Solved

linkbucks.com malware

Posted on 2014-02-16
12
431 Views
Last Modified: 2014-05-10
would appreciate some help in dealing with this intermittent malware that affects some websites by appending a url to the links on that website on mouse down event.
same website when accessed using different dns appears to be normal.
cleaning history and temp files temporarily resolves the problem, but it comes back.
DNS behavior appears to be normal as well.
Any ideas?
0
Comment
Question by:tazm
  • 4
  • 3
  • 2
12 Comments
 
LVL 52

Expert Comment

by:Scott Fell, EE MVE
ID: 39863038
Is this a site you control or other sites?  Firs check if you yourself have an issue.  For windows use anti malware http://www.microsoft.com/security/pc-security/malware-removal.aspx don't even bother with the quick version, do the long.  

If it is for sure other sites, there is nothing you can do, they have an sql injection somewhere.  Try searching for the site on google and see if they have detected.  You can also check to see if a site is infected by searching on https://www.stopbadware.org

The best thing is to stay away from those sites. If it is your site, you probably have a cms like wordpress.  Try and use an older back up of your database as soon as possible.
0
 

Author Comment

by:tazm
ID: 39863143
thanks for the answer.

its not my site.

I have noticed that changing the DNS resolves the problem, however strange that is, even though the ISP's DNS checks out as clean.
0
 

Author Comment

by:tazm
ID: 39864009
a similar problem was seen with an ISP in Peru
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 52

Expert Comment

by:Scott Fell, EE MVE
ID: 39864021
I'm not 100% sure you don't have something on your own system.  Make sure you run the anti malware program from microsoft.  Run the "long" version and not the quick.

Good luck!
0
 
LVL 23

Expert Comment

by:Mohammed Hamada
ID: 39865721
If this is an ISP issue then I suggest that you try to install a linux OS in a Virtual machine using something like Oracle virtual box and see if problem exists there.

http://www.oracle.com/us/technologies/virtualization/virtualbox/overview/index.html
0
 
LVL 52

Expert Comment

by:Scott Fell, EE MVE
ID: 39937203
Did the Microsoft anti malware program do the trick?  Or did you just close out the question?
0
 

Author Comment

by:tazm
ID: 39938977
I just closed the question.
0
 

Author Comment

by:tazm
ID: 39940691
Well no one answered the question correctly, and no I haven't found the answer myself also, so what? shall I just leave the question open forever? so I cannot ask any more questions? does that make any sense to you?

I have already cancelled my subscription to this place, its worthless.
0
 
LVL 23

Accepted Solution

by:
Mohammed Hamada earned 500 total points
ID: 39941660
Tazm, we have made some comments after your latest comment and the only thing you did is awarded points to Scott to just close the question.

If  you don't cooperate with us we will never be able to find out your issue. Have you tried to check another machine in your network?

I would check your windows host file, it might be redirecting your request to something else.

Please download hostsxpert from this link
HostsXpert

Install and run Hostxperts as administrator, then on the left side click restore MS Hosts file then Click on Make read only.

Next download Hijackthis

Install hijackthis and then run then do system scan and save log. please attach it here!

Thanks
0

Featured Post

Master Your Team's Linux and Cloud Stack

Come see why top tech companies like Mailchimp and Media Temple use Linux Academy to build their employee training programs.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
I've been an avid user and supporter of Malwarebytes Premium Version 2.x for years. It's an excellent product that runs alongside just about any Anti-Virus application without issues. It seems to have an uncanny ability to pick up many things that A…
This video teaches users how to migrate an existing Wordpress website to a new domain.
Learn how to set-up custom confirmation messages to users who complete your Wufoo form. Include inputs from fields in your form, webpage redirects, and more with Wufoo’s confirmation options.

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question