It is currently Thu Apr 18, 2024 10:07 pm


Highjacking?

Discuss and share submissions to the Contrebombarde website.
  • Author
  • Message
Offline
User avatar

jocr

Member

  • Posts: 535
  • Joined: Sat Mar 15, 2003 10:58 am
  • Location: El Monte CA

Highjacking?

PostSun Aug 19, 2012 12:21 pm

There was a problem with supposed highjacking.

James Pressler
Last edited by jocr on Wed Aug 22, 2012 11:40 am, edited 2 times in total.
Offline
User avatar

Grant_Youngman

Member

  • Posts: 1203
  • Joined: Sat Jan 20, 2007 6:50 pm
  • Location: Savannah, Ga

Re: Highjacking?

PostSun Aug 19, 2012 12:37 pm

I just checked .. it was working fine.
Grant
Offline
User avatar

pwhodges

Member

  • Posts: 832
  • Joined: Wed Dec 15, 2004 11:08 am
  • Location: UK, Oxford

Re: Highjacking?

PostSun Aug 19, 2012 1:08 pm

Almost certainly you have a virus. I have seen this kind of virus appear at the same time as a keylogger, so don't try any on-line banking until it's sorted.

Paul
Offline
User avatar

jocr

Member

  • Posts: 535
  • Joined: Sat Mar 15, 2003 10:58 am
  • Location: El Monte CA

Re: Highjacking?

PostSun Aug 19, 2012 1:15 pm

[Withdrawn]
Last edited by jocr on Sun Aug 19, 2012 6:06 pm, edited 1 time in total.
Offline
User avatar

pwhodges

Member

  • Posts: 832
  • Joined: Wed Dec 15, 2004 11:08 am
  • Location: UK, Oxford

Re: Highjacking?

PostSun Aug 19, 2012 2:13 pm

Cookies are neither here nor there. Last time I saw a virus with symptoms which could be similar to yours (redirecting some web accesses), it was not detected by the AV program that the machine had installed (which is why it got in); I installed a different AV which did detect it, but failed to remove it - so I had to format and rebuild (which is part of my job).

I would suggest getting a suitable geek (family, neighbourhood helper, commercial, as appropriate) to look at the machine and confirm (or not!) this diagnosis.

I'm taking this seriously because of what I saw the first time I went to that bogus address (it changed the second time, to obscure what's going on, I think). The first time it flashed up a bogus anti-virus message, but subsequent visits are looking like Google. I have definitely seen such behaviour on an infected machine in the past.

Paul
Offline
User avatar

jocr

Member

  • Posts: 535
  • Joined: Sat Mar 15, 2003 10:58 am
  • Location: El Monte CA

Re: Highjacking?

PostSun Aug 19, 2012 2:44 pm

[Withdrawn]
Last edited by jocr on Sun Aug 19, 2012 6:06 pm, edited 1 time in total.
Offline
User avatar

elpaharo

Member

  • Posts: 157
  • Joined: Thu Mar 22, 2007 7:50 pm
  • Location: New Braunfels, TX

Re: Highjacking?

PostSun Aug 19, 2012 4:35 pm

James

If you are running Internet Explorer then you can try this:

1. Open TOOLS (little gear lookiing thing in the upper corner of the browser).
2. Select INTERNET OPTIONS
3. Select the GENERAL TAB
4. Select BROWSING HISTORY | DELETE
5. Select (TICK) all options except passwords
6. Hit DELETE



If that doesn't do the trick the next step is to use the FREE rootkit killer (TDSSKiller)

1. Go here: http://support.kaspersky.com/faq/?qid=208283363
2. Down load the TDSSKiller ap and run it.
3. The process will take less than a minute and will report it finds the cause of the virus.

After this is done retry the link to see if the issue has been repaired.

Bill :roll:
Last edited by elpaharo on Mon Aug 20, 2012 3:20 pm, edited 1 time in total.
Offline
User avatar

jocr

Member

  • Posts: 535
  • Joined: Sat Mar 15, 2003 10:58 am
  • Location: El Monte CA

Re: Highjacking?

PostSun Aug 19, 2012 4:42 pm

[Withdrawn]
Last edited by jocr on Sun Aug 19, 2012 6:05 pm, edited 1 time in total.
Offline
User avatar

pwhodges

Member

  • Posts: 832
  • Joined: Wed Dec 15, 2004 11:08 am
  • Location: UK, Oxford

Re: Highjacking?

PostSun Aug 19, 2012 4:43 pm

It might, conceivably; but there are far worse things out there that cannot be so simply removed - as I said, last time I had to reformat the disk. Removing the redirector was easy, but removing the root kit that installed it was not!

Internet help is not enough to deal with something like this with confidence.

Paul
Offline
User avatar

elpaharo

Member

  • Posts: 157
  • Joined: Thu Mar 22, 2007 7:50 pm
  • Location: New Braunfels, TX

Re: Highjacking?

PostSun Aug 19, 2012 4:45 pm

jocr wrote:Unfortunately I run FoxPro and have tried their similar fixes. but thanks.

James Pressler



James

Sorry about that, I was having the exact symptons as you and it was the Browser cache(s) where the redirector was hiding.

Bill :roll:
Offline
User avatar

ajt

Member

  • Posts: 870
  • Joined: Sun Nov 12, 2006 6:40 pm
  • Location: Hampshire, UK

Re: Highjacking?

PostSun Aug 19, 2012 4:48 pm

Bottom line with al but the most innocuous of viruses (virii?) - you'll never know if your system is in a reliable state until you do reformat and reinstall. It certainly sounds and looks like a virus. I'd at least be tempted to get yourself a copy of something like the Kaspersky rescue CD and boot off that, see what it turns up.
Adrian
Offline
User avatar

Purator

Member

  • Posts: 170
  • Joined: Sat Dec 30, 2006 3:52 pm
  • Location: Leipzig, Germany

Re: Highjacking?

PostSun Aug 19, 2012 5:11 pm

Hello,

I suggest, as already mentioned, you get at least one of these (better both):

http://support.kaspersky.com/en/viruses/rescuedisk
http://www.avira.com/en/download-start/product/avira-antivir-rescue-system

They will tell you what has infected your PC and will give you the ability, to remove the virus if possible. You however, have to decide wether you want to keep your system, or reinstall it. This depends on the kind of virus you got, so if there are only some suspicious cookies, it is usually not a problem. RootKits are much more dangerous - then you should get one of your geeks^^

And what is "FoxPro"? I know that as a database program, but as a Browser? If possible, try Firefox, Chrome or Opera.

Greetings
Purator
Offline
User avatar

jocr

Member

  • Posts: 535
  • Joined: Sat Mar 15, 2003 10:58 am
  • Location: El Monte CA

Re: Highjacking?

PostSun Aug 19, 2012 5:18 pm

Firefox. Problem solved.

James Pressler
Offline

Unda Maris

Member

  • Posts: 42
  • Joined: Fri Apr 01, 2005 3:07 pm
  • Location: Germany

Re: Highjacking?

PostTue Aug 28, 2012 9:56 am

Safari told me:
Parse error: syntax error, unexpected T_OBJECT_OPERATOR in /homepages/24/d228559144/htdocs/concerthall/system/application/controllers/home.php on line 59

Website offline?
Offline
User avatar

jocr

Member

  • Posts: 535
  • Joined: Sat Mar 15, 2003 10:58 am
  • Location: El Monte CA

Re: Highjacking?

PostTue Aug 28, 2012 10:30 am

Google seems to think there's a problem this morning.

contrebombarde.com concert hall
contrebombarde.com/
This site may harm your computer.

James Pressler
Next

Return to Contrebombarde Concert Hall

Who is online

Users browsing this forum: No registered users and 6 guests

cron