Author Topic: Crazy things happening with me  (Read 12043 times)

0 Members and 1 Guest are viewing this topic.

Sartigan

  • Guest
Re: Crazy things happening with me
« Reply #15 on: June 27, 2010, 07:37:51 PM »
It's a bit strange, because I lost all my opened tabs, all my addons and I needed to reinstall them, set the settings, I just hope it will help  :-\

Didn't helped me, FireFox blocks a redirection on chiponline.hu - in the new profile :S
« Last Edit: June 27, 2010, 07:44:04 PM by Sartigan »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: Crazy things happening with me
« Reply #16 on: June 27, 2010, 07:40:27 PM »
Hi sartigan,

Did you try to go to these sites using a website proxy of some sort like Hidemyass or similar, were you allowed to go there then, then it has something to do with a situation outside your machine, try that,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Sartigan

  • Guest
Re: Crazy things happening with me
« Reply #17 on: June 27, 2010, 07:45:02 PM »
I didn't tried it

New profile thing doesn't works - FireFox blocks a redirection at Chiponline :S

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Crazy things happening with me
« Reply #18 on: June 27, 2010, 08:44:18 PM »
Didn't helped me, FireFox blocks a redirection on chiponline.hu - in the new profile :S

Maybe you set FF up to do so...??
There's an option for it, but sorry can't lead you there, as I use the german version.
English users would know better, where to find it... Please jump in..!
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Sartigan

  • Guest
Re: Crazy things happening with me
« Reply #19 on: June 27, 2010, 09:06:40 PM »
AWWW.... I installed internet explorer 8 and asked me to restart, I restarted my system and freezed with a window: Adding personal settings


I rebooted more than 4 times and now Online Armor asked about 2 files from IE8 but Windows Started normally and everything is loaded.
I need back IE7 :S

Now I'm going to restore a backup :S

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Crazy things happening with me
« Reply #20 on: June 27, 2010, 09:10:56 PM »
AWWW.... I installed internet explorer 8 and asked me to restart, I restarted my system and freezed with a window: Adding personal settings


I rebooted more than 4 times and now Online Armor asked about 2 files from IE8 but Windows Started normally and everything is loaded.
I need back IE7 :S

Now I'm going to restore a backup :S

So what is your problem, right now - exactly..?
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Sartigan

  • Guest
Re: Crazy things happening with me
« Reply #21 on: June 28, 2010, 10:40:02 AM »
My only problem is the chiponline.hu redirection - what FireFox blocks

Brusheezy and faviccek.hu redirection doesn't appears, just on chiponline

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: Crazy things happening with me
« Reply #22 on: June 28, 2010, 07:15:03 PM »
Hi Sartigan,

Look for a hidden inline script there, something like: hxxp://79.135.152.181/stats/go.php?sid=1 (the url may vary), scanners hardly detect this script, go to novirusthanks.org and scan with their hidden iFrame detector..
On connecting to chiponline.hu it immediately starts to redirect and download malcode...
#  hidden összes magasan értékelt letöltés  - htxp://download.chip.eu/hu/Home_1899.html?order=5
# <A> hidden összes magas érték - hxtp://download.chip.eu/hu/Home_1899.html?order=3
See: http://jsunpack.jeek.org/dec/go?report=b5da8da1d94e36d98d6515216fee7e516c39f9fe

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Sartigan

  • Guest
Re: Crazy things happening with me
« Reply #23 on: June 28, 2010, 07:54:09 PM »
 :o  :o
OH MY GOD, so this isn't my computer?

I won't go there anymore :S
Thank you very much for giving me answer  ;)
This happens on some PCGuru.hu pages too. I will check it

Thank you again


I didn't allowed the redirection, I though it was my computer - so essexboy, you were right about this site is probably being hacked :D
Thank you and keep up the good work ;)
« Last Edit: June 28, 2010, 08:04:25 PM by Sartigan »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Crazy things happening with me
« Reply #24 on: June 28, 2010, 09:12:41 PM »
Not all problems are on the host computer - and once they have been eliminated there is only one logical answer - a hacked site

Sartigan

  • Guest
Re: Crazy things happening with me
« Reply #25 on: June 28, 2010, 09:17:08 PM »
And what should I do with Combofix's quarantined files? Like C:\Installer.exe and some others...

No more redirections - just these

I hope I won't get any more problems like this! But the bad is always back.....

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Crazy things happening with me
« Reply #26 on: June 28, 2010, 09:31:10 PM »
I will remove my tools now and give some recommendations, but I would like you to run for 24 hours or so and come back if you have any problems

 Now the best part of the day ----- Your log now appears clean  :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

Code: [Select]
:Commands
[resethosts]
[purity]
[emptytemp]
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]
[Reboot]

    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done


    Click Start > Run  and copy/paste the following bolded text into the Run box and click OK:

    ComboFix /Uninstall

    Run OTL and hit the cleanup button.  It will remove all the programmes we have used plus itself.  MBAM can be uninstalled via control panel add/remove along with ERUNT.  But they may be useful tools to keep

    We will now confirm that your hidden files are set to that, as some of the tools I use will change that
    • Click Start.
    • Open My Computer.
    • Select the Tools menu and click Folder Options.
    • Select the View Tab.
    • Under the Hidden files and folders heading select Do not show hidden files and folders.
    • Click Yes to confirm.
    • Click OK.

       Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems

    Upgrading Java:
    • Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 20.
    • Click the "Download" button to the right.
    • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
    • Click on Continue.
    • Click on the link to download Windows Offline Installation (jre-6u20-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
    • Close any programs you may have running - especially your web browser.
    • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
    • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button.
    • Repeat as many times as necessary to remove each Java version.
    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u20-windows-i586-p.exe and select "Run as an Administrator.")
    SPRING CLEAN
     
    Download and run Puran Disc Defragmenter

    Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes: It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

    To keep your operating system up to date visit To learn more about how to protect yourself while on the internet read our little guide  How did I get infected in the first place ?
    Keep safe  :wave:

    Offline polonus

    • Avast Überevangelist
    • Probably Bot
    • *****
    • Posts: 33895
    • malware fighter
    Re: Crazy things happening with me
    « Reply #27 on: June 29, 2010, 12:37:10 AM »
    Howdy Sartigan,

    Fine we could solve this problem and bring it back to its true proportions, hidden script injection of a certain web page with malcode. This is a gigantic online problem at the moment because malcreants try to inject as many web pages as they are able to through ready made exploit kits and also cybercriminals will take to these actions for their own devious ends, and what to think of all the fake av re-directs and malcoded ad code, on one page it is gone and cleansed and on another page it rears again its ugly head. Therefore use in-browser protection and learn to use the full protection of the NoScript extension in the Firefox browser (or any other type of Mozilla browser like flock, etc. for that matter) and these issues won't bite you next time around. May your surfing be safe and secure, is the wish of

    polonus
    « Last Edit: June 29, 2010, 12:38:50 AM by polonus »
    Cybersecurity is more of an attitude than anything else. Avast Evangelists.

    Use NoScript, a limited user account and a virtual machine and be safe(r)!

    Sartigan

    • Guest
    Re: Crazy things happening with me
    « Reply #28 on: June 29, 2010, 10:29:04 AM »
    chiponline.hu is the Hungarian "news portal" of a very popular website that everyone knows: download.chip.eu - and (as it looks like) it's infected, I warned my website's members about this :) - and I wrote this to the end of my post - on my forum (in Hungarian): "Thank you polonus, essexboy!" :)

    Essexboy, where can I download OTL? Because I haven't got OTL, I always update my MBAM and run a scan once a week, I will download Spyware Blaster after I clean up with OTL.....
    « Last Edit: June 29, 2010, 11:04:23 AM by Sartigan »

    Offline Pondus

    • Probably Bot
    • ****
    • Posts: 37527
    • Not a avast user
    Re: Crazy things happening with me
    « Reply #29 on: June 29, 2010, 10:43:47 AM »
    Quote
    Essexboy, where can I download OTL? Because I haven't got OTL
    http://forum.avast.com/index.php?topic=53253.0   click the OTL