a real bad one. Basically it hijacks your dns server which means that you cant even get your e-mail through outlook/express. After much searching, swearing and banging head against wall the solution is as follows. Go to control panel network connections Then right click LAN, internet connections, properties. then click in the box which says "obtain DNS server automatically" Hey presto fixed.
|
|
|
|
|
|
|
|
#2 (permalink) |
|
Pixalo Crew
Join Date: Jul 2005
Posts: 6,980
![]() ![]() ![]() |
Re: JUPK Highjacker solution
Thanks for posting, Gary
|
|
|
|
|
|
#3 (permalink) |
|
Rep Point Winner 07
Join Date: Apr 2005
Location: Sheffield UK
Posts: 2,248
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Re: JUPK Highjacker solution
I cant find any reference to it on my laptop anywhere but after doing the above all seems to be fine. There a a fair number of pro it people who are having the same problem with this HJ and there are not many people who have found a solution at all to the problem. However the above seems to work fine and as we speak I am downloading all the latest windows security updates and installing them. It really is a bad one as you cant even search for stuff on the web after infection as it just redirects to some really horrible stuff. I found the solution by using the aol browser. It had even taken over my version of firefox2 and displayed the same problems.
|
|
|
|
|
|
#4 (permalink) |
|
Pixalo Crew
Join Date: Jul 2005
Posts: 6,980
![]() ![]() ![]() |
Re: JUPK Highjacker solution
Thanks Gary, worth a rep or two that
|
|
|
|
|
|
#5 (permalink) |
|
Feet under the table
Join Date: Mar 2006
Location: Edinburgh
Posts: 1,507
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Re: JUPK Highjacker solution
Try hijackthis. Awesome wee program. I use it all the time to cleanup peoples IE installs. (I'm assuming it was IE that was hijacked)
Run it, do a scan, tick all the BHO entries the do the cleanup selected items. |MG| Free Download - HijackThis 1.99.1 As for the LAN thing - that's a seperate issue. Albeit caused by the same spyware. Hijacked DNS can't stop you changing the default homepage. Although it could redirect any DNS lookups to different servers. |
|
|
|
|
|
#6 (permalink) | |
|
Rep Point Winner 07
Join Date: Apr 2005
Location: Sheffield UK
Posts: 2,248
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Re: JUPK Highjacker solution
Quote:
|
|
|
|
|
|
|
#7 (permalink) |
|
New here
Join Date: Nov 2006
Location: Derbyshire
Posts: 43
![]() ![]() ![]() ![]() ![]() |
Re: JUPK Highjacker solution
Guys,
The only problem with the jupk.com infection is that it's INCREDIBLY polymorphic. It also modifies its file size and name after every reboot in an attempt to sidestep heuristic tools. The DNS change only works for the initial release of this malware. Its since been fixed so that if you're hit by the newer version you're out of luck! Our researchers are currently looking into it in more detail but unfortunately there's potential for it to have a rootkit component which isn't removed by the HJT and DNS clean up. The use of the rootkit is to enable it to hide itself from the common antivirus software on the market. What else it does with it we're still investigating. Personally I would recommend caution at the moment. Oh and the installation of a decent Security package!
__________________
Nathan. --------- Xbox Live: NathanJT QOTM: "Religious wars are basically people fighting over who has the best imaginary friend!" |
|
|
|
|
|
![]() |
![]() |
The thread "JUPK Highjacker solution" has not received any replies for 18 months. It has been automatically closed as a result. Please start a new thread on the topic if the information in this thread is not sufficient. |
| Thread Tools | |
| Display Modes | |
|
|