Results 1 to 16 of 16

Thread: Spyware/malware help

  1. #1
    DILLIGAF GoNz0's Avatar
    Join Date
    Jun 2006
    Location
    Derby
    Posts
    10,872
    Thanks
    632
    Thanked
    1,192 times in 945 posts
    • GoNz0's system
      • Motherboard:
      • Asus Rampage V Extreme
      • CPU:
      • i7 something X99 based
      • Memory:
      • 16gb GSkill
      • Storage:
      • 4 SSD's + WD Red
      • Graphics card(s):
      • GTX980 Strix WC
      • PSU:
      • Enermax Galaxy 1250 (9 years and counting)
      • Case:
      • Corsair 900D
      • Operating System:
      • win10 64bit
      • Monitor(s):
      • Dell 24"
      • Internet:
      • 220mb Cable

    Spyware/malware help

    I have an interesting gremlin I can't nail down. I have noticed when following some links that weirdness happens. If I go to eurocarparts.com for instance I will see the URL change 1st to
    http://thetraffic.info/?id=1450447602
    then to
    http://reprice.us/c/uCRH
    and finally with an attached affiliate link it will go to.
    http://www.eurocarparts.com/?awc=399...n=Sub+Networks

    Considering this is from chrome's homepage I am at a loss, the only thing that tipped me off was the links breaking and instead of taking me to the Asus forums it would drop me on the main support page.

    I have kaspersky internet security installed
    Malwarebytes found nothing,
    adwcleaner found nothing
    smitfraudfix = nada
    tdsskiller = nope
    adaware - zero


    so you can see it isn't for trying to remove this barstool!

    any ideas?

    Capitalization is the difference between helping your Uncle Jack
    off a horse and helping your uncle jack off a horse.

  2. #2
    Senior Member
    Join Date
    Aug 2013
    Location
    North Wales
    Posts
    1,849
    Thanks
    165
    Thanked
    271 times in 202 posts
    • virtuo's system
      • Motherboard:
      • Gigabyte Aorus Master X570
      • CPU:
      • Ryzen 9 5950x
      • Memory:
      • 64Gb G.Skill TridentZ Neo 3600 CL16
      • Storage:
      • Sabrent 2TB PCIE4 NVME + NAS upon NAS upon NAS
      • Graphics card(s):
      • RTX 3090 FE
      • PSU:
      • Corsair HX850 80+ Platinum
      • Case:
      • Fractal Meshify 2 Grey
      • Operating System:
      • RedStar 3, Ubuntu, Win 10
      • Monitor(s):
      • Samsung CRG90 5140x1440 120hz
      • Internet:
      • PlusNet's best, but still poor, attempt

    Re: Spyware/malware help

    Does it do the same on any other computers on your network, or even a different browser?

  3. #3
    Editable... jimbouk's Avatar
    Join Date
    Aug 2005
    Location
    Bristol
    Posts
    3,071
    Thanks
    321
    Thanked
    278 times in 226 posts
    • jimbouk's system
      • Motherboard:
      • Asrock B450M-HDV R4.0
      • CPU:
      • AMD Ryzen 5 3600
      • Memory:
      • Corsair Vengeance LPX 16 GB (2 x 8 GB) DDR4 3200 MHz C16
      • Storage:
      • Sabrent Rocket Q 1TB NVMe PCIe M.2 2280
      • Graphics card(s):
      • Sapphire Pulse RX 580 8GB
      • PSU:
      • Seasonic Core Gold GC-650
      • Case:
      • Lian-Li PC-V1100 ATX
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • AOC CU34G2/BK 34" Widescreen
      • Internet:
      • EE FTC

    Re: Spyware/malware help

    Sounds like url hijacking alright!

    http://thetraffic.info is a blank page, no whois info as it's registered by a proxy company. Have a look at your installed programs, something's probably been installed 'legitimately' on the sly as an adware bundle.

  4. #4
    boop, got your nose stevie lee's Avatar
    Join Date
    Sep 2007
    Location
    southport
    Posts
    2,689
    Thanks
    420
    Thanked
    440 times in 326 posts
    • stevie lee's system
      • Motherboard:
      • ASUS ROG STRIX B450-F Gaming
      • CPU:
      • Ryzen 3600
      • Memory:
      • 16 GB Corsair 3600 MHZ Cas 18
      • Storage:
      • 250GB BX500, M500 240GB, SN750 1TB NVME, mechs - Hitachi 1TB. WDblue 2TB
      • Graphics card(s):
      • sapphire 7700 1gb
      • PSU:
      • corsair RM550X
      • Case:
      • Xigmatech Midgard
      • Operating System:
      • Win 10 Home
      • Monitor(s):
      • 42" Panasonix viera (1080p limited RGB)
      • Internet:
      • plusnet fibre

    Re: Spyware/malware help

    had something similar a while ago.
    there were some registry entries causing redirects to a spoof google home page. no amount of reinstalls of chrome or malware/virus scanning found them. noticed the website redirect showing on the 'status bar' at the bottom. did a registry search for that address and up popped some registry entries. removed them and all was well.

    I ended up doing a full reinstall of windows 7 anyway, just because win 10 was about to be released and I didn't fully trust i'd removed all the registry stuff. and it was 5 years since previous reinstall.

    you may get away with a registry serach and remove. I would reinstall windows just to be sure though.

  5. #5
    DILLIGAF GoNz0's Avatar
    Join Date
    Jun 2006
    Location
    Derby
    Posts
    10,872
    Thanks
    632
    Thanked
    1,192 times in 945 posts
    • GoNz0's system
      • Motherboard:
      • Asus Rampage V Extreme
      • CPU:
      • i7 something X99 based
      • Memory:
      • 16gb GSkill
      • Storage:
      • 4 SSD's + WD Red
      • Graphics card(s):
      • GTX980 Strix WC
      • PSU:
      • Enermax Galaxy 1250 (9 years and counting)
      • Case:
      • Corsair 900D
      • Operating System:
      • win10 64bit
      • Monitor(s):
      • Dell 24"
      • Internet:
      • 220mb Cable

    Re: Spyware/malware help

    Laptops being exchanged in about a month so I will track the little bugger down if I can. I think one of my old chrome extensions to blame, I thought it was FDV Speed Dial at 1st but it happened again after I disabled it.
    so far (but this can happen at random not every click) with everything disabled in chrome it is behaving.
    Now to play the add things back a day at a time game!

    Capitalization is the difference between helping your Uncle Jack
    off a horse and helping your uncle jack off a horse.

  6. #6
    Senior Member watercooled's Avatar
    Join Date
    Jan 2009
    Posts
    11,478
    Thanks
    1,541
    Thanked
    1,029 times in 872 posts

    Re: Spyware/malware help

    I was asked to sort a friend's laptop doing something similar although IIRC the redirects were to some scareware site. Reinstalling Chrome didn't help as whatever it was was just re-injecting itself upon install. However it was quite some time ago and I'm not sure what exactly I did to get rid of it.

    It looks like the reprice link is the villainous one and I found a couple of references to it e.g. https://malwaretips.com/blogs/ads-by-reprice-removal/

    If you find out what it is I'd definitely be making some noise to Kaspersky/Malwarebytes/etc about it!

  7. #7
    DILLIGAF GoNz0's Avatar
    Join Date
    Jun 2006
    Location
    Derby
    Posts
    10,872
    Thanks
    632
    Thanked
    1,192 times in 945 posts
    • GoNz0's system
      • Motherboard:
      • Asus Rampage V Extreme
      • CPU:
      • i7 something X99 based
      • Memory:
      • 16gb GSkill
      • Storage:
      • 4 SSD's + WD Red
      • Graphics card(s):
      • GTX980 Strix WC
      • PSU:
      • Enermax Galaxy 1250 (9 years and counting)
      • Case:
      • Corsair 900D
      • Operating System:
      • win10 64bit
      • Monitor(s):
      • Dell 24"
      • Internet:
      • 220mb Cable

    Re: Spyware/malware help

    yep, not had it return yet so it is looking like a 3rd party plugin I had as i have been adding back the safe bets, google plugins, quidco.


    "read and change all your data on the websites you visit" is in so many plugins details tab!

    Capitalization is the difference between helping your Uncle Jack
    off a horse and helping your uncle jack off a horse.

  8. #8
    DILLIGAF GoNz0's Avatar
    Join Date
    Jun 2006
    Location
    Derby
    Posts
    10,872
    Thanks
    632
    Thanked
    1,192 times in 945 posts
    • GoNz0's system
      • Motherboard:
      • Asus Rampage V Extreme
      • CPU:
      • i7 something X99 based
      • Memory:
      • 16gb GSkill
      • Storage:
      • 4 SSD's + WD Red
      • Graphics card(s):
      • GTX980 Strix WC
      • PSU:
      • Enermax Galaxy 1250 (9 years and counting)
      • Case:
      • Corsair 900D
      • Operating System:
      • win10 64bit
      • Monitor(s):
      • Dell 24"
      • Internet:
      • 220mb Cable

    Re: Spyware/malware help

    well I deleted a couple of unneeded extensions while disabling stuff, foolish as I can't remember what one was called and I think that may have been it as everything's enabled again. My router logs do not show those URLS again but I guess I need a bit longer to be sure it is gone.

    Capitalization is the difference between helping your Uncle Jack
    off a horse and helping your uncle jack off a horse.

  9. #9
    DILLIGAF GoNz0's Avatar
    Join Date
    Jun 2006
    Location
    Derby
    Posts
    10,872
    Thanks
    632
    Thanked
    1,192 times in 945 posts
    • GoNz0's system
      • Motherboard:
      • Asus Rampage V Extreme
      • CPU:
      • i7 something X99 based
      • Memory:
      • 16gb GSkill
      • Storage:
      • 4 SSD's + WD Red
      • Graphics card(s):
      • GTX980 Strix WC
      • PSU:
      • Enermax Galaxy 1250 (9 years and counting)
      • Case:
      • Corsair 900D
      • Operating System:
      • win10 64bit
      • Monitor(s):
      • Dell 24"
      • Internet:
      • 220mb Cable

    Re: Spyware/malware help

    meh, just happened again, back to square 1!

    Capitalization is the difference between helping your Uncle Jack
    off a horse and helping your uncle jack off a horse.

  10. #10
    DILLIGAF GoNz0's Avatar
    Join Date
    Jun 2006
    Location
    Derby
    Posts
    10,872
    Thanks
    632
    Thanked
    1,192 times in 945 posts
    • GoNz0's system
      • Motherboard:
      • Asus Rampage V Extreme
      • CPU:
      • i7 something X99 based
      • Memory:
      • 16gb GSkill
      • Storage:
      • 4 SSD's + WD Red
      • Graphics card(s):
      • GTX980 Strix WC
      • PSU:
      • Enermax Galaxy 1250 (9 years and counting)
      • Case:
      • Corsair 900D
      • Operating System:
      • win10 64bit
      • Monitor(s):
      • Dell 24"
      • Internet:
      • 220mb Cable

    Re: Spyware/malware help

    It is looking like this may be the problem https://chrome.google.com/webstore/d...er-info-dialog

    Reported this to chrome & kaspersky as it redirected a few minutes after enabling, seems crafty as it won't do it straight away.
    Last edited by GoNz0; 19-12-2015 at 10:10 AM.

    Capitalization is the difference between helping your Uncle Jack
    off a horse and helping your uncle jack off a horse.

  11. #11
    Registered+
    Join Date
    Feb 2010
    Location
    Cheshire
    Posts
    22
    Thanks
    0
    Thanked
    7 times in 5 posts

    Re: Spyware/malware help

    Seems very crafty, especially as it has decent reviews. If it is the culpript, may be worth changing your Hotmail/live/Outlook.com password - just as a precaution.

  12. Received thanks from:

    GoNz0 (19-12-2015)

  13. #12
    DILLIGAF GoNz0's Avatar
    Join Date
    Jun 2006
    Location
    Derby
    Posts
    10,872
    Thanks
    632
    Thanked
    1,192 times in 945 posts
    • GoNz0's system
      • Motherboard:
      • Asus Rampage V Extreme
      • CPU:
      • i7 something X99 based
      • Memory:
      • 16gb GSkill
      • Storage:
      • 4 SSD's + WD Red
      • Graphics card(s):
      • GTX980 Strix WC
      • PSU:
      • Enermax Galaxy 1250 (9 years and counting)
      • Case:
      • Corsair 900D
      • Operating System:
      • win10 64bit
      • Monitor(s):
      • Dell 24"
      • Internet:
      • 220mb Cable

    Re: Spyware/malware help

    Quote Originally Posted by davb View Post
    Seems very crafty, especially as it has decent reviews. If it is the culpript, may be worth changing your Hotmail/live/Outlook.com password - just as a precaution.
    You were correct, thankfully I use 2 factor authentication so they didn't get in

    Security challenge 12/12/2015 22:41 United States
    IP address 137.117.8.203 Device/platform Unknown Browser/application Unknown
    Last edited by GoNz0; 19-12-2015 at 07:45 PM.

