Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Computer problems: Last few days, constant browser hijacking

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU
 
Mike 03 Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:11 PM
Original message
Computer problems: Last few days, constant browser hijacking
I have Trend Microsystems anti-virus software and also used Microsoft's live online scan last night.
My firewalls are activated, I supposedly have top-level security, but I'm getting constant new infections of programs that are redirecting links I click on from Google (not sure about whether this would apply to other links).

It's driving me nuts. It seems like my computer gets about five to twelve every couple of hours and while my Trend Microsystems program can clean them after-the-fact, it is not preventing them, and none of the updates (and I'm updating my virus protection software constantly now) seem to do anything to help this situation.

Anybody else having this? It's to the point now where it's almost useless to try to use my computer for more than ten minutes at a time without running a new Scan & Clean operation.

Printer Friendly | Permalink |  | Top
NJmaverick Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:13 PM
Response to Original message
1. Follow the instructions I gave out here
Printer Friendly | Permalink |  | Top
 
Mike 03 Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:20 PM
Response to Reply #1
9. Thank you! I will definitely check this out. NT
Printer Friendly | Permalink |  | Top
 
Mike 03 Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:54 PM
Response to Reply #1
19. This seems to have helped. I downloaded just the first one, so far, because I'm not sure
whether these programs cost money or not. It found five items that my other softwear missed entirely and seemed to fix them.

Is this program worth buying, in your opinion? I hate to use it for free and take advantage.

Is Trend Micro not a very good system?
Printer Friendly | Permalink |  | Top
 
NJmaverick Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:58 PM
Response to Reply #19
20. The free versions work just fine for me
I have fixed many an infected computer with this duo
Printer Friendly | Permalink |  | Top
 
BrklynLiberal Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:13 PM
Response to Original message
2. Same thing happening to me. I put in AVG, Spybot, Adaware, Zonealarm..
I run scans every day....
It stopped it at first, but now it is doing it again.
I think Google is selling us all down the river.....
Printer Friendly | Permalink |  | Top
 
Mike 03 Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:19 PM
Response to Reply #2
6. Whoa, I had no idea how widespread this is. Glad I'm not alone, but it sucks NT
Printer Friendly | Permalink |  | Top
 
anigbrowl Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:19 PM
Response to Reply #2
7. Then you're doing it wrong
Spybot should be sufficient, but that's easy for me to say as I have teh technical knowledge of what's going on so I know how to supplement it. I use Google's services day in day out and have no problems.
Printer Friendly | Permalink |  | Top
 
NJmaverick Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:22 PM
Response to Reply #2
12. Follow the instructions I gave out here
Printer Friendly | Permalink |  | Top
 
BrklynLiberal Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 08:41 PM
Response to Reply #12
21. thks
Printer Friendly | Permalink |  | Top
 
BrklynLiberal Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-07-09 12:37 AM
Response to Reply #12
27. Your recommendations found several problems and fixed them.
Thanks again.
Printer Friendly | Permalink |  | Top
 
juno jones Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 09:29 PM
Response to Reply #2
25. You might have something like vundo which has a tendancy to
leave a file on your drive and re-install on start-up.

Please see my post #24.

There is free assistance on the major geeks forum.
Printer Friendly | Permalink |  | Top
 
TorchTheWitch Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-07-09 03:45 AM
Response to Reply #25
32. it's Conficker - Vundo is somewhat different
Vundo gives you the pop-ups and Conficker gives you the search redirecting while blocking you from anti-virus updates or cleaning tools that kills it. Conficker has several varients, the most recent of which includes more cleaning tools. The patch Microsoft put out in October doesn't keep you from getting all the varients... I got the patch in October but got the most recent varient in January.

Printer Friendly | Permalink |  | Top
 
juno jones Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-07-09 08:27 AM
Response to Reply #32
33. I've had vundo do that as well
It also shut down my system backuup once. But it's all academic because no one has stated which virii their systems have dredged up. I just used vundo as an example.
Printer Friendly | Permalink |  | Top
 
graywarrior Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:15 PM
Response to Original message
3. I keep getting a trojan virus and my AVG will not update.
I downloaded Malwarbytes on a DU'r recommendation and it will eliminate, but not prevent. I had the same problem you have with being redirected to other links from Google. It stopped after installing Malwarbytes, but I was surprised to see another Trojan infection today. It's so annoying. Next computer I get is a MAC.
Printer Friendly | Permalink |  | Top
 
