Asklots.com and Bing
Results 1 to 14 of 14

Thread: Asklots.com and Bing

  1. #1
    Join Date
    Jun 2005
    Location
    Ft Myers FL
    Posts
    8,520

    Asklots.com and Bing

    I'm rusty and looking for answers - not links. Our family-room computer got infected with SecurityTools and after getting rid of it (or so I thought) my wife gets unprompted popups for Asklots.com. Odd thing is, when she now does Google searches and clicks on a link she gets redirected to this Asklots.com, but when she clicks back or double-clicks back on the browser to back out of the suspect site she's redirected to Bing.

    I thought I'd looked in all the possible places for this little stinker. Anyone else run into this? Any solutions from the VDr faithful?

  2. #2
    photolady's Avatar
    photolady is offline Lifetime Friend of Site Staff
    Join Date
    Mar 2002
    Location
    At my computer, cruising VDR and watching your back
    Posts
    23,412
    Which OS?

  3. #3
    Join Date
    Jun 2005
    Location
    Ft Myers FL
    Posts
    8,520
    XP/SP3 using IE7

  4. #4
    photolady's Avatar
    photolady is offline Lifetime Friend of Site Staff
    Join Date
    Mar 2002
    Location
    At my computer, cruising VDR and watching your back
    Posts
    23,412
    Where did you look? If I knew where all you looked I might be able to suggest some place else.

  5. #5
    Join Date
    Jun 2005
    Location
    Ft Myers FL
    Posts
    8,520
    All Local Settings and Application Data folders in all users; NetHood and PrintHood hiding places; Program Files (any folder/program I don't know well); Favorites and Bookmark folders; Documents and subfolders.

  6. #6
    photolady's Avatar
    photolady is offline Lifetime Friend of Site Staff
    Join Date
    Mar 2002
    Location
    At my computer, cruising VDR and watching your back
    Posts
    23,412
    Did you search the registry? Or the computer for Asklots? Did you dump system restore points?

    I would also do a Hijackthis log, that should show where this thing is hiding, too.

  7. #7
    Join Date
    Jun 2005
    Location
    Ft Myers FL
    Posts
    8,520
    Done, done and done and it eludes HJT. Its effects show up, but they change on each boot so it's not readily evident that the same source is responsible for everything.

    I did follow a tip from the MajorGeeks forum, which said this thing hides inside routers and to reset the router. I went one step better and reinstalled the router firmware and the thing was disabled enough for me to get a handle on cleaning it out. More details as I find it all.

  8. #8
    Join Date
    Jul 1998
    Location
    Toronto
    Posts
    26,541
    Worth noting is that our malware experts have lately started changing the recommended scanners to troubleshoot infections.

    DDS is preferred over hijackthis and superantispyware is not as popular. There are also some new scanners that I'm not that familiar with.

    In any case you might want to start a new thread in the intensive care forum if the infection doesn't want to go away.
    _____________________
    cat lovers click here

  9. #9
    Join Date
    Jun 2005
    Location
    Ft Myers FL
    Posts
    8,520
    As some of you may already have seen, it infected our email address book and sent out "love notes" to all and sundry. Anyone know offhand the file extension for a Hotmail address book?

  10. #10
    Join Date
    Jul 1998
    Location
    Toronto
    Posts
    26,541
    I didn't think the hotmail address book was resident on the PC. I assumed it only loaded within the browser and would only be present in the TIF.

    You could open hotmail address book and then have a look at the source page to see more details of it though.

    Having said that it probably didn't infect the address book so much as use its contents.
    _____________________
    cat lovers click here

  11. #11
    Join Date
    Jun 2005
    Location
    Ft Myers FL
    Posts
    8,520
    Further investigation shows you're right, amigo. Even the attachments weren't resident, but URL download links from 65dot55dot39dot119. Tracked that down to Bellevue, WA (kinda funny, right around the corner from Redmond) and couldn't go further. It seems to have been isolated.

  12. #12
    Join Date
    Jul 2002
    Location
    NYC Metro area
    Posts
    2,228
    Quote Originally Posted by fink View Post
    DDS is preferred over hijackthis and superantispyware is not as popular. There are also some new scanners that I'm not that familiar with.
    I've been watching this with interest. What's DDS?

    Win7 Ult/ 3.40 GHZ Intel Core i5-3570K /ASRock mobo Z77 Pro4 /SSD/ EUFI MS 3400 MHZ/8 GB RAM; Win 7 Ult/Verizon FIOS wired network
    Waterfox Classic/Chrome / Firefox 115esr
    --------------------------------------------------------------------------------
    "The medium is the message." - Marshall McLuhan

  13. #13
    Join Date
    Jun 2005
    Location
    Ft Myers FL
    Posts
    8,520
    It's one of a handful of pseudo-HJT analyzers out there being used to diagnose and disinfect computers. OTL is another one, which I just used. (Had nothing to lose, since I was prepared to reinstall XP over itself if I had to.) HJT seems to have reached the point of arrested development, and I was pleasantly surprised at how much more comprehensive OTL is.

    As with HJT, unless you're familiar with reading the results - or extremely adventurous and don't mind bricking your OS with a wrong move! - it's advised you follow instructions from an experienced user at a reputable forum.

  14. #14
    Join Date
    Jul 1998
    Location
    Toronto
    Posts
    26,541
    It's a program very similar to Hijackthis but comes from a different source.

    http://download.bleepingcomputer.com/sUBs/dds.scr

    Hijackthis, like many scanners, especially those that have been taken over from their original developers hasn't quite kept up with the malware that's constantly being written faster than it's upgrades.
    _____________________
    cat lovers click here

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •