how to remove linkbucks browser hijacker

hi :P0l
ehm, during my adventure in the ehm :azn: … the no no land, my browser (Chrome) got infected by linkbucks.
Tried CIS, Eset smart security, malwarebytes, spybot, adwcleaner, & hitman pro, but the ■■■■■■’s still there, both CIS & Eset’s HIPS didn’t work.

help?

Ganda

Hi Ganda, please try following these steps:

  • Run Kaspersky virus removal tool:
  • Run Panda Cloud Cleaner:
  • Run Junkware Removal Tool:

http://thisisudax.org/downloads/JRT.exe

  • Reset your hosts file:
  • Flush your DNS cache:

Copy the text (replacing the [at] with the symbol) below into Notepad and save it as flush.bat on your desktop.
Right click / run flush.bat as administrator - it will automatically shut down your PC.

@Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0
  • Leave your PC turned OFF.
  • Unplug the power cable from the router, then unplug the power cable from the modem and leave it OFF for about 5 minutes.
  • With the PC still being off, plug in the modem’s power cable.
  • When all lights go on, plug in the router again. > When it’s lights have come back on, restart your PC.

Now check if the redirections problem has gone.

Kind regards, REBOL.

hi there mr (miss? 88) ) Reb0l.
Thanks for the help, i think you’ve got it figured out (the problem seems to be within the router and/or DNS setting), but didn’t have the chance to try it though, I solved the problem, yes,… me,… all by myself, mwahahahahaha, i’m so good even I don’t believe it 8)

Spent last night doing scan with all the scanners i can think of, but most of them only caught cookies (almost resorted to arson & exorcism, (un)fortunately can’t find any priest nearby :stuck_out_tongue: )

Then this morning when i connect the laptop to the internet from office, there’s no more linkbucks, i googled some more and some forums mentioned something about DNS poisoning, router hijack and whatnot, it’s like the malware infected the router, not the computer (something like that, i’m computer illiterate) and that’s why most AV can’t detect it and that’s also the reason i only got the linkbucks when i was connected at home.

So i followed the advice, I switched the preferred DNS server address to 8.8.8.8 (attached) and the problem’s solved right away, they also said, if changing the prefered DNS server address don’t work, i should just reset the router (there’s the reset button the size of the pinhole on the router) and contact the internet provider to re-set up the router.

thanks anyway ;D

Ganda

[attachment deleted by admin]

Not a “miss” yet, but thanks for having been “missing” me. :-* Anyway, it’s always either about “hit” or “miss”, right? :azn:

I’m totally proud of you now, Ganda. 8)

You just gave me some shivers. :o

Well, if that worked for you, that’s a quite more beautiful and simple solution than mine, Ganda. :slight_smile: :-La Congrats :-TU

Cheers, REBOL.

Howdy Ganda. Long time no see. May be it would be wise to flash your router with a fresh firmware? Just to be on the safe side of things.