Search the archive:
YaBB - Yet another Bulletin Board
 
   
 
Page Index Toggle Pages: 1
Send Topic Print
Internet 'Virus' or 'Cookie' problem?? (Read 713 times)
Dec 27th, 2003 at 6:15pm

Professor Brensec   Offline
Colonel
Can't you give me a couple
more inches, Adam?
SYDNEY - AUSTRALIA

Gender: male
Posts: 2955
*****
 
Not sure this is the best place to pop this, but I can't see anywhere better.  ???

I'm at work. The Net was down yesterday, I thought because maybe our ISP was down or some such thing. However, the boss has told me this morning that the problem is there seems to be some kind of Virus or 'Hidden Cookie' that is automatically 'activating' IE and going to a page called "www .allneedsearch.com", which is not a 'Search Engine' (as it can't find anything), but it causes a whole pile of 'Adult sites' to automatically come to screen AND even install themselves as 'Favorites'. This 'allneedsearch' site keeps repeatedly making itself the IE 'Homepage' also. Angry Angry

(The Net was down yesterday because there was a lady here in the morning and he didn't want these pages popping up in front of her!)  Shocked

He has tried to delete everything he can thru DOS etc (which I know absolutely nothing about), but the file that he seems to think it is, won't delete.

Has anyone had an encounter with this sort of thing (a page making itself your Homepage, or other pages automatically assigning themselves as 'Favorites' etc).  ???

It seems that one of the 'grubs' here has used the Net and downloaded some nasty little 'hidden cookie' or worse, some sort of 'virus'.  Roll Eyes Roll Eyes Roll Eyes

What does it sound like??  ???

(The boss has the Computer man coming tomorrow to see what he can do, but I told him I'd see if anyone could shed some light)  ???

P.S. Thankfully, this is only occurring on one PC, which is connected to a server. Apparently the 'F' Drive (server) is protected from anything that anyone might do on an 'individual PC' (As you can see, I don't know how all this stuff works)  Grin Wink
 

...&&...&&http://www.ra.online-plus.biz&&&&&&I cried because I had no shoes - until I saw a man who had no feet.&&&&Dell Dimension 8100 - Intel P4 1.7 Gb - 512 RD Ram - nVidia GeForce 128 mb FX5200.
IP Logged
 
Reply #1 - Dec 27th, 2003 at 6:25pm

Hagar   Offline
Colonel
My Spitfire Girl
Costa Geriatrica

Posts: 33159
*****
 
I'm no expert but it sounds like a cookie or Spyware to me. I've had this happen occasionally myself. AdAware would most likely deal with it. I use a little payware program named WindowWasher that does a better job. Not that I frequent too many porn sites you understand. It tidies everything up & frees up a lot of valuable HD space. It actually seems to make WinMe run better. I can't remember the last time I had the old BSOD. Famous last words. LOL
 

...

Founder & Sole Member - Grumpy's Over the Hill Club for Veteran Virtual Aviators
Member of the Fox Four Group

Need help? Try Grumpy's Lair

My photo gallery
IP Logged
 
Reply #2 - Dec 27th, 2003 at 6:38pm

Politically Incorrect   Offline
Colonel
Personal opinion given
free of charge!
Williamsport, PA

Gender: male
Posts: 3915
*****
 
Also clear out all stored cookies in your browser. I no longer use IE because of the lack of security. It is known for being the worst browser when it comes to getting a virus or something. I now use Netscape and never had a security breech since I switched. (knock on wood!) not to mention faster.
I use Spyware blaster, and Spy bot Seek and Destroy.
Both are free and both do a great job at cleaning and preventing spyware.
Also if your browser has a pop-up blocker you may want to activate it until you remove what ever it is infecting your computer. Just to save face in those embarrassing moments!! Smiley
P.S. Also be sure to do a complete virus scan!!!!
 
IP Logged
 
Reply #3 - Dec 27th, 2003 at 6:53pm

Politically Incorrect   Offline
Colonel
Personal opinion given
free of charge!
Williamsport, PA

Gender: male
Posts: 3915
*****
 
Looked around and it appears your computer has been hijacked!! Check out this posting at this site, scrolldown a little and it will give you a link for downloading a program to clean this out of your system.

http://computercops.biz/postt9006.html

Not sure if this will help but it appears to be a good starting spot!
Let us know what happens!!
 
IP Logged
 
Reply #4 - Dec 27th, 2003 at 6:57pm

Politically Incorrect   Offline
Colonel
Personal opinion given
free of charge!
Williamsport, PA

Gender: male
Posts: 3915
*****
 
Also, that little ad that pops up on this site, you know if you brush your mouse pointer over it ,the pop up shows asking if you want to download the IE Plug-in?
That would be the same type thing as the "allneedsearch" and could possibly be what you have if it was accidently allowed to install!!
 
IP Logged
 
Reply #5 - Dec 27th, 2003 at 7:24pm

Tequila Sunrise   Offline
Colonel
Nunquam non paratus
Glasgow Scotland

Gender: male
Posts: 4149
*****
 
all this sounds kinda familiar  Angry
 

If someone with multiple personality disorder threatens suicide, is it a hostage situation?

Thou shalt maintain thine airspeed lest the ground shalt rise up and smite thee
IP Logged
 
Reply #6 - Dec 27th, 2003 at 8:37pm

Katahu   Offline
Colonel

Gender: male
Posts: 6920
*****
 
Quote:
Also, that little ad that pops up on this site, you know if you brush your mouse pointer over it ,the pop up shows asking if you want to download the IE Plug-in?
That would be the same type thing as the "allneedsearch" and could possibly be what you have if it was accidently allowed to install!!