Mike 03 Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:20 PM
Response to Reply #3
8. I hear you about getting a Mac.
I wonder if setting Yahoo as my home page would help, instead of setting Google. (Or some other search engine?)
Printer Friendly | Permalink |  | Top
 
anigbrowl Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:24 PM
Response to Reply #8
13. No, it won't. The problem is at your end, not Google's.
Once your browser has become really compromised, it doesn't matter whether you're going to safest-site-in-the-whole-damn-world.com.
Printer Friendly | Permalink |  | Top
 
graywarrior Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:25 PM
Response to Reply #8
15. I know, I have google as mine too
I hate to do that because I use gmail and like to just open it quick from Google, but maybe I should switch also.
Printer Friendly | Permalink |  | Top
 
NJmaverick Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:24 PM
Response to Reply #3
14. Did you run the advanced system care 3?
After you ran the complete scan with Malware Bytes?
Printer Friendly | Permalink |  | Top
 
graywarrior Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:53 PM
Response to Reply #14
18. No.
But I'll do that tonight after I run MB again.
Printer Friendly | Permalink |  | Top
 
JJ Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-07-09 12:44 AM
Response to Reply #3
29. No need for a Mac
try Ubuntu linux. http://www.ubuntu.com/

It's free.
Printer Friendly | Permalink |  | Top
 
TorchTheWitch Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-07-09 03:40 AM
Response to Reply #3
31. it's Conficker - see post #30 n/t
You just got reinfected again. Conficker is still easy to get and still out there. The Microsoft patch put out last October doesn't keep you from getting the updated varients of the virus. I'm wondering if yet another varient was put out since a lot of people are getting it suddenly again. You also might have gotten reinfected by using a drive that wasn't cleaned when you got it before seeing as Conficker infects all your drives and you have to clean it from all of them or risk getting reinfected again. Stay away from porn sites and file sharing as those are the major ways of getting all kinds of nasties.

I hear ya about the Mac! Seems like developers of these damn invaders are putting out more and more sophisticated crap that's more and more difficult to get rid of, and it doesn't matter how careful you are in securing your system.

Printer Friendly | Permalink |  | Top
 
rucky Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:16 PM
Response to Original message
4. Prepare a report to send to hijackthis
Printer Friendly | Permalink |  | Top
 
anigbrowl Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:16 PM
Response to Original message
5. What you want is 'Spybot - Search and Destroy'
Get it from http://www.safer-networking.org/index2.html

As a bonus, it's free.

It'll possibly take you a whole day and several reboots to clean everything off. I find it bulletproof, but bear in mind I've got many years as a computer tech so I don't rely 100% on the automated fixes and supplement them with some manual poking around. But it is by far the best of its kind.

It's just possible some malware will prevent you from opening up the Safer Networking website. If you are unable to download and can't ask anyone else to DL it for you, PM me and I'll email the zip file to you within 24 hours.
Printer Friendly | Permalink |  | Top
 
Elidor Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:27 PM
Response to Reply #5
16. I use Spybot and Malwarebytes together
Plus an authenticator for Warcraft, lol. Not to mention Zone Alarm, NoScript and disabling Flash. I can't see half the internets, but I'm safe at last! Hahaha. I think the joke's on me.

While not all of this junk comes from websites, there are certain precautions everyone should take, like porn affiliates, all warez sites, and especially any site that sells Warcraft gold. I've seen numerous people get hacked going to free Warcraft servers as well. Even the websites for those servers will fuck you up. It pays to be extremely choosy where you go on the web. You can end up in a back alley and get mugged pretty quick if you don't know the neighborhood, so to speak.
Printer Friendly | Permalink |  | Top
 
backscatter712 Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 08:45 PM
Response to Reply #16
23. ++. Also try Combofix.
Combofix, Spybot and Malwarebytes should make your malware go away.

I just used Malwarebytes to clean some crap off of my sister's computer - she clicked on some popup that looked like an antivirus warning, and got a piece of malware called "System Security 2009" that was throwing obnoxious popups on her screen every few minutes and asking for her credit card number. All fixed now.
Printer Friendly | Permalink |  | Top
 
Poll_Blind Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:21 PM
Response to Original message
10. Here are a few suggestions all bundled up which can help alot.
First, you've got a serious problem there. If you can't use your computer for more than 10 minutes at a time without having to do a scan you are not using a personal computer: You are using a torture device.

