Welcome to Laser Pointer Forums - discuss green laser pointers, blue laser pointers, and all types of lasers

LPF Donation via Stripe | LPF Donation - Other Methods

Links below open in new window

ArcticMyst Security by Avery

Browser hijacker - redirect "virus"

Status
Not open for further replies.
Joined
Sep 29, 2011
Messages
800
Points
0
I use OSX, not affected.

Same here. The only problem I have ever had on this site was when like 50 copies of the same ad would appear on the bottom of the screen thus slowing me down. I ad block filtered them. Are they still there?
 





Joined
Jan 29, 2012
Messages
3,164
Points
113
Yup me too. I got it yesterday and it kept on opening a web page saying Id won an iphone...

Eventually got rid of it by booting in safe mode and deleting the temp internet files from all users, in the local settings (hidden) folder. I had to use safe mode from the admin account, because I had lost privileges to the temp internet files as a user even with admin privilages...:gun::beer:
 
Last edited:
Joined
Mar 27, 2011
Messages
14,125
Points
113
I should also add I suppose... I have a tendency to clear all temp files, internet, windows, etc, on a regular basis.
 
Joined
Jan 29, 2012
Messages
3,164
Points
113
I should also add I suppose... I have a tendency to clear all temp files, internet, windows, etc, on a regular basis.

I do that too, but as I mentioned I realised something was awry when I tried to open the temporary internet file folder. Somehow I no longer had access to it and hence why I rebooted in safe mode as a different user to delete the contents.

BTW there were 10 or so files all relating to "rstrui.exe"? :beer:
 
Joined
Feb 5, 2008
Messages
6,252
Points
83
No problems here on this end.

Using ESET Internet security and AdBlock plus on Mozilla Firefox.

I do clear out my temp files every now and then with CCleaner.
 
Joined
Nov 4, 2011
Messages
801
Points
28
It's back. WTF It does seem to come from here. I have not clicked on any ads .
 
Joined
Jan 29, 2012
Messages
3,164
Points
113
It came back for me too. Id switched off noscript for a couple of mins and 6 new tabs opened all on their own... Noscript back on and all quitet...:beer:

BTW only had my bank page, email, a local garage webpage and LPF open, so common denoninator here is LPF. :(
 
Last edited:
Joined
Sep 25, 2012
Messages
87
Points
0
I think certainly something is coming from LPF. Malwarebytes has popped up with a warning several times recently while I've been loading LPF.
I believe a couple warnings were for trojan.exploit.9
Edit: just did it with trojan.happili as well...
 
Last edited:
Joined
May 4, 2009
Messages
5,443
Points
113
It hit me two days ago and plays music and opens windows but i close them immediately and go on about my business, the
sound tracks from the adds are annoying they come and go with out any windows opening, it's scary like a ghost in the machine.

I have been on no other web site that I think would have this, could youtube be infected ?

AVG has popped up twice and said it killed something.

So what's the best way to get rid of this crap and keep it away, sounds like nothing works so far :thinking:
 
Last edited:
Joined
Sep 20, 2008
Messages
17,622
Points
113
I hate anything that Hijacks my computer and
SPAMS it...

I've been lucky and it hasn't happened again since the 16th.


Jerry

You can contact us at any time on our Website: J.BAUER Electronics
 
Last edited:

norbie

0
Joined
Jul 6, 2012
Messages
37
Points
0
I'm a dumb IT guy so here's something you may be able to do to resolve it...

Type msconfig into the run command. Go to the startup tab and look for any suspicious programs and uncheck them and hit the apply button. If you get an access denied error don't worry it still worked.

Type regedit into the run command. Go to Hkey Local Machine -> Software -> Microsoft -> Shared Tools -> MSconfig

The things that you unchecked should show up under the folders startupreg or startupfolder below MSconfig. You should be able to see what those programs correspond with when you expand those two folders. If one of the programs looks like it goes with something you use don't mess with it...if it looks vague and obscure go ahead and delete it. This does not delete a program from your computer! All it does it is remove the program from the list of programs that startup when your computer starts up. Usually this will remove the symptoms of the virus/spyware (pretty sure you've actually got spyware but I could be wrong).

Once you can use the internet again try to download the following two free programs...malwarebytes and combofix. Malwarebytes is great at removing spyware and I use it a lot at work. Combofix is really used as a measure of last resort as it's a bit powerful and can accidentally delete something you need (I've never had that happen to me but I've heard it's happened so I'm at least acknowledging it as a possibility). I tend to use it only on severely affected machines. Combofix is really good at removing really malicious things called Rootkits.
 
Joined
May 20, 2012
Messages
301
Points
18
Joined
Nov 4, 2011
Messages
801
Points
28
Google is unusable. I tried Malwarebytes and it got rid of it for a day and now it’s back. Yahoo works but Google is hosed. Norton will not find it.
I have cleaned all temp files also. I need to find something that works.
 
Last edited:

wheedy

0
Joined
Feb 14, 2012
Messages
149
Points
18
I don't know how you guys keep getting this thing.
I go all over the internet and Google, without any antivirus anything (minus Adblock Plus on Chrome), and never have seen this ever.

I'll try to remember malwarebtyes for when my family gets this on their computers though (bound to happen sooner or later, every time I come back into town I do IT work for them lol).
 

Onryo

0
Joined
Aug 3, 2012
Messages
73
Points
0
The people having this problem could you please tell us what OS and browser/s you are using. Is this issue just hitting Windows and if so what version. Same with the browser type and version. Could you also tell us step by step what you did just before you are jacked. What page on LPF you are on last etc?

All the best
 
Joined
May 20, 2012
Messages
301
Points
18
I am using Windows 7 & IE 8. McAfee anti virus.
I can not tell you where I was page by page, minute by minute.
I don't know I have it until I use Google.
It could have been there for a few minutes or a day.
 
Status
Not open for further replies.




Top