Alert - Google redirect virus

  • Active since 1995, Hearth.com is THE place on the internet for free information and advice about wood stoves, pellet stoves and other energy saving equipment.

    We strive to provide opinions, articles, discussions and history related to Hearth Products and in a more general sense, energy issues.

    We promote the EFFICIENT, RESPONSIBLE, CLEAN and SAFE use of all fuels, whether renewable or fossil.
Status
Not open for further replies.
Many hijacks occur when admin credentials are stolen while an admin is logged in.

One thing we do at work and now I do at home is set up non-admin accounts for all users, even myself. "Power User" or "Network User" are good built-in presets for user levels. Admin operations can be handled using Windows' "runas" command without the need to log in and out.

Its a little bit of a hassle but I've been able to keep multiple machines clean this way without having to reformat.
 
Jags said:
mayhem said:
I've pretty much stopped putting massive efforts into virus/malware repair. Do your best to do a data backup and nuke it.

Ding, ding, ding.

I take an overview of the infection and decide on which will take less time. Flushing out the virus, or flushing the drive.

Same here. The redirect virus is the only one that I've personally encountered and found it to be a PITA. Most variants of it don't send any of your personal information to the owner or cause any actual harm to you... Just incredibly annoying. I bet places like best buy make a killing off of dummies when they bring in a computer infected with it.
 
I run Malwarebytes once in a while - is it worth it to upgrade from the free version and buy the 'Realtime Protection Module'? Would that pick something like this up right away before it does damage? Would it slow my computer down a lot while it was doing its thing in the background?
 
ill sound stupid for asking but... how do you end up with it and... can it happen to a cell phone that runs a BREW OS also? thats what my phone runs so i was just wondering.
 
Status
Not open for further replies.