bannerBaka-UpdatesManga
Manga Poll
How many series are you currently regularly reading?
None
1-5
6-10
11-20
21-50
51-100
100+
 
mascot
Manga is the Japanese equivalent of comics
with a unique style and following. Join the revolution! Read some manga today!

RSS Feed

Computer Viruses that Redirects your Browser

Pages (3[ 1 2 3 ] Next
You must be registered to post!
From User
Message Body
user avatar
Uncultured
Member


16 years ago
Posts: 2128

________________

Point & Squirt

Post #336139 - Reply To (#336136) by G-17
Post #336139 - Reply To (#336136) by G-17
user avatar
Middle aged
icon Member


16 years ago
Posts: 7789

Quote from G-17

http://goodbye-microsoft.com/

🤣

This.


user avatar
KYOKUGEN !!!
icon Member


16 years ago
Posts: 878

This can be a pain, especially if you aren't too computer savvy.

Hijackers are tricky to remove, especially when you can't seem to find them. Most anti-virus/ anti-spyware programs don't do a very good job detecting and removing hijackers.

There's ways to remove them using 'HijackThis' and other tools, but again if you haven't done it before and don't know anyone who has it can take a long time to get the hang of it.

So it's best to purchase another hard drive and transfer all the stuff you want to keep to the new one. Then format the old drive and re-install an operating system. Hard drives are relatively cheap, and a wipe and re-install takes 2 hours, which makes it fast and easy.


________________
Post #336182 - Reply To (#336145) by xtr3m3dude
Post #336182 - Reply To (#336145) by xtr3m3dude
user avatar
Member


16 years ago
Posts: 157

Quote from xtr3m3dude

This can be a pain, especially if you aren't too computer savvy.

Hijackers are tricky to remove, especially when you can't seem to find them. Most anti-virus/ anti-spyware programs don't do a very good job detecting and removing hijackers.

There's ways to remove them using 'HijackThis' and other tools, but again if you haven't done it before and don't know anyone who has it can take a long time to get the hang of it.

So it's best to purchase another hard drive and transfer all the stuff you want to keep to the new one. Then format the old drive and re-install an operating system. Hard drives are relatively cheap, and a wipe and re-install takes 2 hours, which makes it fast and easy.

That's a good plan, except i don't have a cd for the operating system, so I can't re-install.

Is 'HijackThis' automatic? I downloaded it, but it still doesn't do anything, but a couple of my favorite websites came back, but not all of it.


________________
Post #336238 - Reply To (#336182) by Karis
Post #336238 - Reply To (#336182) by Karis
Member


16 years ago
Posts: 27

Quote from Karis

Quote from xtr3m3dude

This can be a pain, especially if you aren't too computer savvy.

Hijackers are tricky to remove, especially when you can't seem to find them. Most anti-virus/ anti-spyware programs don't do a very good job detecting and removing hijackers.

There's ways to remove them using 'HijackThis' and other tools, but again if you haven't done it before and don't know anyone who has it can take a long time to get the hang of it.

So it's best to purchase another hard drive and transfer all the stuff you want to keep to the new one. Then format the old drive and re-install an operating system. Hard drives are relatively cheap, and a wipe and re-install takes 2 hours, which makes it fast and easy.

That's a good plan, except i don't have a cd for the operating system, so I can't re-install.

Is 'HijackThis' automatic? I downloaded it, but it still doesn't do anything, but a couple of my favorite websites came back, but not all of it.

Like I said in my earlier post, it's a rootkit. It prevents programs with certain file names from running. You simply need to rename the exe file to run it. Rename the install file to "asdf.exe" and it'll run. This also goes for the program exe after you install it. I still suggest using combofix because you don't need to install it. You just run it. (after you rename it)

edit: Hijackthis doesn't clean anything. It lists all the running process and stuff so you can see if anything bad is running in the background.


user avatar
Member


16 years ago
Posts: 1901

Keep in mind that adware and spyware are different from viruses. You'll have to make sure if you are using an anti-virus program that it specifically says it will get rid of adware as well.

