Pelican Parts Forums

Pelican Parts Forums (http://forums.pelicanparts.com/)
-   Off Topic Discussions (http://forums.pelicanparts.com/off-topic-discussions/)
-   -   My Web Browsers been hacked - redirected (http://forums.pelicanparts.com/off-topic-discussions/710668-my-web-browsers-been-hacked-redirected.html)

Rusty Heap 10-10-2012 08:27 AM

My Web Browsers been hacked - redirected
 
I'm open for ideas from any IT guys or 'puter wizards out there SmileWavy



The last week on a IBM Windows 7 PC machine using Explorer for web use, when I Google or Bing search a topic, 90% of the time I get re-directed to some other website trying to sell me something.

So basically, I've got a virus or been hacked while doing a web search.

I'm running the lastest Microsoft Security Essentials, and Malwarebytes Anti-Malware software and have done full deep scans on both, which come up empty for any trojan or other virus.


Any ideas on what to do next, to get my Google and Search engine back and clean so I'm not re-directed to some other unwanted website?


Thanks in advance.

stomachmonkey 10-10-2012 08:40 AM

DNS hijack.

DNS hijacking - Wikipedia, the free encyclopedia

Rusty Heap 10-10-2012 10:07 AM

oh this looks like it'll be fun to fix........

of course for me to google several options to download fix-it software, I got redirected dozens of times.........

This is the best I could find for a cure.

Redirection virus - Malwarebytes Forum



Other Suggestions other than using software "Combofix", or "Farbar" like the above tech suggested to the other victim of the virus in the above link?

Time to do a backup of the hard drive and go for broke me thinks.

billwagnon 10-10-2012 10:56 AM

I've used ComboFix successfully for a virus.

I thought running MSE and AntiMalwareBtyes I was safe. Good luck!

It is always best to have an uninfected laptop for research and it usually takes a couple hours to figure out and permanently remove it.

The redirect virus I had redirected everything related to removing the virus. Kind of ingenious but annoying when it happens.

KaptKaos 10-10-2012 12:22 PM

Don't use Bing.

Bing is the most heavily poisoned search engine, study says • The Register

red-beard 10-10-2012 12:42 PM

Quote:

Originally Posted by KaptKaos (Post 7023684)

Some how I expect that Google is behind that study...

tharbert 10-10-2012 12:56 PM

You might try a few of these things:

If it's just a poisoned cache:
1. Click the Start logo
2. Click All Programs
3. Click Accessories
4. RIGHT-click on Command Prompt
5. Select Run As Administrator
6. In the command window type the following and then hit enter: ipconfig /flushdns
7. You should see the following confirmation:

Windows IP Configuration Successfully flushed the DNS Resolver Cache.

Restore to a point before hack:
Click the Start button and in the "Search Programs and Files", type "System restore"

The System Restore wizard will begin. Select a date before you had the problem.

Follow the directions.

I'd check to make sure the site didn't put in a proxy:
I.E. Tools/Internet Options - Connections Tab LAN Settings: Make sure there isn't a proxy server listed.

Reset I.E. to factory defaults (Beware, you will lose all your settings)

Partial Nuke:
Go to tools/Internet options. In the General tab/browsing history, select "delete". Uncheck "preserve favorite website data..." and select all others then "delete.".

Full Tactical:
Go to the advanced tab. At the bottom, there is the button to reset the program.

If you've been ignoring those pesky Windows, Java, Adobe Reader, Flash or Quicktime updates for more than a week, I'd be very leery of that machine until the operating system could be reloaded. I'd avoid any finacial transaction or logging into anything that you want to remain secure. Some of the compromises coming through unpatched software may be visible but there are an equal number of invisible compromises used to steal data that you'll never see until you get a bill for a TV in Germany.

RWebb 10-10-2012 12:57 PM

who is your ISP?

Head416 10-10-2012 01:23 PM

Check what your DNS servers are set to. Ipconfig /all

cstreit 10-10-2012 02:00 PM

Yep. Redirect virus. HARD to get rid of.... Had it a few moths ago. ComboFix and others finally killed it. Disable/uninstall Java too...

Rusty Heap 10-10-2012 03:12 PM

Thanks all, especially Tharbert for the multi-prong approach.

No it's not just a poisoned cache.

No I don't have any proxy's listed.

Verizon is my ISP.


ComboFix sounds like a scary proposition reading reviews of it. need to back up all my data then pull out all the stops.


thanks all........it's beer-thirty here so not going to worry about it right now.


All times are GMT -8. The time now is 03:54 AM.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website


DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.