Pixalo Photography Community  

Go Back   Pixalo Photography Community > Photography Forums > Computer hardware, software, networking and internet

Computer hardware, software, networking and internet Discuss JUPK Highjacker solution...Hiya all, I have come accross a rather nasty browser hijacker in the last 24 hours which not only takes ...

Welcome to the Pixalo Photography Community. As a Guest you are free to browse the site, but see what extras you get as a Member here.


Expired Thread The thread "JUPK Highjacker solution" has not received any replies for 18 months. It has been automatically closed as a result. Please start a new thread on the topic if the information in this thread is not sufficient.

Reply
 
LinkBack Thread Tools Display Modes
Old 01-12-2006, 11:51   #1 (permalink)
Rep Point Winner 07
 
Gary Bagshawe's Avatar
 
Join Date: Apr 2005
Location: Sheffield UK
Posts: 2,248
Gary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of light
Gary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of light

Image editing O.K.
User's Gallery
Users Camera Equipment List
JUPK Highjacker solution

Hiya all, I have come accross a rather nasty browser hijacker in the last 24 hours which not only takes over your browser but will not let you set your home page back to what you want. when you type in websites to the address bar it just goes to what it wants which are some very nasty sites. it gets all it's stuff seemingly from jupk.whatever.
I have run all the spyware malware software in safemode and emptied temp files etc but this is a real bad one.
Basically it hijacks your dns server which means that you cant even get your e-mail through outlook/express.
After much searching, swearing and banging head against wall the solution is as follows.

Go to control panel
network connections
Then right click LAN, internet connections, properties.
then click in the box which says "obtain DNS server automatically"

Hey presto fixed.
__________________

Gary Bagshawe is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 01-12-2006, 12:46   #2 (permalink)
Pixalo Crew
 
stepheno's Avatar
 
Join Date: Jul 2005
Posts: 6,980
stepheno is a jewel in the rough
stepheno is a jewel in the roughstepheno is a jewel in the rough

Image editing O.K.
User's Gallery
Users Camera Equipment List
Re: JUPK Highjacker solution

Thanks for posting, Gary I assume you found and exterminated the culprit?
stepheno is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 01-12-2006, 13:09   #3 (permalink)
Rep Point Winner 07
 
Gary Bagshawe's Avatar
 
Join Date: Apr 2005
Location: Sheffield UK
Posts: 2,248
Gary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of light
Gary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of light

Image editing O.K.
User's Gallery
Users Camera Equipment List
Re: JUPK Highjacker solution

I cant find any reference to it on my laptop anywhere but after doing the above all seems to be fine. There a a fair number of pro it people who are having the same problem with this HJ and there are not many people who have found a solution at all to the problem. However the above seems to work fine and as we speak I am downloading all the latest windows security updates and installing them. It really is a bad one as you cant even search for stuff on the web after infection as it just redirects to some really horrible stuff. I found the solution by using the aol browser. It had even taken over my version of firefox2 and displayed the same problems.
Gary Bagshawe is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 01-12-2006, 13:51   #4 (permalink)
Pixalo Crew
 
stepheno's Avatar
 
Join Date: Jul 2005
Posts: 6,980
stepheno is a jewel in the rough
stepheno is a jewel in the roughstepheno is a jewel in the rough

Image editing O.K.
User's Gallery
Users Camera Equipment List
Re: JUPK Highjacker solution

Thanks Gary, worth a rep or two that just don't send me any emails
stepheno is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 01-12-2006, 16:41   #5 (permalink)
Feet under the table
 
orangepeel's Avatar
 
Join Date: Mar 2006
Location: Edinburgh
Posts: 1,507
orangepeel is a glorious beacon of lightorangepeel is a glorious beacon of light
orangepeel is a glorious beacon of lightorangepeel is a glorious beacon of lightorangepeel is a glorious beacon of lightorangepeel is a glorious beacon of lightorangepeel is a glorious beacon of lightorangepeel is a glorious beacon of lightorangepeel is a glorious beacon of lightorangepeel is a glorious beacon of lightorangepeel is a glorious beacon of light

Image editing O.K.
User's Gallery
Users Camera Equipment List
Re: JUPK Highjacker solution

Try hijackthis. Awesome wee program. I use it all the time to cleanup peoples IE installs. (I'm assuming it was IE that was hijacked)

Run it, do a scan, tick all the BHO entries the do the cleanup selected items.

|MG| Free Download - HijackThis 1.99.1


As for the LAN thing - that's a seperate issue. Albeit caused by the same spyware. Hijacked DNS can't stop you changing the default homepage. Although it could redirect any DNS lookups to different servers.
orangepeel is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 01-12-2006, 17:01   #6 (permalink)
Rep Point Winner 07
 
Gary Bagshawe's Avatar
 
Join Date: Apr 2005
Location: Sheffield UK
Posts: 2,248
Gary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of light
Gary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of lightGary Bagshawe is a glorious beacon of light

Image editing O.K.
User's Gallery
Users Camera Equipment List
Re: JUPK Highjacker solution

Quote:
Originally Posted by orangepeel View Post
Try hijackthis. Awesome wee program. I use it all the time to cleanup peoples IE installs. (I'm assuming it was IE that was hijacked)

Run it, do a scan, tick all the BHO entries the do the cleanup selected items.

|MG| Free Download - HijackThis 1.99.1


As for the LAN thing - that's a seperate issue. Albeit caused by the same spyware. Hijacked DNS can't stop you changing the default homepage. Although it could redirect any DNS lookups to different servers.
highjack this, adaware, spybot search and destroy plus many other well known and proven detection/removal systems do not find this one. even after downloading the latest updates
Gary Bagshawe is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 04-12-2006, 15:55   #7 (permalink)
New here
 
Join Date: Nov 2006
Location: Derbyshire
Posts: 43
Nathan will become famous soon enoughNathan will become famous soon enoughNathan will become famous soon enoughNathan will become famous soon enoughNathan will become famous soon enough

Image editing O.K.
User's Gallery
Users Camera Equipment List
Re: JUPK Highjacker solution

Guys,

The only problem with the jupk.com infection is that it's INCREDIBLY polymorphic. It also modifies its file size and name after every reboot in an attempt to sidestep heuristic tools.

The DNS change only works for the initial release of this malware. Its since been fixed so that if you're hit by the newer version you're out of luck!

Our researchers are currently looking into it in more detail but unfortunately there's potential for it to have a rootkit component which isn't removed by the HJT and DNS clean up. The use of the rootkit is to enable it to hide itself from the common antivirus software on the market. What else it does with it we're still investigating.

Personally I would recommend caution at the moment. Oh and the installation of a decent Security package!
__________________
Nathan.
---------
Xbox Live: NathanJT
QOTM: "Religious wars are basically people fighting over who has the best imaginary friend!"
Nathan is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Expired Thread The thread "JUPK Highjacker solution" has not received any replies for 18 months. It has been automatically closed as a result. Please start a new thread on the topic if the information in this thread is not sufficient.


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT +1. The time now is 23:29.


vBulletin Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
ReviewPost & PhotoPost vB3 Enhanced, Copyright 2003-2006 All Enthusiast, Inc.
SEO by vBSEO 3.2.0
Copyright © 2006 - 2008 Pixalo.com

Bad Credit Mortgages | Secured Loans | Record Internet Radio with Tags | MPAA | Free Ringtones

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98