Quote from G-17

http://goodbye-microsoft.com/

🤣

You're too predictable gan. 😮


________________
Post #336320 - Reply To (#336238) by Mushroomtea
Post #336320 - Reply To (#336238) by Mushroomtea
user avatar
Member


16 years ago
Posts: 157

Quote from Mushroomtea

Like I said in my earlier post, it's a rootkit. It prevents programs with certain file names from running. You simply need to rename the exe file to run it. Rename the install file to "asdf.exe" and it'll run. This also goes for the program exe after you install it. I still suggest using combofix because you don't need to install it. You just run it. (after you rename it)

Sounds like using ComboFix is really risky. I'm not really good with dealing with this sort of thing, and I don't want to risk losing my computer which i just recently bought this year. Are you certain this program is the only thing that can fix this problem, along with the problems i mentioned in the first post?


________________
Member


16 years ago
Posts: 313

Run hijjackthis and post a thread on castlecops or some similar site, and include the log.

As for debian replacing windows.... Or MacOS or any other OS really... Heh. No.


Post #336380 - Reply To (#336131) by blakraven66
Post #336380 - Reply To (#336131) by blakraven66
user avatar
jail bait
Member


16 years ago
Posts: 1444

Quote from blakraven66

Quote from otakuness

did anyone of you people tried playing "hotel 626"??
well i did...and it nearly crashed my mozilla...im just sharing... 😐

Works fine for me though...

well...
i played it two times...the second time was alright...

so about the game...
did it scared ya?! cause it made me scream...not from terror but from the shock- attack
🤣


________________

oh please do click this!
The sweeter the apple, the higher the branch. The quieter the fart, the nastier the smell.
GUESS WHO??

user avatar
Member


15 years ago
Posts: 157

I'm in serious trouble here:

A phony antispyware called Antispyware Soft just invaded my computer, and it keeps popping up on my computer, persuading me to download it. there are also several ones like these lurking in my computer, and I can't get rid of them even with the instructions given to me in removal help. Plus, the redirecting website virus, a virus that prevents me from downloading anything, and a virus that prevents me from using any antispyware removal programs! And they are messing up my computer as i type this. Just what am i suppose to do?
I tried to go to this website for instructions, but it just doesn't make sense to me...
http://www.2-spyware.com/remove-antispyware-soft.html
http://www.2-viruses.com/remove-antispyware-soft


________________
Member


15 years ago
Posts: 87

Your computer is heavily infected with a malware that is downloading other malware/adware into your computer. Those sites showing you how to remove the malwares are mostly scam sites that make you enter your information (such as address, phone, credit cards...etc), steal your money then leave you with an infected PC. Read more about it here

http://www.bleepingcomputer.com/virus-removal/remove-antispyware-soft

Here is the step-by-step I usually use to clean out an infected PC.

1st: Download malwarebytes and hijackthis or have an offline version of any of the strong anti-virus program installed. You'll get an exe file that you can run but will need to connect to the internet. Don't worry about installing any of them yet.

2nd: Reboot into safe-mode (very important) with network if possible to run and install malwarebytes and any of the anti-virus you have (some might not work in safe-mode). If you have safe-mode with network (thus internet) then you can run and update malwarebytes. Save the finished log of malwarebytes after you scan. If you can't even get into safe-mode or you have no network in safe-mode thus can't install/run any of those then stop here and skip to step 4.

3rd: If malwarebytes or anti-virus program and catch the malware then it's good, if not then run hijackthis (in safe-mode). The program will generate a log and give you a list of the programs that is running in your pc. You can delete some of the suspicious entry if you want but if you area not sure, just save the log file.

4th: If you are used to deal with infected PC then you can attempt to repair your PC by deleting the suspicious files shown on the malwarebytes and hijackthis log. If you aren't then you should post those logs on any of the self-help for PC sites for more experienced user to take a look and give you advice.

5th: They will most likely going to show you how to remove the infecting files from your PC by downloading some of the programs and they might ask you to use ComboFix with a special text file they will give you to clean your PC. This program is very powerful and might harm your OS so only use it as a last resort short of reformatting your HDD.

PS: If you have a 2nd PC or a friend's PC then you can just install a strong anti-virus program and/or malwarebytes into that PC. Then remove the HDD from the infected PC, plug it into the 2nd PC as a back-up drive and run a scan. This should clean out most if not all of the infection without much hassle.

PSS: After this, if you're still using your PC then start getting the following: Firefox + Adblock + Noscript. IE has some powerful adblocking program too but I usually use Firefox. Install a strong anti-virus like kaspersky (spelling?) and run it every once in a while. Also, update your windows and flash program.


... Last edited by Oddwaffle 15 years ago
Post #377660 - Reply To (#377652) by Oddwaffle
Post #377660 - Reply To (#377652) by Oddwaffle
user avatar
Member


15 years ago
Posts: 157

Quote from Oddwaffle

Your computer is heavily infected with a malware that is downloading other malware/adware into your computer. Those sites showing you how to remove the malwares are mostly scam sites that make you enter your information (such as address, phone, credit cards...etc), steal your money then leave you with an infected PC. Read more about it here

http://www.bleepingcomputer.com/virus-removal/remove-antispyware-soft

Here is the step-by-step I usually use to clean out an infected PC.

1st: Download malwarebytes and hijackthis or have an offline version of any of the strong anti-virus program installed. You'll get an exe file that you can run but will need to connect to the internet. Don't worry about installing any of them yet.

2nd: Reboot into safe-mode (very important) with network if possible to run and install malwarebytes and any of the anti-virus you have (some might not work in safe-mode). If you have safe-mode with network (thus internet) then you can run and update malwarebytes. Save the finished log of malwarebytes after you scan. If you can't even get into safe-mode or you have no network in safe-mode thus can't install/run any of those then stop here and skip to step 4.

I've downloaded previous software mentioned above, but they do not run even after installing them. Even when they did, i still need to update it, and for some reason, I can't. hijackthis doesn't even do anything even after installing. Plus even in safe-mode with networking, it still won't let me download any software, and instead redirect me to a different website.

Quote from Oddwaffle

3rd: If malwarebytes or anti-virus program and catch the malware then it's good, if not then run hijackthis (in safe-mode). The program will generate a log and give you a list of the programs that is running in your pc. You can delete some of the suspicious entry if you want but if you are not sure, just save the log file.

When you say you can delete some suspicious entry that is in the log, where am i suppose to delete it? I tried using task manager, but i don't see any programs that looked suspicious...

Quote from Oddwaffle

4th: If you are used to deal with infected PC then you can attempt to repair your PC by deleting the suspicious files shown on the malwarebytes and hijackthis log. If you aren't then you should post those logs on any of the self-help for PC sites for more experienced user to take a look and give you advice.

Even if i did generate a log, where am i suppose to send it to? Its kind of difficult to find a site you can trust. I tried to review it, but the content was to overwhelming for me...

Quote from Oddwaffle

5th: They will most likely going to show you how to remove the infecting files from your PC by downloading some of the programs and they might ask you to use ComboFix with a special text file they will give you to clean your PC. This program is very powerful and might harm your OS so only use it as a last resort short of reformatting your HDD.

Quote from Oddwaffle

PS: If you have a 2nd PC or a friend's PC then you can just install a strong anti-virus program and/or malwarebytes into that PC. Then remove the HDD from the infected PC, plug it into the 2nd PC as a back-up drive and run a scan. This should clean out most if not all of the infection without much hassle.

PSS: After this, if you're still using your PC then start getting the following: Firefox + Adblock + Noscript. IE has some powerful adblocking program too but I usually use Firefox. Install a strong anti-virus like kaspersky (spelling?) and run it every once in a while. Also, update your windows and flash program.

