About two weeks ago, Norton picked up on a file named "Suspicious.Cloud". It was a trojan. Shocker, right? I looked it up, and apparently it acts like a chameleon of sorts by constantly changing its coding so antiviruses can't pick up on it. I didn't download anything; Norton found it right after I updated my definitions, so I assume it had been on my computer for a while. My computer hadn't been acting funky, though, and Norton said it successfully removed it, so I didn't pay it much attention.
A few days later, I was Googling something- don't remember what, though I doubt it matters, as I didn't visit any suspicious looking sites -I clicked on one of the links, and instead of being taken to the website Google had listed, I was redirected to some "Monster Marketplace". I backed up and clicked the link again, and I was taken to the website I originally intended to go to. This kept happening throughout the night. Norton didn't pick up on anything, though I ran MBAM and had it remove three files it found. That seemed to be the problem, but soon I started getting redirected again, and to even more sites this time. I ran HijackThis and deleted two suspicious files... can't remember what they were called, something with "adhook" in the name, and I figured that they couldn't be good. Again, the problem subsided for a bit, but now I'm being redirected to even MORE sites- eBay, Scour.com, video sites, and more that I didn't bother to identify. The Monster Marketplace still comes up on occasion, as well.
Looking through my history, I've found some suspicious looking pages; one named "Redirect", which always comes up before the Monster Marketplace site; a bit more than a dozen called "nclk", that lead me to the sites I'm getting redirected to; and two named "c.php". This "c.php" might be the cause of my problem: when I clicked this, I was redirected to a very slow loading page, which abruptly had its connection reset when Norton popped up and said that "a recent attempt to attack my computer was blocked".
There's a depressingly small amount of reliable information on this out there. The virus (or whatever you'd call this) seems to have several different strains that redirect to different websites at different levels of frequency- compared to what I've read, I'm lucky in that this only happens about half the time, and that I can simply go back a page and click the link again to correct it. However, I'd like to correct the problem before it becomes more serious.
...wow, that's a lot of text. Anyone that bothers to read all that, could you please give me some suggestions?
This post has been edited by hamluis: 03 April 2011 - 04:47 PM
Reason for edit: Moved from XP to Am I Infected.

Help

Back to top










