Recently two disturbing things have happened on my computer. Last week, while viewing a video on YouTube, (couldn’t remember what it was, one of those Top 10 lists I believe) I stepped away from the PC for a call of nature and when I came back, there was something, I don’t know where it came from, on the site. I can’t quite remember the title (it began with “This is not a . . .” something or other). It showed a figure of someone doing a sexual act (I’m not going to go into details, basically back passage stuff). It sort of looked like an animated chalk figure. It was superimposed over the YouTube video. I clicked it off, the video ran as it should but I was wondering, “Where the f… did that come from?” I ran a scan with Norton. It didn’t find anything. Then today, only a few minutes ago, while I was browsing another website (strictly adult but generally safe, not known to have problems, perfectly within my rights) something popped up that replaced the site. It had titles like National Security Agency, InterPol, junk like that. It looked official; I read a few lines. Something about violating a law or another. I only read for a few seconds before closing the browser in case this . . . thing was trying to put Malware on it. It took longer than it should. The site’s legal so far as I can tell. I think that . . . whatever came from something or someone definitely not legit, but two incidents like this in such a short time has caused me to seriously question my security. Has anyone had any trouble like this recently? Am I hacked? Did something sneak by my defenses? Can I expect anything more like this? This is troublesome and I’m starting to worry.
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Unsettling. Disturbing. Am I being hacked?
Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Unsettling. Disturbing. Am I being hacked?
- This topic has 24 replies, 10 voices, and was last updated 9 years, 7 months ago.
Viewing 14 reply threadsAuthorReplies-
WSF.U.N. downtown
AskWoody LoungerAugust 24, 2015 at 2:50 pm #1524793Don’t know about the first one, second one is just a redirect with something trying to get you to click on it further to indeed try to get you to help malware get on to your computer. I’m surprised you were able to close it; often it will lock up the browser. I run Chrome with Add Block Plus extension (to kill ads if that’s what the first was) and the Chrome task manager open and ready in case of an incident like the second; just go to the Chrome task manager and kill the offending page (otherwise you’ll have to kill the entire browser from the system task manager)…and then don’t go back to whatever caused it.
-
WSF.U.N. downtown
AskWoody LoungerAugust 24, 2015 at 9:04 pm #1524869Redirects are based on browser urls sent from other computers, if it was on your computer and one of those ransom viruses your computer would be locking up even without using the browser and when/if you did try to use a browser, you would be taken immediately to whatever site the virus wanted to take you or it would display ransom demands immediately, no sites of your choosing would likely work at all.
-
WSrobertpri
AskWoody LoungerAugust 26, 2015 at 2:26 am #1525009Redirects are based on browser urls sent from other computers, if it was on your computer and one of those ransom viruses your computer would be locking up even without using the browser and when/if you did try to use a browser, you would be taken immediately to whatever site the virus wanted to take you or it would display ransom demands immediately, no sites of your choosing would likely work at all.
We’ve all heard horrendous stories about ransom sites. Never happened to me or family, but stuff happens. What exactly does one do if this ransom thing ever appears?
-
WStiger4
AskWoody LoungerAugust 26, 2015 at 3:31 pm #1525125We’ve all heard horrendous stories about ransom sites. Never happened to me or family, but stuff happens. What exactly does one do if this ransom thing ever appears?
I think I found out what this thing was; I believe its called Reveton. It’s a police/cop trojan. I found it on Wikipedia when I googled ransom virus. Its description pretty much fits what I saw. Am I compromised? Can my Norton Security Suite deal with this? I clicked it off as soon as I saw it but I’m wondering if it’s still hiding somewhere on my PC. My PC’s working okay now but I’m wondering . . . And would a malware removal tool react with my Norton?
-
WSspeedball
AskWoody LoungerAugust 27, 2015 at 9:55 am #1525297buy a new pc generally —
unless you want to pay them and encourage more such attacks on pcs —then
load it up with mbam and other goodiesstay away from bad sites
plus dont open email attachmentskill flash and other popular security holes
We’ve all heard horrendous stories about ransom sites. Never happened to me or family, but stuff happens. What exactly does one do if this ransom thing ever appears?
-
-
-
Paul T
AskWoody MVPAugust 25, 2015 at 2:04 am #1524884You should run the usual collection of malware removal tools.
http://www.bleepingcomputer.com/forums/t/540376/recommended-offline-scanners/cheers, Paul
-
Paul T
AskWoody MVPAugust 26, 2015 at 3:07 am #1525017 -
Paul T
AskWoody MVPAugust 27, 2015 at 3:17 am #1525170Using malware removal tools should not conflict with Norton, but you have a full backup don’t you?
cheers, Paul
-
Paul T
AskWoody MVP -
WStiger4
AskWoody LoungerAugust 27, 2015 at 11:44 pm #1525480I followed the instructions on that link you sent me. According to my startup folder, there’s nothing in it. I don’t know if that means I opened the wrong folder or I should open something else or I managed to click off Reveton before it could do something nasty. I still don’t feel safe; I’m still wondering if that thing is in my PC somewhere.
Booting into Safe Mode is required to access Windows to clean up the malware.
I don’t know if MB will clean that infection for you.cheers, Paul
-
-
Paul T
AskWoody MVP -
WStiger4
AskWoody LoungerAugust 29, 2015 at 3:29 am #1525665Well, I downloaded and ran a free MalwareBytes. It didn’t find anything either. When the ransomware initially appeared, I clicked the X in the upper corner a couple of times and it disappeared. I’m wondering if I did something before it could do something. Maybe I should download another scanner.
Are you getting any indication of the malware?
Have you run the scanners from post #5?cheers, Paul
-
-
WSrobertpri
AskWoody LoungerAugust 29, 2015 at 2:20 am #1525664From my very novice approach, here is what I think might work with a sudden ransom-ware attack. First, do not touch a single key. Hold down the power button until computer shuts down. Second, attach a bootable pre-configured thumb drive having an anti-virus program, like Windows defender. Boot to the usb drive to clean the machine. If not possible, boot to safemode and run virus cleaners.
I think this worked until Windows 8 [and probably W10] because unlike the good old days, one cannot simply boot to bios/setup and change boot sequence.
I have done this endless times on older machines, but could never boot to USB with Win 8. I called Dell on this and they said it was simple. Just boot to Win 8 and inside the OS, change the boot sequence. Unclear on the concept, eh?
-
Paul T
AskWoody MVP -
WStiger4
AskWoody Lounger
-
-
WSPointFive-Win10 HOME
AskWoody LoungerSeptember 3, 2015 at 4:15 pm #1526744PANDA ATTACK?
After reading the above, I followed the Bleeping Link and while there, decided to first read the info about installing the Panda, before downloading Panda. That took me to Panda’s site and then a 1″ tall reversed white out of black message appeared at the bottom of my screen, which said “We use our own and third party cookies to enhance your computer experience. By continuing to browse this site or clicking the close button you agree to our use of cookies.” aka you lose both ways. I got out of there, but when I re-opened the Lounge, there was an ad floating at the bottom of the screen. Have I been hacked by the Panda? What should I do now, or should I start a new message? -
b
AskWoody_MVPSeptember 3, 2015 at 5:16 pm #1526760PANDA ATTACK?
After reading the above, I followed the Bleeping Link and while there, decided to first read the info about installing the Panda, before downloading Panda. That took me to Panda’s site and then a 1″ tall reversed white out of black message appeared at the bottom of my screen, which said “We use our own and third party cookies to enhance your computer experience. By continuing to browse this site or clicking the close button you agree to our use of cookies.” aka you lose both ways. I got out of there, but when I re-opened the Lounge, there was an ad floating at the bottom of the screen. Have I been hacked by the Panda? What should I do now, or should I start a new message?No, you have not been hacked. Cookies are not evil.