Man, I just can't keep up with you. Does that mean I have to purchase an anti-virus program?


________________
user avatar
Lalaaa
Member


15 years ago
Posts: 15

I don't quite get the first part of the first website you gave (just follow their instructions, I guess), but phony anti-spyware softs have invaded my computer several times before so I can help you with the bottom portion.
And as others have stated, it is really important you boot your computer in Safe Mode. Like it says,

  1. Restart your computer. As your computer restarts but before Windows launches, tap "F8" key constantly. Use the arrow keys to highlight the "Safe Mode with Networking" option as shown in the image below, and then press ENTER.

I don't know what safe mode does exactly, but I guess it makes your computer less vulnerable.

NEXT, to delete the registry keys:
Start menu > accessories > run
Open the program, then type in "regedit".
Then find all the keys listed on the website and delete them. Make sure you have the right key before deleting, as deleting the wrong keys can mess up your computer.

The registry key is basically storage for all the possible commands in your computer.

NEXT, killing a process:
press ctrl+shift+esc to open the task manager.
The process tab is the second.
Find the task the website tells you to kill, click on it, and click "end process".

A process is basically everything that's running in your computer.

FINALLY, deleting files:
Open up the Search window. Type in the file name that the website provides. When you find the file, delete it.

This way you can find and delete files you otherwise would not see on your computer. It would be useful to look on other sites as they may have other file names, processes, and registry keys. Personally, I would stick to deleting the files because it's dangerous to get involved with registry keys.

REMEMBER, this is all done in safe mode.

After everything is done, you should download an actual antispyware soft (in regular mode).
By now, your computer should be back to normal.

I've been able to do this all without buying anything. Just make sure in the future to get McAfee Site Advisor (which is free) and set your internet browser options so that it blocks all popups.


________________
Member


15 years ago
Posts: 87

To run any cure on your PC, you'll need to be in 'safe-mode' since this is the mode that windows run with only a bare skeleton of programs (thus least amount of infected programs). Don't run any of the downloaded program until you are in 'safe-mode'. If you can't access the internet to download anything then you're having something like a DNS changer which change the IP address of common anti-virus sites and preventing you from downloading/updating from them.

Try to run hijackthis, it will show you a list of stuff (R1, 03, 04...etc). There should be a box next to each of the line. if you check the box and click on the button at the bottom to fix/delete the entry. I don't think this will do much as the malware that is infecting your PC is a bit trickier to fix than normal. Post the log here if you are not too sure or here http://www.bleepingcomputer.com/forums/forum22.html

The site I posted in the previous post shown should show you a step by step instruction of how to download, install and work around the infection. Read the "Automated Removal Instructions for Antispyware Soft using Malwarebytes' Anti-Malware:" part.

No, you don't have to buy any anti-virus program. It's merely a recommendation after you have removed the malware. Just... don't pay anyone anything while you are still having malware in your PC. Remove them by following the instruction on the link I posted (the 1st part tells you what problem you are having, 2nd part tells you how to manually fix it, 3rd part tells you how to automatically fix it)


... Last edited by Oddwaffle 15 years ago
user avatar
Member


15 years ago
Posts: 157

siiiigggghhhh

I'm sorry everyone, but everything i tried to do is not working.

I tried to delete certain registry keys that was listed in the website, but those keys don't exist on my pc.

I even tried to transfer the software from one pc to the infected pc, but it didn't even work at all.

Safe mode doesn't even make a difference, whether i tried to or not. And whenever i tried to click on a program in normal mode, it doesn't work because the virus is preventing me from even using it.

I tried using the rkill.com, but i keep getting a notepad page, and it doesn't look like its doing as it should be instructed.

plus, renaming the files don't even work either; i tried to rename the removal files, but i keep getting nothing.

I'm running out of options; what am i gonna do now?


________________
Pages (3[ 1 2 3 ] Next
You must be registered to post!