HOLY CHRIST!!!!!!!!!

Thanks for warning me.

That thing keeps poping up everytime I visit any site. At first, I thought it was something from Microsoft. But now that you tell me what it really is, I'll avoid it as much as I can.

Just yesterday, I had to clean out my entire computer AGAIN!!!

This is because I had several interuptions on my Previous cleaning process. Therefore, my computer kept thinking that there is more than 1 operating system installed. As a result [everytime I start the system] it kept asking me [in MSDOS prompt] which OS to start.

It was annoying. So, like I said, I cleaned it up yesterday. I backup a critical Windows Update file that I needed so that my computer is safe from the Blaster worm everytime I go online. I then went online to download and install the rest of the critical updates for the system and Norton. I also did a full system scan.

Nothing found. Whew.

Now I need to download and install the latest video drivers from Nvidia. Version 53.03. It's already available for everyone.

Man. First, the war. Then the Flu. Then the earthquakes. Then the viruses. Where the h377 is this world coming to?
 
IP Logged
 
Reply #7 - Dec 27th, 2003 at 9:17pm

chomp_rock   Offline
Colonel
I must confess, I was
born at a very early
age.

Gender: male
Posts: 2718
*****
 
Sounds bad! My PC is a veritable fortress though, I've never gotten a virus.
 

AMD Athlon 64 3700+&&GeForce FX5200 256Mb&&1GB DDR400 DC&&Seagate 500Gb SATA-300 HDD&&Windows XP Professional X64 Edition
&&&&That's right, I'm now using an AMD! I decided to give them another try and they kicked the pants off of my P4 3.4!
IP Logged
 
Reply #8 - Dec 27th, 2003 at 11:18pm

Professor Brensec   Offline
Colonel
Can't you give me a couple
more inches, Adam?
SYDNEY - AUSTRALIA

Gender: male
Posts: 2955
*****
 
Thanks people.  Cheesy I knew I could count on some help here.  Wink

I'll try a couple of the things that have been suggested and let you know how things went.

Who knows, I might be able to save the boss a few bucks........lol  Grin Wink

P.S. This is really a nasty thing, whatever it is. It's doing something else now!!
No matter what web page or documant is on screen, certain words are now automatically 'hyperlinked' to promotional web pages!!!
Wherever the word 'Credit' appears on the screen (regardless of the document it's in), it links to a 'Credit facility site'. Wherever the word "health' appears, it links to an 'Online prescription site".
It's really beginning to get out of hand!! Angry Angry
 

...&&...&&http://www.ra.online-plus.biz&&&&&&I cried because I had no shoes - until I saw a man who had no feet.&&&&Dell Dimension 8100 - Intel P4 1.7 Gb - 512 RD Ram - nVidia GeForce 128 mb FX5200.
IP Logged
 
Reply #9 - Dec 27th, 2003 at 11:42pm

Professor Brensec   Offline
Colonel
Can't you give me a couple
more inches, Adam?
SYDNEY - AUSTRALIA

Gender: male
Posts: 2955
*****
 
Quote:
Looked around and it appears your computer has been hijacked!! Check out this posting at this site, scrolldown a little and it will give you a link for downloading a program to clean this out of your system.

http://computercops.biz/postt9006.html

Not sure if this will help but it appears to be a good starting spot!
Let us know what happens!!


Thanks everyone. And thank you Fret!  Grin Wink

This Forum thread (Computercops) has the solution, but it's a bit long and tedious. Plus I don't have the access to safe mode at the moment. But I can give this Forum thread to the Boss and he can go through the exercise tomorrow.

If it fixed this blokes PC, it should fix this one, as it's exactly the same little mongrel and it's doing exactly the same things.  Grin Wink

Thanks again.
 

...&&...&&http://www.ra.online-plus.biz&&&&&&I cried because I had no shoes - until I saw a man who had no feet.&&&&Dell Dimension 8100 - Intel P4 1.7 Gb - 512 RD Ram - nVidia GeForce 128 mb FX5200.
IP Logged
 
Reply #10 - Dec 28th, 2003 at 3:59am

ozzy72   Offline
Global Moderator
Pretty scary huh?
Madsville

Gender: male
Posts: 37122
*****
 
Bren try finding a copy of a program called EndItAll (its freeware), this will show up all processes running on your machine, you should find any irregular ones, and their file name. You can then stop them running, search your system and delete them (make sure hidden folders are visible though, these spyware people are getting nastily clever!).
Apparently the new freeware video codecs are having spyware built in. The program has a name like tickler, and its got a strange filename. Its hidden in c:\WINDOWS\Documents and Settings\user name\Local Settings\Temp\somewhere here. There will be three folders Wink Remember to run AdAware and SpyBot daily to help keep your machine free of these nasty things Smiley

Ozzy
 

...
There are two types of aeroplane, Spitfires and everything else that wishes it was a Spitfire!
IP Logged
 
Reply #11 - Dec 28th, 2003 at 4:21am

paulb   Offline
Colonel
Wales

Gender: male
Posts: 322
*****
 
There is a lot of good advice here, so I will try not to repeat it!

However, I have had a similar problem in the past.

My solution is to use a good anti virus programme (I use Norton) with a live online subscription update and to run it every couple of days.

Also don't click on anything that pops up and you are not 100% sure about! Roll Eyes

And watch out for 'spam'. I get a lot  Angry.  Never open it and never write back to the sender.

You can try to check your files with windows explorer also for any 'spyware' programmes and delete any that you find.

Cheers Paul
 
IP Logged
 
Page Index Toggle Pages: 1
Send Topic Print