Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: I Think I've Been Browser Hijacked .... Please Help  (Read 2863 times)

0 Members and 1 Guest are viewing this topic.

tomdogz

  • Guest
I Think I've Been Browser Hijacked .... Please Help
« on: December 02, 2008, 03:57:33 PM »
Ok, not brilliant with computers, but here goes.  I was on a website (nothing dodgy) and I had a pop-up get through my anti pop-up software.  Anyway, seconds later my Registry goes mad, telling me a change has been detected in Rundll32, and the name of the source is "weboyisatu."

So i set my blocker thing to automatically deny any changes, and run all my anti-viruses etc.  Found a few Trojans etc.

I think that i have found the .exe that it is, but I a not sure.

The files are in Rundll32, and are called 1) doriyubi  and 2) bevukeyo

Are these files I need to delete when I run msconfig???


Please help, the pop-up websites are starting to get really annoying.

Many thanks to anyone who can help...

evilfantasy

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Calm like a bomb
  • Thanked: 493
  • Experience: Experienced
  • OS: Windows 11
Re: I Think I've Been Browser Hijacked .... Please Help
« Reply #1 on: December 02, 2008, 04:26:11 PM »
Using msconfig to deal with malware isn't a good method. Msconfig is meant to be used for trouble shooting and nothing more. It is not a substitute for a startup manager either. Enable all stsrtups with msconfig and then follow the instructions here http://www.computerhope.com/forum/index.php/topic,46313.0.html

Post the 3 logs when complete.