Every return I get from a search engine redirects me to an advertisement

enwar3

Golden Member
Jun 26, 2005
1,086
0
0
This is really, really annoying. Everytime I click a search result on, say, Google or live.com, it redirects me to a random advertisement. Is this a virus? I recently (as in half an hour ago) removed AntivirusXp2009 =X


This looks like it fits Security better than Software For Windows.

AnandTech Moderator
mechBgon
 

BoomerD

No Lifer
Feb 26, 2006
63,429
11,758
136
Yes, and apparently the damage is worse than originally thought. It also directed you to the wrong forum where you can be ridiculed for
a) posting in the wrong forum
b) Not knowing how to google a solution
c) downloading infected pron.
 

waggy

No Lifer
Dec 14, 2000
68,145
10
81
AntivirusXp2009? yeah its a ivrus. a very nasty one. itjgets worse over time.also its a pain to remove
 

law9933

Senior member
Sep 11, 2006
394
0
0
I guess you all know of the OP.
Try free MalwareBytes. It does a great job of removing AntivirusXP2009 I thought, and many more.
 

lxskllr

No Lifer
Nov 30, 2004
57,685
7,912
126
Originally posted by: BoomerD
Yes, and apparently the damage is worse than originally thought. It also directed you to the wrong forum where you can be ridiculed for
a) posting in the wrong forum
b) Not knowing how to google a solution
c) downloading infected pron.

:^D
 

enwar3

Golden Member
Jun 26, 2005
1,086
0
0
I got AntivirusXP2009 off, but I didn't notice until afterwards that all my browsers were still hijacked.

I ran malwarebytes three times or so amidst a number of reboots until the problem seemed fixed (at least in Opera), which was this morning. Tonight I open up firefox, BOOM the trojan is back and now it's back in Opera as well. In addition, I can't get to www.malwarebytes.org or open malwarebytes. This is really sad times.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
If the hijack occurred because you downloaded and ran a Trojan Horse program, thinking it was a ________ (Flash Player update, codec, ActiveX dealiebob, whatever), then be more suspicious in the future. Bait... fish hook... you get the picture.

If the hijack occurred "under the surface" without direct help from you, then look at these security steps to make it unlikely to happen again.

Regarding your current problem, could you list these:

1) your Windows version and Service Pack level (for example, "Windows XP Home Edition, SP3" or whatever)

2) do you have a router?

3) what antivirus software you have installed

4) what anti-spyware software you have installed


It may sound like a far-fetched possibility, but if you have a router, it may have been compromised. Give it a full reset using the RESET button on the back, for starters.

As a starting point for cleaning up the infection, use a working computer to download and burn a .ISO of F-Secure's Rescue CD. Boot your infected computer from the bootable CD, and run a scan with it. It will take time, so this may be something you want to do overnight.

 

enwar3

Golden Member
Jun 26, 2005
1,086
0
0
Originally posted by: mechBgon
If the hijack occurred because you downloaded and ran a Trojan Horse program, thinking it was a ________ (Flash Player update, codec, ActiveX dealiebob, whatever), then be more suspicious in the future. Bait... fish hook... you get the picture.

If the hijack occurred "under the surface" without direct help from you, then look at these security steps to make it unlikely to happen again.

Regarding your current problem, could you list these:

1) your Windows version and Service Pack level (for example, "Windows XP Home Edition, SP3" or whatever)

2) do you have a router?

3) what antivirus software you have installed

4) what anti-spyware software you have installed


It may sound like a far-fetched possibility, but if you have a router, it may have been compromised. Give it a full reset using the RESET button on the back, for starters.

As a starting point for cleaning up the infection, use a working computer to download and burn a .ISO of F-Secure's Rescue CD. Boot your infected computer from the bootable CD, and run a scan with it. It will take time, so this may be something you want to do overnight.

It occurred without my knowing.. so "under the surface" I guess.

1. XP Pro SP2

2. No router... but I am on university campus and I use campus wireless...?

3. McAfee

4. I've run the McAfee scan and Malwarebytes (which removed it the first time but now I can't get the program to run). I tried to install search & destroy but a lot of the antivirus sites are blocked and the .exe file can't access the site to continue the install.

I'll try Rescue CD tonight.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Ok, give the Rescue CD a try, and then I would go in this order:

1) after the Rescue CD is done, boot into Windows and disable your wireless.

2) while your wireless is disabled (and wired network connections are unplugged), now uninstall the McAfee software and reboot as needed.

3) while your wireless and wired network connections are still down, enable the Windows Firewall as shown in my security steps link above. Use the No Exceptions checkbox for now.

4) now that the Windows Firewall is enabled, you can turn your wireless back on. To get started, I'd go get the free version of AntiVir from http://www.freeav.com/, and get that installed and updated. No AV is perfect but I feel it's a lot better than McAfee these days.

5) AntiVir will put a shortcut on your desktop. Double-click it and you'll see where it says there's never been a full scan of your computer. So run a full scan, and now you've scanned the system with two different antivirus products (F-Secure/Kaspersky and AntiVir).

