PDA

View Full Version : Another one for the computer geeks



Squisha
Wed Nov 30th, 2011, 07:09 AM
I'm fairly savvy with computers (red belt, maybe a brown belt) and I have learned alot about how to prevent infection and how to deal with it when it happens. I'm stumped on this though and there seems to be very little information out there even though it appears not to be new by any stretch:

Browser Jacking (clickjacking)

This happened on my work computer where they're freaky about security. The local computer geeks took my computer for a day, returned it declaring it cured, then took it again for two days the next morning. (This was all at $120/hr!) I have it back but it's still showing signs of infection. This appears to be some kind of Java exploit.

I installed NoScript, and found the punchline to the joke, so to speak. When I did a search on Google, my computer acted like it wanted to go where I clicked, then returned to google. I checked "recently blocked sites" in NoScript and found that my computer had been forced to attempt to go to "Webplains.net". NoScript blocked it but it means I've still got something. Malwarebytes found nothing, nor did the Trend Micro thing they've got on my comp here.

Whip out your big brains, guys. What say you on this?

LambeauXLIV
Wed Nov 30th, 2011, 07:26 AM
hosts file and internet settings reset?

LambeauXLIV
Wed Nov 30th, 2011, 07:28 AM
also, you could check out trend micro's hijack this tool, but be careful what you remove....

birchyboy
Wed Nov 30th, 2011, 07:37 AM
I'm not sure if you're running Windows XP or similar, but it is possible your DNS entries have been compromised. Try opening a command prompt and typing in the following:

ipconfig /flushdns

This should reset your DNS entries to an empty set and every page you open should resolve to the correct website/IP address. There is likely a similar Linux command but I don't know it off the top of my bald head.

Good luck!

Squisha
Wed Nov 30th, 2011, 08:01 AM
Thanks guys.

I've looked into HijackThis but I lack the knowledge to work confidently at this point. I'd need to spend a day doing my research. I'll keep that one in my hip pocket for now.

Our computer guy said my Java console was out of date and that was the issue. He updated it but didn't disable the old versions (there were three). I disabled them and coincidentally haven't seen that nasty old webplains thing come up since. Coincidence? My knowledge of Java is limited.

Ricky
Wed Nov 30th, 2011, 08:37 AM
I don't have to deal with much of that stuff anymore... But when I do, I redo the entire computer. At my last job, if we couldn't fix a virus problem within 15 minutes, we would just re-image their machine. We could do that in about 30 minutes vs spending even a full hour on trying to remove it.

What browser are you using? Have you tried others?

Scatterbrain
Wed Nov 30th, 2011, 07:42 PM
Stop searching porn and your pc will work great. I'm tellin ya it works...LOL

Wrider
Thu Dec 1st, 2011, 12:17 AM
But then how would I see all of my girlfriends???