
I just had a redirect @ BTJunkie(I've got google-analytics blocked there)...
Assume we're referring to btjunkie.org? I just went there. Script allowed. No redirect. Tried clicking a random page. No redirect. If it was an internal page, please provide exact URL.myBad wrote:...or not![]()
I just had a redirect @ BTJunkie(I've got google-analytics blocked there)...
lol, I haven't seen anyone doing personal websurfing there, but since the computer is on a desk used by a part time employee and is the closest computer to the break room and the time clock, it's quite possible they were doing it on their breaks. There are so many innocent sites hacked, it wasn't necessarily anything more suspicious than checking to see when their kids have early dismissal from school to request time off.Tom T. wrote:Why are you going to all those sites on the company's computer and time?AlphaCentauri wrote:...I'd love to know who downloaded the malware in the first place and from where (shared work computer),
The btjunkie redirects occur shortly after performing a search. The query of the search has been irrelevant in my experiences.Tom T. wrote: Assume we're referring to btjunkie.org? I just went there. Script allowed. No redirect. Tried clicking a random page. No redirect. If it was an internal page, please provide exact URL.
I should also mention that Adblock Original shows two blocked subdocument iFrames, both from bluelithium.com, an ad server. This was also true at a related post that I just marked "resolved". (Warning: @dult site.)
I like Adblock Original -- it blocks all that stuff by default, with no user action. I use it all the time. You might try it and see if it helps.
I allowed "everything" on the page in NS, disabled Adblock, disabled Fx pop-up blocker, did several searches, and still couldn't reproduce.myBad wrote:...The btjunkie redirects occur shortly after performing a search. The query of the search has been irrelevant in my experiences....
Sounds like a Sysadmin Group Policy problem to me! (and don't all kids today have cell phones and text messaging anyway? lol)AlphaCentauri wrote:lol, I haven't seen anyone doing personal websurfing there, but since the computer is on a desk used by a part time employee and is the closest computer to the break room and the time clock, it's quite possible they were doing it on their breaks. There are so many innocent sites hacked, it wasn't necessarily anything more suspicious than checking to see when their kids have early dismissal from school to request time off.Tom T. wrote: Why are you going to all those sites on the company's computer and time?
But I sure would have liked to have seen the browser history!
http://adblock.mozdev.org/myBad wrote:I'm unable to find Adblock Original. I guess Mozilla took it off of their site.
It's worth a try before wiping the disk. Or after. GL.It's obvious malware. At this point, I think I'm just going to wipe the disk.