6) Once that's done, head to Microsoft Update to upgrade your Windows Update engine to the Microsoft Update engine. Then go back again, and again, and again, until your system has all the Service Packs and all the Critical or High-Priority patches. This will take quite a while, so make sure you have lots of snacks

7) Next, get your Data Execution Prevention fully enabled (the "security steps" link has info on that).

8) Run the free Secunia Personal Software Inspector to fix vulnerable stuff that no one realizes they've got. There's a link to that in the "security steps" page too.


Keep the Windows Firewall enabled. You may need to allow exceptions as time goes by, but don't take the firewall down altogether. Hope that helps
 

enwar3

Golden Member
Jun 26, 2005
1,086
0
0
Originally posted by: mechBgon
Ok, give the Rescue CD a try, and then I would go in this order:

1) after the Rescue CD is done, boot into Windows and disable your wireless.

2) while your wireless is disabled (and wired network connections are unplugged), now uninstall the McAfee software and reboot as needed.

3) while your wireless and wired network connections are still down, enable the Windows Firewall as shown in my security steps link above. Use the No Exceptions checkbox for now.

4) now that the Windows Firewall is enabled, you can turn your wireless back on. To get started, I'd go get the free version of AntiVir from http://www.freeav.com/, and get that installed and updated. No AV is perfect but I feel it's a lot better than McAfee these days.

5) AntiVir will put a shortcut on your desktop. Double-click it and you'll see where it says there's never been a full scan of your computer. So run a full scan, and now you've scanned the system with two different antivirus products (F-Secure/Kaspersky and AntiVir).

6) Once that's done, head to Microsoft Update to upgrade your Windows Update engine to the Microsoft Update engine. Then go back again, and again, and again, until your system has all the Service Packs and all the Critical or High-Priority patches. This will take quite a while, so make sure you have lots of snacks

7) Next, get your Data Execution Prevention fully enabled (the "security steps" link has info on that).

8) Run the free Secunia Personal Software Inspector to fix vulnerable stuff that no one realizes they've got. There's a link to that in the "security steps" page too.


Keep the Windows Firewall enabled. You may need to allow exceptions as time goes by, but don't take the firewall down altogether. Hope that helps

Thanks for all the help! I will definitely try your suggestions.

As for Rescue CD, there are a lot of warnings about how the cd will rewrite system files that could turn my currently-limping-along laptop into a completely dead laptop. Should I go ahead and run the scan still?
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Originally posted by: enwar3
Originally posted by: mechBgon
Ok, give the Rescue CD a try, and then I would go in this order:

1) after the Rescue CD is done, boot into Windows and disable your wireless.

2) while your wireless is disabled (and wired network connections are unplugged), now uninstall the McAfee software and reboot as needed.

3) while your wireless and wired network connections are still down, enable the Windows Firewall as shown in my security steps link above. Use the No Exceptions checkbox for now.

4) now that the Windows Firewall is enabled, you can turn your wireless back on. To get started, I'd go get the free version of AntiVir from http://www.freeav.com/, and get that installed and updated. No AV is perfect but I feel it's a lot better than McAfee these days.

5) AntiVir will put a shortcut on your desktop. Double-click it and you'll see where it says there's never been a full scan of your computer. So run a full scan, and now you've scanned the system with two different antivirus products (F-Secure/Kaspersky and AntiVir).

6) Once that's done, head to Microsoft Update to upgrade your Windows Update engine to the Microsoft Update engine. Then go back again, and again, and again, until your system has all the Service Packs and all the Critical or High-Priority patches. This will take quite a while, so make sure you have lots of snacks

7) Next, get your Data Execution Prevention fully enabled (the "security steps" link has info on that).

8) Run the free Secunia Personal Software Inspector to fix vulnerable stuff that no one realizes they've got. There's a link to that in the "security steps" page too.


Keep the Windows Firewall enabled. You may need to allow exceptions as time goes by, but don't take the firewall down altogether. Hope that helps

Thanks for all the help! I will definitely try your suggestions.

As for Rescue CD, there are a lot of warnings about how the cd will rewrite system files that could turn my currently-limping-along laptop into a completely dead laptop. Should I go ahead and run the scan still?

I guess there's always that risk. Backing up your important stuff (emails, contacts, files, music, photos and documents) to an external drive, and making sure you have your Windows installation disc and CD key, would probably be a good just-in-case move.

 
Nov 5, 2001
18,367
3
0
I spent about 6 hours cleaning up someones laptop with similar issues. I ran the programs in the Security Toolkit that is stickied on the front page and eventually it was cleaned up, but I ran everything again under safe mode.
 

tvdang7

Platinum Member
Jun 4, 2005
2,242
5
81
help i need help!! im having this problem im going nuts. what tool kit? i dont see any toolkits
 

lightstar

Senior member
Mar 16, 2008
579
0
0
wow this was an annoying little ah heck to get rid of! thanks for this post and the tips- took a while but it finally worked
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |