Forum Settings
       
Reply To Thread

Sigh =(Follow

#1 Mar 18 2004 at 11:38 PM Rating: Good
*
136 posts
Tonight while doing whatever it is he does on the net and navigating through a zillion pop-ups my husband’s auto-debug popped up. When he viewed the source code he found an address that turned out to be the source of the pop-ups.

When he went to the website to check it out they literally took his browser over, and downloaded something called Assistant.3721.com, deleted all his favorite links, replacing it with a bunch of ****. They also embedded a bunch of extensions in his browser. Apparently the route he took in was the numerical link from the debugger.

The site appears to be a marketing company with the normal About Us, Work for Us type links … the moral of the story is…use your security settings, even if you’re OS is a ********* PoS its better than having a screwed up browser. He’s disabled browser extensions now but damnit they never should have been put there without permission in the first place… sigh… =(

Gonna be up all night trying to figure out how to fix this…just needed to ***** a little…





Edited, Thu Mar 18 23:40:12 2004 by plick
#2 Mar 19 2004 at 12:13 AM Rating: Good
Everybody who is cool has Windows XP Professional and can use System Restore when **** like that happens.
#3 Mar 19 2004 at 12:26 AM Rating: Good
*
136 posts
Yeah but I'm not cool...

Though I have XP, he has Win 2000 Advanced Server... and since he's a dba, he keeps nothing backed up...why you ask? Because bless his geeky little heart dba's are certifiably insane.


<I know my grammer and sentence structure sucks balls on this post, but I'm about to rip my hair out and chew my knuckles to the bone in frustration...sorry in advance for the lack of editing>

Edited, Fri Mar 19 00:29:09 2004 by plick
#4 Mar 19 2004 at 2:07 AM Rating: Good
Prodigal Son
******
20,643 posts
You would have to be insane to actually go to the address shown in a debugger log of an ad script.

It was from ****, without a doubt.
____________________________
publiusvarus wrote:
we all know liberals are well adjusted american citizens who only want what's best for society. While conservatives are evil money grubbing scum who only want to sh*t on the little man and rob the world of its resources.
#5 Mar 19 2004 at 6:40 AM Rating: Excellent
Avatar
******
29,919 posts
Try this:

Step one. run a search for any "hosts" files that may have been created on the machine. Chances are they are not needed, so rename them to something other than hosts for the time being so they won't be active.

Next in internet explorer go to Tools: Internet Options. On the General tab, Click on Delete cookies; Delete files (delete all ofline files is Checked); click on the settings button, go to view files (delete anything in that directory) then click view objects (Also delete anything in that directory). Click Clear History.

On the security tab, Select Internet and then click on custom level then select Reset to: Medium and press the reset button.

On the Content tab, click Clear SSL state

On the Connections tab, if you are connected via a network card, click on the LAN button. If the Proxy server section has any content in it, or is checked, uncheck and delete all information.

On the Programs tab, press the Reset all web settings button

On the advanced tab, click the restore all defaults.

Now go to Start:Run and type in ipconfig /flushdns

After that, restart the computer and see if it will connect to the internet when it restarts. If it will, great. If it won't there is probably still another registry key that is messed up. The easiest way to fix that will be to grab a new copy of internet explorer (you can get IE 6 off the windows XP cd) and install it over the existing copy.

That should reset most vectors of problems. If not, it may be in the VxD's or the registry. Easiest thing to do at that point may be to just reinstall windows. Running "Hijackthis" could also help.
#6 Mar 19 2004 at 7:38 AM Rating: Good
*****
18,463 posts
I'm tempted to go do all of that just because I see it listed. I love lists!
#7 Mar 19 2004 at 1:05 PM Rating: Good
Flea wrote:
I'm tempted to go do all of that just because I see it listed. I love lists!


1. Hug me.

2. Kiss me.

3. Do me.

4. Marry me.

Smiley: grin
#8 Mar 19 2004 at 2:07 PM Rating: Good
*
136 posts
Finally gave up and went to bed...thanks Kao going to check through that now...

The irritating part is, though it is *his* computer...for another week...it's mine when he gets a new laptop next week...so he's not too motivated to bother fixing it...which dumps the mess on my lap if i want to use the damned thing...



Edited, Fri Mar 19 14:11:40 2004 by plick
#9 Mar 19 2004 at 8:41 PM Rating: Good
*
136 posts
Whoo Hoo! Thanks Kaolin, 2 cookies and a bagel for you!! Now my dilema is: do I tell him that his fixed 'puter is results of guru advice I got in a forum and not my own doing now -or- after the jewelry, fancy dinner and luvin...hrm...
#10 Mar 19 2004 at 8:43 PM Rating: Excellent
Avatar
******
29,919 posts
As long as I get my cookies and bagels, whatever you tell him will be fine great (make sure it is a rasin bagel!)
#11 Mar 19 2004 at 8:55 PM Rating: Good
*
136 posts
cream cheese?
#12 Mar 19 2004 at 8:59 PM Rating: Excellent
Avatar
******
29,919 posts
Of course!
#13 Mar 19 2004 at 9:20 PM Rating: Good
*
136 posts
#14 Mar 21 2004 at 2:11 AM Rating: Decent
****
5,311 posts
Take the credit Plick. I'm sure Kao will understand it's for the cause of love and all that.
#15 Mar 21 2004 at 4:06 AM Rating: Good
Official Shrubbery Waterer
*****
14,659 posts
Well, inspired by the success stories that I've read here, I decided to see if I can stop all the pop-ups and spam that I'm getting. I can do everything on that list except for view files and objects. Every time I click on those buttons, IE crashes.

WTF is going on? What should I do?


Edit: Oh yeah, ding 500!

Edited, Sun Mar 21 04:05:14 2004 by TwiztidSamurai
____________________________
Jophiel wrote:
I managed to be both retarded and entertaining.

#16 Mar 21 2004 at 12:39 PM Rating: Excellent
Avatar
******
29,919 posts
do it manually. Find your temporary internet files directory (probably somewhere under c:\windows) then nuke everything inside by hand. then reinstall internet explorer. If it is crashing on that you may have one of the nasty embedded ones installed, and they are truly a pain to get rid of
#17 Mar 21 2004 at 3:51 PM Rating: Good
Quote:
Well, inspired by the success stories that I've read here, I decided to see if I can stop all the pop-ups and spam that I'm getting. I can do everything on that list except for view files and objects. Every time I click on those buttons, IE crashes.


How much RAM do you have?

I've had that happen on friends coputers with little RAM, wasn't enough ram to have the webpage up and the "view files and objects" so IE would crash with the "Internet Explorer has caused an invalid page fault in bla bla bla" error message.

And while we're talking about crashing browsers, don't use Mozilla Firebird yet, they have a major bug with the new Tab system, which, lucky for you and bad for me, has killed many of my posts.

#18 Mar 22 2004 at 2:19 AM Rating: Decent
*
136 posts
After that nasty little dilema I downloaded This

#19 Mar 22 2004 at 1:34 PM Rating: Good
*****
16,160 posts
That guy looks like one of the dynamic duo of Ace and Gary.

0.o

Totem
#20 Mar 22 2004 at 1:58 PM Rating: Good
***
1,907 posts
I have to mention this story here because it's so funny and tells how sneaky the a$$es are who want to take over your computer.

We had a customer, an elderly gentleman, with a wife and grandkids, who went "accidentally" to a porno site. With no encouragement (giggle), it put an icon titled "Big Boobs" on his desktop with a picture of a large pair as the icon. If you deleted the icon, it came back when the PC was rebooted. You could change the icon, but not the name, or it would come back. Of course the icon took you to a site where the first image loaded was a large boobed woman.

He was really upset, because he didn't want his wife or grandkids to see this sort of thing on grandad's PC.

Turns, out the website had downloaded a "new" version of the file find.exe (still worked as always with some added programming), much larger than the original find.exe, with all kinds of additions, including the "Big Boob" programming. We simply replaced that file and all was well.

But I thought this was a VERY nasty trick, and the average user would never have figured it out. MEAN. MEAN. The hardest part of the whole thing was keeping a straight face through all the explanations of how the "accidental" viewing of the porno page had taken place.

Reply To Thread

Colors Smileys Quote OriginalQuote Checked Help

 

Recent Visitors: 324 All times are in CST
Anonymous Guests (324)