While following the instructions contained in Mike Healan's article, I discovered & removed a home page hijacker which does not appear documented yet. It places a search home page with filename sp.html in Local Setting/Temp, points all search & start pages to it and loads itself, apparently, using BHO %windir%/system32/lkgd.dll. I did not find this BHO in the list of all known BHO's maintained on this site. It keeps recreating the fake home page & resetting the start & search page entries after deletion. It also seems to prevent Windows Update from working under IE6 (but not IE5). The purpose seems to be to direct the user to a spyware removal site (which I have not visited for obvious reasons) using popups with a fake Microsoft signature situated at h**p://4bf65.ilxt.info.
It took me a while to figure it out but I must thank Mike Healan & the people who maintain this site for their guidance.
No replies to this topic
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users