also @ TechSpot: Exploit allows command prompt to launch at Windows 7 login screen

TechSpot

Search engine links being redirected

Discussion in 'Virus and Malware Removal' started by tikool17, Dec 17, 2009.

Thread Status:
Not open for further replies.
  1. ziondaddy Newcomer, in training

    thewesitesurvey.com and local-news-online problem

    FYI,

    when i first got this last week, it was right after i did the following:

    1. opened windows live messenger and the "TODAY" news window opened.
    2. clicked on some tiger woods controversy news and pics (elin nordegren specifically, haha)
    3. immediately had a virus, the alureon, to be exact. also found the old BankerFox one as well. weird...

    after going thru many steps, avast, adaware, malware bytes, even root repeal., i got rid of the virus it seemed. then the websitesurvey and local-news-online popups started and havent stopped. ive tried system restore, "last known good configuration", all that. subscribed to bleeping computer, but no help.. not even a comment yet.

    i even downloaded firefox and deleted IE8 thinking the browser itself was infected.. within 15 minutes, they started popping up again. so my wife started asking me questions and suggested i change my messenger settings so the TODAY msn news window would not open automatically when messenger opens. since it was thru there that i went to the articles and pics that led me to the infected link.

    so i did, and voila.. no more of any of those pop ups, but just now, i used the top right corner google search and it happened again-thewebsite survey thing. also, when i clicked on a link for a century 21 osborne realty here in yuma az, it took me to one of the bogus search sites the other person was talking about.

    but i thought someone could benefit from this info. im about to reformat cause im sick of this crap... too time consuming and time is money... david
  2. tikool17 Newcomer, in training

    sorry for the delay. still no symptoms but eset keep throwing up the same infection. log attached...
  3. Bobbye Helper on the Fringe

    Regarding the Eset find of "js HTML/Iframe.B.Gen virus", the consensus is that it is a False Positive. Are you getting any message when you startup such as "windows\system32\config\ is corrupt or missing."? But since it's a temp file, you can try either of these:

    TFC (Temp File Cleaner)

    Download TFC to your desktop
    • Open the file and close any other windows.
    • It will close all programs itself when run, make sure to let it run uninterrupted.
    • Click the Start button to begin the process. The program should not take long to finish its job
    • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean

    TFC only cleans temp folders. TFC will not clean URL history, prefetch, or cookies. Depending on how often someone cleans their temp folders, their system hardware, and how many accounts are present, it can take anywhere from a few seconds to a minute or more. TFC will completely clear all temp files where other temp file cleaners may fail. TFC requires a reboot immediately after running. Be sure to save any unsaved work before running TFC.

    TFC (Temp File Cleaner) will clear out all temp folders for all user accounts (temp, IE temp, java, FF, Opera, Chrome, Safari), including Administrator, All Users, LocalService, NetworkService, and any other accounts in the user folder.

    Then rescan with Eset.
  4. tikool17 Newcomer, in training

    no missing or corrupt messages on startup. and i ran tfc and and then eset again and got the same result. so i'm with you on the false positive; i'm not gonna worry about it.

    thank you so much for all your help, and a happy new year to you.
  5. Bobbye Helper on the Fringe

    You're welcome. You can remove the cleaning programs and old restore points:

    Remove all of the tools we used and the files and folders they created
    • DownloadOTCleanIt by OldTimer
    • Save it to your Desktop.
    • Double click OTCleanIt.exe.
    • Click the CleanUp! button.
    • If you are prompted to Reboot during the cleanup, select Yes.
    The tool will delete itself once it finishes.

    If you are prompted to Reboot during the cleanup, select Yes.

    You should now set a new Restore Point to prevent infection from any previous Restore Points. The easiest and safest way to do this is:
    • Go to Start > All Programs > Accessories > System Tools and click "System Restore".
    • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the Restore Point a name then click "Create". The new Restore Point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
    • Go to "Disk Cleanup" which can be found by going to Start > All Programs > Accessories > System Tools.
    • Click "OK" to select the partition or drive you desire.
    • Click the "More Options" Tab.
    • Click "Clean Up" in the System Restore section to remove all previous Restore Points except the newly created one.

    More details and screenshots for Disk Cleanup in Windows Vista can be found here.

    And here's some Firefox-specific info you might want to use:

    To prevent Tracking Cookies and block most ads:
    For Firefox: Tools> Options> Privacy> Cookies> CHECK ‘accept Cookies from Sites’> UNCHECK 'accept third party Cookies'> Set Keep until 'they expire'. This will allow you to keep Cookies for registered sites and prevent or remove others.

    I suggest using the following two add-on for Firefox. They will prevent the Tracking Cookies that come from ads and banners and other sources:
    AdBlock Plus
    Easy List

    To block or restrict a site in Firefox:
    Open Firefox> Tools> Options> Privacy> Cookies section> Exceptions> type the site domain or URL as you would in IE> Click on Block.

    Using the add-ons I mentioned does some of this, but it want want to restrict a specific site, type it in this section.

    Be sure to update and run a virus scan occasionally. And if the problem starts again, please let me know.
  6. jafang Newcomer, in training

    Thank You!!

    Hey Bobbye,
    just registered to say Thanks, I was just about to through the whole PC out of the window before google got me here:), so I like to thank also TechSpot and Google.
    Keep up the good work,

    Cheers.
  7. Bobbye Helper on the Fringe

    Welcome to TechSpot, jafang. Your thoughtfulness in signing on to say this is greatly appreciated! It's people like you who make this all worthwhile. Some days, I have to admit, I wonder if a user gets anything out of what we say and do here.

    One thoughtful person such as you goes a long way! Now that you know where we are and what we do, please let us know if we can be of assistance.
Thread Status:
Not open for further replies.