    Capitalization is the difference between helping your Uncle Jack
    off a horse and helping your uncle jack off a horse.

  14. #13
    DILLIGAF GoNz0's Avatar
    Join Date
    Jun 2006
    Location
    Derby
    Posts
    10,872
    Thanks
    632
    Thanked
    1,192 times in 945 posts
    • GoNz0's system
      • Motherboard:
      • Asus Rampage V Extreme
      • CPU:
      • i7 something X99 based
      • Memory:
      • 16gb GSkill
      • Storage:
      • 4 SSD's + WD Red
      • Graphics card(s):
      • GTX980 Strix WC
      • PSU:
      • Enermax Galaxy 1250 (9 years and counting)
      • Case:
      • Corsair 900D
      • Operating System:
      • win10 64bit
      • Monitor(s):
      • Dell 24"
      • Internet:
      • 220mb Cable

    Re: Spyware/malware help

    Confirmed by Kaspersky labs.

    Dear customer,

    Please accept my apologies for not getting back to you earlier.

    The extension provided has been indeed detected as a potential risk program. We have added new detection for it as "Not-a-Virus:AdWare.JS.ChromeExt.a".

    No malicious software has been found on the websites provided. The malicious code may have been removed from our mail Anti-Virus server. If you have a local copy of the suspicious file, please send it to me in a password-protected archive, with password 'infected' (without quotes).

    1. http://thetraffic.info/?id=1450447602
    2. http://reprice.us/c/uCRH

    Thank you very much for your feedback.

    Capitalization is the difference between helping your Uncle Jack
    off a horse and helping your uncle jack off a horse.

  15. Received thanks from:

    peterb (18-01-2016)

  16. #14
    Senior Member Bonebreaker777's Avatar
    Join Date
    Dec 2012
    Location
    Herts, UK
    Posts
    2,035
    Thanks
    55
    Thanked
    203 times in 186 posts
    • Bonebreaker777's system
      • Motherboard:
      • MSI H97I AC
      • CPU:
      • Xeon 1225 v3 + Freezer 11 L
      • Memory:
      • 2 x 4GB 1600Mhz 1T-8-8-8-20 1.35V Crucial BallistiX Tactical VLP
      • Storage:
      • 128GB CRUCIAL MX100///XPEnology server + 3 x WD Purple 3TB
      • Graphics card(s):
      • Intel HD 4600
      • PSU:
      • be quiet! L8 300W PSU BN220
      • Case:
      • Cooler Master Elite 120
      • Operating System:
      • Windows 10 Pro 64bit
      • Monitor(s):
      • Samsung SyncMaster 226BW
      • Internet:
      • Virgin 100Mb

    Re: Spyware/malware help

    Junkware removal Tool and Malware Bytes had no significant result in safe mode?

  17. #15
    DILLIGAF GoNz0's Avatar
    Join Date
    Jun 2006
    Location
    Derby
    Posts
    10,872
    Thanks
    632
    Thanked
    1,192 times in 945 posts
    • GoNz0's system
      • Motherboard:
      • Asus Rampage V Extreme
      • CPU:
      • i7 something X99 based
      • Memory:
      • 16gb GSkill
      • Storage:
      • 4 SSD's + WD Red
      • Graphics card(s):
      • GTX980 Strix WC
      • PSU:
      • Enermax Galaxy 1250 (9 years and counting)
      • Case:
      • Corsair 900D
      • Operating System:
      • win10 64bit
      • Monitor(s):
      • Dell 24"
      • Internet:
      • 220mb Cable

    Re: Spyware/malware help

    Quote Originally Posted by Bonebreaker777 View Post
    Junkware removal Tool and Malware Bytes had no significant result in safe mode?
    Why would it, I was the 1st to log this and have it confirmed as a new threat, I had already removed it by the time it was added to the database.

    Capitalization is the difference between helping your Uncle Jack
    off a horse and helping your uncle jack off a horse.

  18. #16
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: Spyware/malware help

    Good call, and excellent result to hammer a nail into spamware.
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •