September 06, 2002

Hijacked!

Yes, I have been hacked. Well, my computer here at home where I view my e-mail, anyway. I think it started with one of those SPAM e-mails that will auto-launch a new browser window. Then, the web page that gets loaded in the popup exploits a security hole in Internet Explorer that allows a Registry entry. This little line in the Registry subsequently sets your browser's home page and search page (most likely to a porno site) every time you reboot. It took me a few times to finally track this little bugger down. The one that I was infected with is called HTML/Oprad and I found other similiar exploits, Reg_Startpage.A and Trojan.Winreg.Start.

These trojans take advantage of security hole in Internet Explorer versions 4 and 5. Read the security bulletin and then download the Microsoft patch here.

If you think you've already been infected, search on Google using the keyword OPQFile. You'll find lots of tips on how to root that little annoyance out of your system.