Donate Now Goal amount for this year: 799 USD, Received: 100 USD (13%)
Please donate to help support this website. The funds will be used to purchase owned license of LiteSpeed Web Server Enterprise (2-CPU). It provides superior performance in terms of raw speed, scalability and anti-DDoS capabilities.

Page 1 of 3 123 Last
Results 1 to 10 of 26

Thread: IE is hacked..

  1. #1
    Verified Member
    Points: 37,255, Level: 100
    Level completed: 0%, Points required for next Level: 0
    Overall activity: 0%
    Achievements:
    31 days registered3 months registeredTagger Second ClassTagger First Class500 Experience Points
    Awards:
    Calendar Award

    Join Date
    Jan 2010
    Location
    India
    Posts
    2,641
    Liked
    10 times

    Spin IE is hacked..

    posting for a friend.

    IE is hacked & opens by default site

    hxxp://www.adserver5.com/dsnr/dec/sa.html

    actions taken
    1. MBAM-comes clean-Full scan
    2. Spybot - fixed 42 problems-still same issue

    what next needs to be done?



    Friends here is the exact error message/warning:

    Last edited by grr; 03-18-2010 at 09:30 AM. Reason: image added for exact error message

  2. #2
    Banned
    Points: 9,474, Level: 65
    Level completed: 42%, Points required for next Level: 176
    Overall activity: 0.5%
    Achievements:
    31 days registered3 months registered1 year registered100 Experience Points500 Experience Points

    Join Date
    Jul 2009
    Posts
    563
    Liked
    2 times
    Quote Originally Posted by grr View Post
    posting for a friend.

    IE is hacked & opens by default site:
    hxxp://www.adserver5.com/dsnr/dec/sa.html

    actions taken
    1. MBAM-comes clean-Full scan
    2. Spybot - fixed 42 problems-still same issue

    what next needs to be done?

    also sometimes synmentic antivirus popups the msg saying Http loop toolbar activity...
    The first thing you could do is edit your post so there is no direct link to a known malware site...
    Good grief...
    Attached Images Attached Images
    Last edited by hellnoire; 03-18-2010 at 12:51 AM. Reason: Calm down, and removed your quote's link

  3. #3
    Verified Member
    Points: 37,255, Level: 100
    Level completed: 0%, Points required for next Level: 0
    Overall activity: 0%
    Achievements:
    31 days registered3 months registeredTagger Second ClassTagger First Class500 Experience Points
    Awards:
    Calendar Award

    Join Date
    Jan 2010
    Location
    India
    Posts
    2,641
    Liked
    10 times
    Quote Originally Posted by acr View Post
    The first thing you could do is edit your post so there is no direct link to a KNOWN MALWARE SITE !!!! Good grief...
    done. .

  4. #4
    Rookie
    Points: 42,879, Level: 100
    Level completed: 0%, Points required for next Level: 0
    Overall activity: 7.0%
    Achievements:
    31 days registered3 months registered1 year registered100 Experience Points500 Experience Points

    Join Date
    Jan 2009
    Location
    Malaysia
    Posts
    2,135
    Liked
    22 times
    Scan your computer with ESET Online Scanner

    ESET Online Scanner is able to remove threats. Post a HijackLog as well.
    Thoughts are like a never ending ocean where it is deep, endless and dangerous

  5. #5
    Senior Techie
    Points: 3,410, Level: 36
    Level completed: 40%, Points required for next Level: 90
    Overall activity: 0.7%
    Achievements:
    31 days registered3 months registered1 year registered100 Experience Points500 Experience Points

    Join Date
    Sep 2008
    Location
    UK/ Midlands
    Posts
    207
    Liked
    0 times
    Go to control panel>add or remove programs

    Is there a toolbar there that you don't recognize {remove it}


    If no try doing a system restore to a time before the problem

  6. #6
    Junior Techie
    Points: 3,412, Level: 36
    Level completed: 42%, Points required for next Level: 88
    Overall activity: 0.5%
    Achievements:
    31 days registered3 months registered100 Experience Points500 Experience Points1000 Experience Points

    Join Date
    Nov 2009
    Posts
    153
    Liked
    5 times
    Quote Originally Posted by fletch View Post
    If no try doing a system restore to a time before the problem
    This is bad advice. System Restore is last resort.

    Start by uninstallin symantec antivirus, which sucks and installing a better one, like Avira. Run a scan and post a Hijackthis log. I´m sure some expert here can have a look at your log.

  7. #7
    Banned
    Points: 9,474, Level: 65
    Level completed: 42%, Points required for next Level: 176
    Overall activity: 0.5%
    Achievements:
    31 days registered3 months registered1 year registered100 Experience Points500 Experience Points

    Join Date
    Jul 2009
    Posts
    563
    Liked
    2 times
    Quote Originally Posted by grr View Post
    done. .
    No it's not done. MBAM's IP protection blocks the site from loading. But your link is still a direct link to a malicious site. If your "friend" was infected just by visiting the site then it is possible for someone else to be infected by clicking your link. Your editing the link has only succeeded in making the matter worse. It's normally better to edit the address of the site so that it will not load (for instance, use hxxp instead of http).

  8. #8
    *nix Technical Support
    Points: 25,110, Level: 95
    Level completed: 76%, Points required for next Level: 240
    Overall activity: 18.0%
    Achievements:
    Recommendation Second Class31 days registered3 months registered1 year registeredTagger Second Class
    Awards:
    Frequent Poster

    Join Date
    Jan 2009
    Location
    /home/hellnoire
    Posts
    10,231
    Liked
    293 times
    I was going to suggest a HijackThis log as well... works to show the host file, which we can then fix out if need be. (it happens with a lot of hijackers)
    pacman -Syyu life not found in sync db

  9. #9
    Moderator
    Points: 49,066, Level: 100
    Level completed: 0%, Points required for next Level: 0
    Overall activity: 45.0%
    Achievements:
    Recommendation Second ClassRecommendation First Class31 days registered3 months registered100 Experience Points

    Join Date
    Dec 2008
    Location
    Italy
    Posts
    6,548
    Liked
    544 times
    I think that the friend of Grr catched this
    Code:
    hxxp://loop. myfamilytoolbar. com/
    Which is a type of counduit toolbar (loop toolbar).

    Generally a-squared free is able to detect and remove this kind of adware once installed

    After hellnoire will tell you how to fix this issue with HiJackThis, do not forget to reset IE to the default settings

    http://support.microsoft.com/kb/923737

    [EDIT to add]



    Here is the Threat Expert analysis:

    http://www.threatexpert.com/report.a...5755b709ced215
    Last edited by leofelix; 03-18-2010 at 09:47 AM. Reason: Automerged Doublepost
    ‎"If you really want something in this life, you have to work for it. Now, quiet! They're about to announce the lottery numbers..." - Homer Simpson

  10. #10
    Verified Member
    Points: 37,255, Level: 100
    Level completed: 0%, Points required for next Level: 0
    Overall activity: 0%
    Achievements:
    31 days registered3 months registeredTagger Second ClassTagger First Class500 Experience Points
    Awards:
    Calendar Award

    Join Date
    Jan 2010
    Location
    India
    Posts
    2,641
    Liked
    10 times

    Confused

    Thanks Everyone.

    From what all i have seen recommended here, I would ask my friend to do the following in the sequence:

    1. try to remove toolbar from add or remove programs, if visible
    2. Scan your computer with ESET Online Scanner
    3. analyze computer using HijackThis, and share the logs
    4. scan using a-squared-free
    5. analyze computer using HijackThis, and share the logs



    I have no words to Thank You all for the help.
    Hope everything goes fine..




    Regards,
    Grr

    Friends here is the exact error message/warning:

    Last edited by grr; 03-18-2010 at 09:29 AM. Reason: Automerged Doublepost

 

 
Page 1 of 3 123 Last

Similar Threads

  1. Twitter Hacked
    By vickypark in forum General Forum
    Replies: 2
    Last Post: 05-12-2010, 02:22 AM
  2. Wordpress hacked?!
    By brayden in forum Chat
    Replies: 3
    Last Post: 02-11-2009, 07:48 PM
  3. I keep getting Hacked!
    By zalude in forum Spyware/Viruses
    Replies: 12
    Last Post: 10-07-2007, 08:47 PM
All times are GMT +8. The time now is 04:05 PM.