Notebookforums
 
 Home 
       
 Forums 
 
 Guides 
   
Old 12-30-2009, 05:38 PM   #1
Garbuckle
Vive le Backbacon!
 
Garbuckle's Avatar

Join Date: Mar 2006
Location: tor.ont.eh?
Posts: 9,502
Credits: 76,598
 
Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!
Redirecting adware due to Adobe Flash

This is a post to share my current experience / problems with some stubborn adware.

I originally got a virus/trojan while trying to view an internet stream. I was running MS Security Essentials, which caught and removed the virus. I thought everything was back to normal.

Then I noticed that once in a while, I would randomly get redirected in my browser to a "primawega" ad site, or sometimes "nysearchengine" or other such nonsense. After much research, I learned that there was no adware program that would detect this adware, and yet many people are having the same problem. It looks like the only resort is to reformat your pc!

At first, I thought it was a FireFox only problem, and switched to IE. Then I got the same error in IE. While it doesn't appear to cause any damage, it is extremely annoying.

Then one day, I noticed a link in my start programs for IE 64-bit (which isn't the default IE, even on Win 7 64-bit). I figured with a 64-bit PC and OS, I should use a 64-bit browser. It works well, except for one small problem: Adobe Flash does not work in 64-bit browsers (but they say they are working on a 64-bit version). Oh well, I figured I would just use the 32-bit when I need Flash (i.e. Youtube and other media streams).

After a while of using the 64-bit, I noticed I was no longer getting redirects! It is therefore my conclusion that the adware redirect problem is due to some script or plugin associated with Adobe Flash. A re-install of Flash did not help. This thing is really buried somewhere.

I still feel a reformat of my PC is needed, but at least I know now how to avoid the adware for the most part (except for the times where I need a media stream and have to use the 32-bit browser).

So, if anyone else is experiencing this problem, at least now you know what is causing it, and a way to avoid it. Alas, my only solution at the moment is not a good one (reformat), but perhaps this post can enlighten others.
__________________
Antec Black Fusion 430 Intel E8400 2 x WD 500GB SATA Asus P5K-VM Mushkin 4 X 1GB DDR2-800 @ 667 1:1 Iomega 500GB ScreenPlay LaCie 300GB FW800 MS Sidewinder X6 MS Sidewinder Samsung 32" HDTV Logitech Harmony 880 Asus 8800 GT 512MB @ 600MHz Belkin N1 Vision Denon 1508, Klipsch Quintet II, Boston Acoustics HPS10SE

Cole's Axiom: The sum of the intelligence on the planet is a constant; the population is growing.

P @ 7k, 13.8k, 20.6k, 27.4k, 34.2k, 41.0k, 47.8k, 54.6k, 61.4k, 68.2k
Garbuckle is online now   Reply With Quote

Old 12-31-2009, 05:52 AM   #2
Mr T
Registered User
 
Mr T's Avatar

Join Date: Nov 2007
Posts: 338
Credits: 2,456
 
Mr T is cool enough to have people show up to his/her party!
Tried this:

1) Download CrapCleaner, Malwarebytes Antimalware, SuperAntispyware (google for them, but some can be downloaded from http://www.filehippo.com ...

2) Install them all and update
3) delete your IE cache using properties of IE
4) Run CrapCleaner
5) Boot into SAFE MODE and run Antimalware and SuperAntispyware..
Mr T is offline   Reply With Quote
Old 12-31-2009, 04:03 PM   #3
Garbuckle
Vive le Backbacon!
 
Garbuckle's Avatar

Join Date: Mar 2006
Location: tor.ont.eh?
Posts: 9,502
Credits: 76,598
 
Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!
Have you personally experienced this problem and does doing what you indicate solve the issue?

...and it's not specifically an IE problem, but that's besides the point.
__________________
Antec Black Fusion 430 Intel E8400 2 x WD 500GB SATA Asus P5K-VM Mushkin 4 X 1GB DDR2-800 @ 667 1:1 Iomega 500GB ScreenPlay LaCie 300GB FW800 MS Sidewinder X6 MS Sidewinder Samsung 32" HDTV Logitech Harmony 880 Asus 8800 GT 512MB @ 600MHz Belkin N1 Vision Denon 1508, Klipsch Quintet II, Boston Acoustics HPS10SE

Cole's Axiom: The sum of the intelligence on the planet is a constant; the population is growing.

P @ 7k, 13.8k, 20.6k, 27.4k, 34.2k, 41.0k, 47.8k, 54.6k, 61.4k, 68.2k
Garbuckle is online now   Reply With Quote
Old 01-01-2010, 02:46 AM   #4
Mr T
Registered User
 
Mr T's Avatar

Join Date: Nov 2007
Posts: 338
Credits: 2,456
 
Mr T is cool enough to have people show up to his/her party!
Quote:
Originally Posted by Garbuckle View Post
Have you personally experienced this problem and does doing what you indicate solve the issue?

...and it's not specifically an IE problem, but that's besides the point.
Yep, and adobe flashplayer is an add on to IE so it specifically exploits that, cannot remember the name of the virus, but it left a residue in IE (7) with peculiar names such as hmjjl as I remember.... It took 50 pages of google trawl through to find Antimalware and Super Antispyware resolved... Scanning with Norton, AVG, Trend and Mcafee online scanners picked up zilch... Afterwards, I updated to IE8, did all windows updates, installed latest version of AVG free and update it regular, and I regularly clear the IE cache... Not hit since...
Mr T is offline   Reply With Quote
Old 01-02-2010, 11:28 AM   #5
Garbuckle
Vive le Backbacon!
 
Garbuckle's Avatar

Join Date: Mar 2006
Location: tor.ont.eh?
Posts: 9,502
Credits: 76,598
 
Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!Garbuckle posts at Mach speed!
OK, it appears I have found the culprit. For some reason, there was a "Loudmo Contextual Ad Assistant" in the "program uninstall" area of CCleaner, while it was not listed in the usual Windows add/remove. Upon further research, I found that this Loudmo is linked to the redirects (i.e. to primawega and iamwired, etc). I promptly removed it, and haven't yet had any more redirects.

It's interesting to note that there is tons of information on this Loudmo, and yet their practices are not illegal? The fact that they deal with FLV shows their Flash connection. Here's some links/proof:

A detail of the threat level:
http://www.threatexpert.com/report.a...89d1ea7106c26a

A forum with the same solution:
http://support.mozilla.com/no/forum/1/532304

A forum with someone affiliated with Loudmo trying to recruit users of their adware:
http://forums.digitalpoint.com/showthread.php?t=1604846

And they even have a website with contact info:
http://www.loudmo.com/support/

So, if anyone experiences the same problems, I suggest running CCleaner and seeing if you have this Loudmo thing installed.
__________________
Antec Black Fusion 430 Intel E8400 2 x WD 500GB SATA Asus P5K-VM Mushkin 4 X 1GB DDR2-800 @ 667 1:1 Iomega 500GB ScreenPlay LaCie 300GB FW800 MS Sidewinder X6 MS Sidewinder Samsung 32" HDTV Logitech Harmony 880 Asus 8800 GT 512MB @ 600MHz Belkin N1 Vision Denon 1508, Klipsch Quintet II, Boston Acoustics HPS10SE

Cole's Axiom: The sum of the intelligence on the planet is a constant; the population is growing.

P @ 7k, 13.8k, 20.6k, 27.4k, 34.2k, 41.0k, 47.8k, 54.6k, 61.4k, 68.2k
Garbuckle is online now   Reply With Quote
Old 01-02-2010, 02:58 PM   #6
qhn
... am invisible
 
qhn's Avatar

Join Date: Mar 2006
Posts: 33,407
Credits: 94,668
 
qhn posts at Mach speed!qhn posts at Mach speed!qhn posts at Mach speed!qhn posts at Mach speed!qhn posts at Mach speed!qhn posts at Mach speed!qhn posts at Mach speed!qhn posts at Mach speed!qhn posts at Mach speed!qhn posts at Mach speed!qhn posts at Mach speed!
Good one there Garb

cheers ...
__________________
m6805@3700; SZ71WN/C ; Macbook 2ghz/4gig/250gb/superdrive; 7811FX
are u Folding@Home? - Firefox Beta - MediaPortal "the" Media Centre/HTPC!
qhn is online now   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Adobe Flash Player Help?? Top Hat Windows Operating Systems & Software (Windows 7 questions here) 3 10-10-2009 08:31 AM
adware help Synergism Dell Legacy (single-core notebooks) 23 06-23-2005 02:23 PM
got killed on adware ocean158 Sager & Clevo Notebooks 13 11-04-2004 01:16 PM



All times are GMT -6. The time now is 09:29 AM.


Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright © 2001-2010 NotebookForums LLC