Rules
Terms of Use

Topic Options
#205226 - Wed Dec 10 2003 01:18 PM Hijacked
Jax Offline
Mainstay

Registered: Mon Jun 11 2001
Posts: 724
Loc: Okla
Hijacked
A few weeks ago my search page was hijacked by Gobal-finder. Managed to get is straightened out but it would just change back again. Then I would get the message on start up that iedll was corrupt.
Turns out the iedll is part of the program I guess, and ends up in as c:\window\iedll.exe. Delete stops the error message until the next boot. OK go to the msconfig and un click iedll in the start menu. That should do it. Wrong! It just redoes it again.
I have been fighting with this thing for weeks. Every time I reboot the message corrupted Iedll appears.
Search for iedll in C and there it is in windows as iedll.exe, delete and reboot it is gone,, until the next time.
After extensive research I finally deleted a string of supposedly related stuff from my registry this morning. Computer may never reboot again.
I don't pretend to know all the workings of a computer but it seems there can be all sorts of control devices placed on your computer with out you knowing about them, or knowing even how they work.
First Has anyone else had this problem with the iedll?

And What part does the registry play? How is it used by windows?
Jax

_________________________
Zebra

Top
#205227 - Wed Dec 10 2003 03:23 PM Re: Hijacked
tellywellies Offline
Forum Champion

Registered: Sat Apr 13 2002
Posts: 5473
Loc: South of England
From what I read it appears that Gobal-finder is just about the worst hijack to get rid of. Adaware and Spybot apparently have no effect on it.

It is possible to get rid of it, as you have done, by going into the Registry and deleting various keys and also some files. However, this can be somewhat of a slippery slope and lead to all sorts of troubles.

As an alternative to this, there is a tool called CWShredder that can be used. This is written by the creator of HijackThis, another anti-hijack tool. Reports say that CWShredder gets rid of Global-finder easily. There are a number of computer dedicated forums on the Internet discussing it's use.

This hijack takes advantage of ActiveX to install itself on your computer. Only Internet Explorer uses ActiveX. I guess that means I'm pretty safe from the hijack because I use Mozilla Firebird (sorry to take yet another opportunity to plug this excellent browser ).

Anyway, for Internet Explorer users, there is another tool that will help prevent further invasions of the Registry by hijackers. Check out RegistryProt

The Registry governs just about everything that happens on the computer. The files that make up The Registry are User.dat and System.dat. Regedit, which resides in the Windows directory, is used to edit these files. Do anything to your computer and it will be tracked by the Registry. Install a program or make changes to preferences and it will be recorded in the Registry. The Registry is somewhat the heart of the computer. It tells programs to start (including hijack ones) and if it faulters for any reason the effects will surely be seen on the screen.

*EDIT* Correction of product name.


Edited by tellywellies (Thu Dec 11 2003 12:06 AM)
_________________________
Error: Keyboard not attached. Press any key to continue..

Top
#205228 - Thu Dec 11 2003 10:26 PM Re: Hijacked
lothruin Offline
Multiloquent

Registered: Wed Nov 12 2003
Posts: 2165
Loc: Nebraska USA
Another excellent tool as called AdAware. Search for it on Google. I use it at home and at work. My browser was recently hijacked by another search tool and AdAware did the trick. Also, make sure your security patches for Microsoft IE are up to date. They've been working on ActiveX control changes for these patches.
_________________________
Goodbye Ruth & Betty, my beautiful grandmothers.
Betty Kuzara 1921 - April 5, 2008
Ruth Kellison 1925 - Dec 27, 2007

Top

Moderator:  flopsymopsy, ladymacb29