Ads on this site are controlled and personalized by Google: “In addition to seeing ads based on the types of sites you visit, you may also see ads based on your interests and more.”
You can change settings to opt-out of personalized ads. You’ll still see ads but they will be less relevant to you. Click on the small AdChoices (for AdSense) triangle at top right of an ad.
-
-
WSF.U.N. downtown
AskWoody Lounger -
WSPointFive-Win10 HOME
AskWoody LoungerSeptember 5, 2015 at 11:27 am #1527016 -
Anonymous
Inactive -
access-mdb
AskWoody MVP -
David F
AskWoody Plus
Viewing 14 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Uninstalr Updates
by
jv16
5 hours, 16 minutes ago -
Apple zero days for April
by
Susan Bradley
33 minutes ago -
CVE program gets last-minute funding from CISA – and maybe a new home
by
Nibbled To Death By Ducks
6 hours, 4 minutes ago -
Whistleblower describes DOGE IT dept rumpus at America’s labor watchdog
by
Nibbled To Death By Ducks
17 hours, 54 minutes ago -
Seeing BSOD’s on 24H2?
by
Susan Bradley
48 minutes ago -
TUT For Private Llama LLM, Local Installation and Isolated from the Internet.
by
bbearren
8 hours, 17 minutes ago -
Upgrade from Windows 10 to 11
by
Holdsworth8
1 day, 2 hours ago -
Microsoft : AI-powered deception: Emerging fraud threats and countermeasures
by
Alex5723
1 day, 5 hours ago -
0patch
by
WSjcgc50
6 hours, 22 minutes ago -
Devices might encounter blue screen exception with the recent Windows updates
by
Susan Bradley
22 hours, 46 minutes ago -
Windows 11 Insider Preview Build 22631.5261 (23H2) released to Release Preview
by
joep517
1 day, 8 hours ago -
Problem opening image attachments
by
RobertG
1 day, 9 hours ago -
advice for setting up a new windows computer
by
routtco1001
2 days ago -
It’s Identity Theft Day!
by
Susan Bradley
1 day, 4 hours ago -
Android 15 require minimum 32GB of storage
by
Alex5723
2 days, 5 hours ago -
Mac Mini 2018, iPhone 6s 2015 Are Now Vintage
by
Alex5723
2 days, 5 hours ago -
Hertz says hackers stole customer credit card and driver’s license data
by
Alex5723
2 days, 6 hours ago -
Firefox became sluggish
by
Rick Corbett
2 days, 3 hours ago -
Windows 10 Build 19045.5794 (22H2) to Release Preview Channel
by
joep517
2 days, 10 hours ago -
Windows 11 Insider Preview Build 22635.5235 (23H2) released to BETA
by
joep517
2 days, 10 hours ago -
A Funny Thing Happened on the Way to the Forum
by
bbearren
1 day, 7 hours ago -
Download speeds only 0.3Mbps after 24H2 upgrade on WiFi and Ethernet
by
John
4 hours, 49 minutes ago -
T-Mobile 5G Wireless Internet
by
WSmmi16
1 day, 8 hours ago -
Clock missing above calendar in Windows 10
by
WSCape Sand
1 day, 9 hours ago -
Formula to Calculate Q1, Q2, Q3, or Q4 of the Year?
by
WSJon5
3 days, 1 hour ago -
The time has come for AI-generated art
by
Catherine Barrett
2 days, 5 hours ago -
Hackers are using two-factor authentication to infect you
by
B. Livingston
2 days, 15 hours ago -
23 and you
by
Max Stul Oppenheimer
2 days, 22 hours ago -
April’s deluge of patches
by
Susan Bradley
1 day, 2 hours ago -
Windows 11 Windows Updater question
by
Tex265
16 hours, 12 minutes ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.