Video Cop? Anyone else?

Status
Not open for further replies.

pugsandkids

Well-Known Member
10 Year Member!
Joined
Mar 18, 2010
Messages
1,019
Often when I'm trying to log on to TF, or simply moving from one thread to another, I end up on a site called Video Cop. It happens on all three of the computers in my house. Does this happen to anyone else? I don't know if its a site thing, my network, or?
 

Josh

Ask questions, share answers, talk torts!
TFO Admin
10 Year Member!
Joined
Aug 15, 2007
Messages
4,126
Location (City and/or State)
Redlands, CA
I'm with Cory. Smells like somethin fishy. Could be spyware too...
 

Yvonne G

Old Timer
TFO Admin
10 Year Member!
Platinum Tortoise Club
Joined
Jan 23, 2008
Messages
93,448
Location (City and/or State)
Clovis, CA
Never happens to me. I'd have to agree with the above comments. Your computers have become infected!
 

pugsandkids

Well-Known Member
10 Year Member!
Joined
Mar 18, 2010
Messages
1,019
Damnit! Thats what I was afraid of...Thanks for the confirmation folks ;D
 

dmmj

The member formerly known as captain awesome
10 Year Member!
Joined
Aug 15, 2008
Messages
19,670
Location (City and/or State)
CA
mika09 said:
hello.It seems to me that you are not so sure about your antivirus.If you want to change it I can recommend you top ten best antiviruses (spam link deleted by mod)
hope it will be usefull
LOL I always love how polite the spammers are.
 

michael2

New Member
5 Year Member
Joined
Sep 2, 2010
Messages
1
I was infected by the VideoCop bug, and it took me long time to figure out how to get rid of it. I’m really impressed by the ingenuity of its developers. It’s unlike any Malware I’ve ever dealt with before.
First off, let me go over the symptoms. You will frequently see advertisements for VideoCop on legitimate, well respected web sites that would never allow malicious web sites to advertise on their web pages. Mostly these ads show up on Google ad space.
Firefox frequently hangs as it’s trying to contact Google analytics.
After doing a Google search, and clicking on a result, you will be taken you to an unrelated, malicious web site, but if you “back arrow” to the results and click the link again, you will go to the correct web site.
The root of the problem is not on your computer, it’s on your router. Somehow, and I’m not quite sure how, the DNS entries on your router have been changed. I have a Linksys WRT54G v6.0 with the latest firmware, and the default password was changed the day I turned it on. My Wi-Fi security is enabled, even with MAC filtering. For the record, the DNS servers were 213.109.68.7, 213.109.73.245, 1.1.1.1.
I can only think of two ways this happened. Most likely, the Malware used my router’s password that was cached in my browser, or there is a vulnerability in the router that is being exploited. If the VideoCop hackers are using a vulnerability, there’s nothing we can do to prevent this from happening again except wait for Linksys to release a new firmware that fixes the vulnerability. But if it’s using a cached password, the solution is to never cache your router’s password.
To resolve this problem, first log into your router and change your password, and log back in with the new password. If IE or Firefox asks you if it should remember your password say “No”. Now clear the DNS servers (all 3) by putting 0’s in the boxes. 0.0.0.0 will tell your router to use your IPS’s DNS settings which are obtained as part of the DHCP protocol. Now fully scan your computer with MalWareBytes, Spybot Search and Destroy, and any other Spyware remover. Also, do a full scan with your resident antivirus since you’ve possibly picked up a few spywares with all of the VideoCop forwards you’ve been experiencing.
I hope this helps.
 

Yvonne G

Old Timer
TFO Admin
10 Year Member!
Platinum Tortoise Club
Joined
Jan 23, 2008
Messages
93,448
Location (City and/or State)
Clovis, CA
Wow, Michael! You've joined our forum and come on like gang busters! Thank you for your help with this mal-ware problem. Do you have an interest in tortoises too?
 
Status
Not open for further replies.
Top