We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Is my PC infected?

I've had the following two pages popup whilst viewing Gumtree. It only happens on Gumtree and has come up at least 10 times now.


I tried running the malicious software removal tool but it found nothing.




Untitled_zps38a480a0.jpg


jh_zpsa9185196.jpg
«1

Comments

  • somersethillbilly
    somersethillbilly Posts: 524 Forumite
    edited 17 November 2014 at 6:55PM
    Check that Flash Player is up to date.

    http://helpx.adobe.com/flash-player.html

    Download and run Malwarebytes Anti-Malware, do not select the trial when installing.
  • esuhl
    esuhl Posts: 9,409 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    That doesn't look like a genuine message.

    Try scanning with MB Anti-Malware: http://www.malwarebytes.org/

    And then adwCleaner: https://toolslib.net/downloads/viewdownload/1-adwcleaner/
  • maas
    maas Posts: 512 Forumite
    Part of the Furniture 100 Posts I've been Money Tipped!
    The adverts are fake, just make sure you dont install the dodgy program masquerading as an Adobe Update.

    You can get those adverts from time to time from general web browsing, but if you find they are popping up all the time (like every day) then you'll have something on your computer running triggering them.
  • I'd run ccleaner too and its inbuilt registry cleaning tool.


    'Hijack this' is an effective old classic that'll display all running processes, startup items, safe zone sites, BHO - browser helper (read hijacking) objects etc.


    Update your flash direct from the flash site. General rule of thumb is if anything pops up asking you to click/download, be suspicious.


    I fell victim to the ransomware worm/virus a few months back. That was a nuisance. Pop up telling me to pay £200 to unlock my computer. After wiping out that annoyance I significantly upped my security settings - nothing gets in here now without my say-so. Makes applying for accounts and credit cards frustrating sometimes if I don't add the site to the safe zone first. Worth it though. I've not detected a single piece of malware since despite almost daily checks.
  • Strider590
    Strider590 Posts: 11,874 Forumite
    Gumtree makes money from selling targeted advertising space, a dodgy ad is creating those popup messages.
    “I may not agree with you, but I will defend to the death your right to make an a** of yourself.”

    <><><><><><><><><<><><><><><><><><><><><><> Don't forget to like and subscribe \/ \/ \/
  • Thats malware or spyware and not genuine firstly run your AV scan fully. Also reset IE in internet options.
    Kind Regards,
    Arron
    Gadget Geek on Smartphones, Android and Apple, Windows, Apple Mac
  • esuhl wrote: »
    That doesn't look like a genuine message.

    Try scanning with MB Anti-Malware: http://www.malwarebytes.org/

    And then adwCleaner: https://toolslib.net/downloads/viewdownload/1-adwcleaner/

    Second this, I would also run ccleaner (it will delete your cache, history, cookies etc) You can get it here https://www.piriform.com/ccleaner/download
  • Just to complicate matters further, it might just be your router which has been compromised, rather than your computer.

    Just over six months ago, a number of router makes had their traffic routed via servers mostly in the USA, and this normally manifested itself as warnings to update Flash Player. The update warning was simply an attempt to get users to download virus/malware. I didn't - I was suspicious and noticed a couple of spelling mistakes also.

    My router, made by TP-Link (very many TP-Link routers are/were vulnerable as well as other makes), was compromised and other family machines using my network (including an ipad) had unexpected update messages, suggesting that it was the network rather than my machine which was compromised. I had gone through all of the normal malware checks on our machines first, without finding anything amiss.

    I then undertook a number of internet searches which confirmed my suspicion that my router had been compromised. Here are a couple:

    ***.bleepingcomputer.com/forums/t/526875/flash-update-virus-damaged-router/

    ***.pcworld.com/article/2104380/attack-campaign-compromises-300000-home-routers-alters-dns-settings.html

    Replace all * with w - newcomer here and not allowed to post direct links.

    Essentially, it seems that many routers can be compromised in a similar way to the newspaper 'phone hacking - it depends on the admin password still being at its default which means that the router traffic can be redirected by a third party. Even though nothing had been downloaded and installed to my laptop, I still felt very exposed that my traffic was going via servers presumably controlled by hackers and thieves.

    The solution in my own case was a hard reset (unplugged and then a reset was done when it was plugged back in - both together are probably a bit overkill, but belt and braces....) and changing the admin password. If you suspect that this might have happened to you then your router manufacturer is probably the best place to go for advice.

    That uncomfortable, not quite secure, feeling remains with me despite following TP-Link's advice, and even now, seven months later, I regularly check my router settings using 'IP address lookup' to ensure that my traffic is going through 'expected' UK servers (in my case Tiscali/talk talk).

    Complicated but I hope that you manage to sort this out. If the malware scans don't find anything, then suspect your router. It may be that this vulnerability is still being exploited.
  • Laz123
    Laz123 Posts: 1,742 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Also run MBAN.
  • esuhl
    esuhl Posts: 9,409 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    WorkerB wrote: »
    Just to complicate matters further, it might just be your router which has been compromised, rather than your computer.

    Avast has a component that lets you scan your network for compromised routers. I don't know how effective it is, but my network was given the all clear.

    Is the main vulnerability in routers due to having UPnP enabled? That has always seemed a risky option (and is enabled by default on most home routers). I have it disabled and use port-forwarding for the odd occasions I want a device to respond to an incoming connection.

    https://nakedsecurity.sophos.com/2013/02/05/upnp-flaws-turn-millions-of-firewalls-into-doorstops/
    http://www.howtogeek.com/122487/htg-explains-is-upnp-a-security-risk/
    http://www.zdnet.com/how-to-fix-the-upnp-security-holes-7000010584/
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.5K Banking & Borrowing
  • 254.2K Reduce Debt & Boost Income
  • 455.1K Spending & Discounts
  • 246.6K Work, Benefits & Business
  • 603K Mortgages, Homes & Bills
  • 178.1K Life & Family
  • 260.6K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.