Unexpected changes to Internet Explorer, unauthorized downloads and pop-ups
An increasing risk of web surfing or downloading freesoftware is picking up rogue software that makes unauthorized changes to your settings in Internet Explorer or results in annoying or alarming pop-up windows.
If the problem is not the installation of unauthorized software, but instead is the more ordinary annoying advertising popup window see Eureka! document 19038 — Control of pop-up windows. For performance and other operating system problems see the list of Operating System documents. Also make sure that the changes are not merely the result of changes with I.E. 6 See Eureka! document 19044 — New features of Internet Explorer 6.
Because these problems are primarily the result of non-work related activity PeopleSoft resources will focus only on any related security issues, but not on resolving merely annoying behavior. If the solutions provided here are not sufficient then the resolution is to rebuild the machine and use more care in the future.
Note: Completely cleaning the machine of the problem may take a couple hours of hard work, and may include repeating some steps. Your alternative is to submit the machine for a rebuild. Because these problem programs change rapidly these instructions are generic and designed to account for the most stubborn and difficult to remove of the rogue software.
Quicklist
Close all programs. Print out these instructions, and close Internet Explorer.
End suspcious tasks and processes.
If you have Internet Explorer 6 disable third-party browser extensions
Delete temporary Internet files and cookies
Attempt to terminate the program in Task Manger
Check for viruses
Attempt to uninstall the program.
Search for contaminated files or folders.
Check your connections settings
Reset the desired option
Call TSO for help with cleaning the registry.
These steps are not the solutions, but they are necessary for the solutions to work
Open only the solution software you need e.g. Norton AntiVirus. Then be sure to close it before attempting the next solution. That includes closing Windows Explorer, Internet Explorer, Lotus Notes, Notepad etc.
Check the title bars of any pop-up windows, the title bar of menus and windows to try to identify the name of the program that is causing the problem. You can often find out the URL of the problem pop-up or rogue software by checking page properties as follows:
- Click once in the page to make sure it is selected.
- Right-click.
- Select Properties.
- In the middle of the Properties window you will see an entry for Address: (URL)
The website doxdesk.com may help identify the rogue program.
Check this list of known rogue programs. If you don't find it there, check the list of start-up applications on Pacman's Portal.
These links are to help you identify the problem. Do not assume the fixes they supply are safe and valid for our systems. Downloading any of the suggested solutions from those sites may violate PeopleSoft policy. Contact Technical Support Operations for assistance with any solutions involving the registry.
See Eureka! document 16093 — How to clear the cache in Internet Explorer and 19012 — How to find and delete cookies in Internet Explorer
If you think you have identified the name of the program causing the problem you should attempt to disable it before starting the removal process. The rogue program may appear in the Task or Processes list of Task Manger. Try to terminate the task or process before taking further steps to remove it. Eureka! document 69001 — What is this process? What does this process do? lists many of the processes you are likely to find that are legitimate. Ending the wrong process in Task Manager might cause a freeze up or force a reboot, but its unlikely to cause permanent damage.
To terminate a program in Task Manger:
Press {CTRL}+{ALT}+{DEL}
Select Task Manager
On the Applications tab check the Task list to see if the rogue software appears.
Click once on the entry you want to stop.
Click End Task
Click on the Processes tab.
Click on the column heading " Image Name" to put the processes in alphabetical order
Look for an entry that appears to be from the rogue software. Click on the icon to see a "clean" TaskManager with lots of "stuff" in it, none of it rogue.
If you don't recogonize a processes as legitimate you can try stopping it.
Click once on the entry you want to stop.
Click End Process
The applications that take over your home page or search functions are "Browser Helper Objects". There are some you might choose to use, such as the one provided by Google. By default third-party browser extensions are enabled. Disabling this feature will prevent some unwanted extensions from taking over. Effectively resolving your unexpected changes is made easier in I.E. 6 which provides an easy means for disabling these applications.
- Close all instances of Internet Explorer, click Start, point to Settings, and then click Control Panel.
- Double-click Internet Options.
- Click the Advanced tab.
- Under Browsing, click to clear the Enable third-party browser extensions (requires restart) check box.
- Restart Internet Explorer.
Use your AntiVirus softare to . See Eureka! document 15036 — How to launch AntiVirus software.
2. Attempt to uninstall the program.
If you have been able to identify the name of the problem program attempt to uninstall it. See Eureka! document 69004 — How to uninstall and install software. In some cases this step is sufficient. Sometimes you will be re-routed to the originator's web site for an uninstall. Although the obvious features of the program are removed with an originator's uninstall I would not trust it to remove components that send information back to the originator. Carefully search your computer for any remaining components.
Make sure your view settings will show hidden files and file extensions. See Eureka! document 69051 — Show hidden files in Windows Explorer and My Computer
Run a search on your hard drive for any files with names that appear to be related to the rogue software.
That may not always be identical to the name of the rogue software. For example, Virtual Bouncer files may start with "Vbouncer."
Be careful in deciding what to delete. Some files can obviously be deleted e.g. a file with "xupiter" in the name has no legitimate use on your machine. Other files, however, may have names similar to legitimate files and should be deleted only after ensuring the file is not legitimate.
Run a search on your hard drive for any files ending with *.hta or *.js.
If you find any open them in Notepad. Look for references to the rogue software, e.g. the URLs that you have been hijacked to. Delete those references.
To open the file in Notepad:
- Right click the file.
- Select Open With ....
- Select "Notepad" from the list, or select Choose Program ... then select Notepad from the application list that opens.
Also find and delete all *.tmp files on your drive; some of them may contain malicious code (for e.g. browser hijacks or malware (re)installations). Besides, deleting *.tmp files doesn't hurt anything.
You may also want to search your hard disk for files that may have been used by the virus or code in the form of a malicious attack and delete these files. For example, files named Rad*.tmp (where * is a random set of letters and numbers), any files containing "regedit" or ".reg" (for example, a file containing "C:\Windows\regedit.exe/s C\Windows\System\radB9819.tmp"), or Windows.vbs are known to be associated with certain viruses.
You should have a limited number of items in your Startup folder. The following are OK to leave in the Startup folders: Connected Taskbar Icon, Sametime Connect, Push Client, PSVer, Microsoft Office, Install Pending Files. Any other items should be removed from the Startup folders, unless you are positive they belong there. Deleting items from the startup folder does not delete the program, it deletes the reference or shortcut to the program. If you later determine it is safe you can always drag a short cut back into the Startup folder.
- Click Start, then Programs, then Startup.
- If you need to remove a program from the Startup folder:
- Right click the program shortcut.
- Select delete.
- Confirm the delete.
Note: These changes are being made via Control Panel and with Internet Explorer closed to best improve the chances that the changes will be successful.
- Click on your Start button.
- Select Settings, then Control Panel.
- Double-click on the Internet Options icon to open it.
- On the Connections tab
- Under "Local Area Network" click on the LAN Settings ... button.
- Under "Automatic configuration" the Automatically detect settings box should be checked. If it is not checked click in the box to check it.
- Under "Proxy server" the box next to Use a proxy server should not be checked. If it is checked click in the box to uncheck it.
If there is an address in the Address: box leave it there.- Select OK, then OK to finish your changes.
- Restart your computer, and then restart Internet Explorer.
Note: These changes are being made via Control Panel and with Internet Explorer closed to best improve the chances that the changes will be successful.
A. For example, to restore the search engine in Internet Explorer:
- Click on your Start button.
- Select Settings, then Control Panel.
- Double-click on the Internet Options icon to open it.
- On the Programs tab click on Reset Web Settings
- Check "Also reset my home page." That will install the Microsoft home page, not PeopleSoft, but you can change this later.
- Select Yes
- Restart your computer, and then restart Internet Explorer.
- If that does not work try the steps in Eureka! document 19045 — How to change your Internet Explorer search engine or customize your search settings
B. For example, to set your Home page in Internet Explorer:
- Click on your Start button.
- Select Settings, then Control Panel.
- Double-click on the Internet Options icon to open it.
- On the General tab, under Home page is an address box.
- If you want to open to the browser to Planet use http://planet.peoplesoft.com, otherwise use the URL of the page you want, or click on the "Use Blank" button.
- Click on OK.
- Restart your computer, and then restart Internet Explorer. If the issue is resolved, do not follow the remaining steps.
Frequently there will be registry changes made that will restore the program when you reboot. If that occurs contact Technical Support Operations for assistance in removing the program from the registry . Submit a NorthStar ticket, include the steps you have tried, and the results. Identify a good time to work with the analyst, who may use remote tools to work on your computer. Set aside at least 30 minutes for this work.
Rogue software is any software that appears on your machine by less than honorable means. It might have mislead you into giving permission, it might have installed without any semblance of permission. Various names are used to reference rogue software including parasites, spyware, adware, trojan, ... Adware simply pops up advertising, a mere annoyance. Spyware sends back to the originator information from your machine. Hijackers may take over a function and re-route you to their site. Certain parasites may acutally use processing time on your computer to complete tasks for the originator. http://www.ciac.org/ciac/techbull/CIACTech02-004.shtml
When you start Internet Explorer your default startup page (the Web page that your browser automatically opens to at startup) may be unexpectedly changed. Or you may get a pop-up box warning you of "spyware". You shouldn't have anything on your machine that will automatically detect it and pop-up with such a message. There is, however, spyware that masquerades as a spyware detector and pops up with such warnings or requests for registration etc. (Virtual Bouncer).
Most of these will not be detected by Norton AntiVirus because you have given permission to load them, even in you didn't intend to do so. The "permission" most often occurs when a person responds mechanically to a message either believing they already know what it says or failing to read it. Authors of these programs write messages that appear to be standard or bury the permission in a license agreement for another software or service. Did you install the "free" version of RealPlayer (AKA Real One Player)? Congratulations, you also agreed to the installation of adware. The adware will connect to its homesite and deliver pop-ups to you even if you have your browser closed. Be careful what you click. Read it. Understand it.
Do not download tools from the Internet to try to resolve or prevent these kind of problems. Some of the available software is of beneficial intent, but some are malicious or intrusive programs. Even the well-known "legitimate" tools typically come with a waiver of liability absolving the author of any responsibility for harm to your machine. This is not acceptable in the business environment. Software also should be tested for compatibility with business needs, and appropriate security before installation. Many of our PeopleSoft applications rely on scripts, cookies, popups and similar techniques to process information. It is likely that downloaded software intended to block these techniques will cause problems with our web based software. Furthermore, if you install software that results in a security compromise the consequences could be very serious, don't do it.
The difficulty in removing the various programs is that they have so many means of self preservation. An application can consist
of multiple executable files (programs). So the one referenced in the registry might be "runner.exe" (this is entirely made up!) then there is another called "watcher.exe" (also made up) that has a copy of "runner.exe" And watcher's job is simply to watch and see if runner is deleted. If it is the watcher spits out a new copy. The program may also reload if there is a reference to a URL in the registry. The program may also reload if it is running as a process and detects a removal attempt.
Merely removing the program reference in the registry will work some of the time. The program will still be on your drive. Depending upon how "polite" it is it main remain there without ever causing you trouble again. Or it may be reactivated by visting a particular web site (not necessarily the same one as you got it from). Or it may be reactived merely by opening your browser.
Manual removal is tedious but should you trust an uninstall provided by the same company that was so rude in their original install? If a company is low enough to try to trick you or hide its intentions then their "uninstall" is suspect. If a company used subtrefuge to install their wares then likely the only thing "uninstalled" will be the thing you can see, but the rest of the
activity may continue.
List of known rogue programs, files and folders: To search this list press {
Ctrl}+{
f} or from the menu bar select
E
dit, then
F
ind (on this page)....
'fsg_
Alexa
Aureate/Radiate
Blazing Logic
C2Media
CMEII
Comet Cursor
Commonname
Conducent Timesink
Coolwebsearch
Cybersearch
Cydoor
Date Manager
eZula
Flashpoint
Flashtrack
Flyswat
GAIN
Gator
Gator eWallet
GMT
GoHip!
Hotbar
ISTbar
KaZaa Toptext
Lions Pride Enterprises
Lop
Mattel Brodcast
Morpheus
MySearch
NewDotNet
Offer Companion
OrbitUpdate
OrbitView
Passthison
PDP
Precision Time
Realplayer
SecondPower
Songspy
SQConfigChecker
SQUpdatesChecker
Sureseeker
Transponder
Trek Blue
Trickler
Tsadbot
VX2 RespondMiter
VBouncer
Virtual Bouncer
Web3000
Webcombo
WebDM
WebHancer
WebPT
XupiterCfgLoader
XupiterStartup
Check your temporary internet settings for any of the following URLs known to distribute rogueware:
...bonzi.com
...cometsystems.com
...commonname.com
...cool-downloads.com
...Coolwebsearch.com
...date-manager.com
...friend-greeting.com
...friendgreetings.com
...gator.com
...gatoradvertisinginformationnetwork.com
...gatorcorporation.com
...offercompanion.com
...permissionmedia.com
...precision-time.com
...shopnav.com
...websearch.com
...xpsn.com
...xupiter.com
Check this list of software known to bundle rogue software:
Real Player
Created by the PeopleSoft Knowledge Management Team.
Copyright © 2003
All rights reserved.
Created: db 03/21/2003
Revised: db 10/16/2003