If you are able to, reinstall your operating system and reinstall your AV software. BUT, instead of surfing the web with the browser on your computer, create a virtual computer using Sun's VirtualBox or similar- I think Microsoft and VMWare both have free programs which will allow you to make a virtual machine. Browse with that virtual machine, not with your actual machine.

If you don't have a lot of memory instead of installing Microsoft into the virtual machine, install something small like Simply Mepis (a linux distribution) or Knoppix or some of the other nice friendly Linux OSes. That way even your virtual machine is very unlikely to catch a virus.

Some of the stuff I mentioned above will require you to do a bit of research. What I suggest is just one possible alternative but it's a widely used method to stay clean. I guarantee any effort you expend learning about how to do what I describe above is going to be far less than the crap you're going to have to do to keep your computer running at this point.

Nuke it and pave over it. Nuke and pave. Nuke and pave. You'll be so happy. That sounds like it sucks mightily.

PB
Printer Friendly | Permalink |  | Top
 
NeedleCast Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:22 PM
Response to Original message
11. Do all of you work at my office?
My users constantly manage to wreck their systems as well, despite their AV and spybot programs.
Printer Friendly | Permalink |  | Top
 
Suich Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 06:35 PM
Response to Original message
17. That sounds like go.google.com. and it's a real mother!
My neighbor just spent 2 days getting rid of it for me...good luck!

:(
Printer Friendly | Permalink |  | Top
 
BlooInBloo Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 08:42 PM
Response to Original message
22. Check hijackthis forums, get off the pron.
Printer Friendly | Permalink |  | Top
 
juno jones Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 08:53 PM
Response to Original message
24. Sounds like you have something that is re-installing itself.
Edited on Mon Apr-06-09 09:20 PM by juno jones
That happens, especially with some of the trojans like vundo (in fact if it IS vundo, there is a vundo removal tool that works very well, it can be found on Major Geeks). Little bastards dig into your system and re-intall on reboot. It's happened to me a couple of times. It can drive you mad.

I have had extremely good luck with Re-Animator (which I use after all else has failed) but it takes a bit of knowlege of your start-up and registry to do right.

I really suggest going to the Major Geeks forum and posting there. They are very helpful and I have been walked thru some pretty complex virus removal by the techs there on a couple of occasions. They will have you run a number of programs such as malwarebytes and have you send the reports to them. They can often reccomend specialized proceedures and programs tailored to the problem you have. They are good teachers too, I've been able to remove some stubborn stuff with the techniques I've learned there. I don't welcome infection, but it no longer scares me, in fact I consider it a challenge.

Of course, I also keep my important stuff backed up elsewhere in case I have to wipe everything and start over.

As for anti-virus, I have had good luck with the free home version of 'avast!', as have several others on this board.

Good Luck to you! :hi:
Printer Friendly | Permalink |  | Top
 
TreasonousBastard Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Apr-06-09 11:32 PM
Response to Original message
26. Something might be playing with your Hosts file...
and you can easily check and modify it:

http://www.bleepingcomputer.com/tutorials/tutorial51.html

(I've never had the problem, so never needed to try the fix, but geek lore tells me this works)

Printer Friendly | Permalink |  | Top
 
Imagevision Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-07-09 12:41 AM
Response to Original message
28. I use Kaspersky 2009 - got explore virused out, did a scan and it cleaned the problem up...
Printer Friendly | Permalink |  | Top
 
TorchTheWitch Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-07-09 03:27 AM
Response to Original message
30. it's Conficker
Same thing happened to me back in January. If you're able to download and install Malwarebytes's most recent version it's probably one of the older varient's of the evil thing from hell. Make sure you clean ALL your drives as it infects all of them. Conficker blocks you from getting updates from your anti-virus or any other cleaning tool it recognizes from downloading/running to kill it.

This is good forum with tech folks that can help you thoroughly clean the evil monster up...
http://www.windowsbbs.com/malware-virus-removal/

Even if you think your computer is is totally cleaned of it, I'd advise you to have these folks (or any learned techie person you might know) check a computer scan log to make sure.

I know what you're going through, dude. That one is one nasty booger to have and get rid of. I use top flight anti-everything, firewall for the paranoid, etc., etc., so don't feel bad you got it. This wretched creature is REALLY nasty and way to easy to get.

Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Wed Apr 24th 2024, 10:56 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC