dimanche 13 octobre 2013

Frickin' Malware

I seem to have gotten some weird not-exactly-a-hijack thing, and I can't figure out how to get rid of it.



It doesn't exactly hijack the page in Chrome, but it opens and takes me to one of their pages (directspecialstoday.com or diysimplify.com). It opens the page I'm trying to get to as well, sometimes in a separate tab, sometimes I have to hit the back arrow to get to my intended destination. Sometimes it opens as a separate page in a not-exactly-a-browser instance. I am, of course, concerned that it's not just a hijacker, but that worse things are going on behind the scenes.



I've tried everything I can think of to get rid of it: I tried system restore, and it fails everytime; I did an uninstall on the programs I was attempting to download. (I had checked the authenticity of the program I was trying to install; I stupidly trusted the download utility.)



Yesterday, when I was first trying to figure out what went on, it would open a window that would start talking to me, but there was nothing (apparently) running in the applications or processes of task manager. (Which was a little weird, because I rebooted after an attempt to clear it, and it immediately started talking to me, even before I opened anything at all -- and according to task manager nothing was running!)



I've run avast, Microsoft Security Essentials, adwcleaner, malwarebytes, and I even ventured into Hijackthis. Except for avast, all of them found something to get rid of, but that doesn't seem to actually make it go away.



Since I can't figure out the name of it, I can't look for it by name, and I'm not finding anything that describes the behavior of this sucker.



Hijackthis scares me though, because I don't know what all those things it reports do, and I don't want to do the wrong thing. I tried browsing their forum, and couldn't find anything that seemed to match up to my exact problem.



(For what it's worth, it appears to have only infected my Chrome browser -- and I can't find anything in the settings there; and I'm running Windows 7.)



Any ideas?





via JREF Forum http://forums.randi.org/showthread.php?t=266887&goto=newpost

Aucun commentaire:

Enregistrer un commentaire