Share via

Potential malware: rdsrv.com

Anonymous
2014-12-31T05:20:48+00:00

Hi,

Since yesterday, out of the blue, whenever I  open a non-https website (in IE11 or chrome) ,such as twitch.com or vg247.com, if I click anywhere on the page a new tap is automatically opened (it seems there is an invisible layer covering whole page) and every time it redirects me to a new website. When I'm holding the mouse cursor on the page it shows that it has a address like"rdsrv.com/newbidder/***". I tried several malware removal programs such as microsoft, spyhunter and malwarebytes without any help. Also, I've restarted both IE11 and chrome to their default settings.

I'm using Microsoft essential security and windows 7 default firewall. 

Tnx

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

Answer accepted by question author

Anonymous
2015-04-23T10:47:06+00:00

For the "rdsrv.com/newbidder/***" problem spreading to all computers in my home, it was resolved by having the router reset by my ISP (because we have to lease the router here on Guam).  They said the virus hijacked the DNS inside the router, so no matter what anti-virus jobs I performed on the computer won't take that out. the problem persists.  

Yes, reset the router!  Good luck.  

And we should find a way to go after those companies created such an ugly virus prompting us to buy their "Repair Window" software.

Was this answer helpful?

0 comments No comments

Answer accepted by question author

Anonymous
2014-12-31T22:53:09+00:00

I think I found the problem.  I had the exact same situation.  Looks at some articles/etc. on "The Moon" worm and Linksys Routers.  I reset my Linksys E4200 to factory defaults, reconfigured for my environment and... so far, my Chrome browser has been behaving.  Good luck.

Was this answer helpful?

0 comments No comments

21 additional answers

Sort by: Most helpful
  1. Anonymous
    2014-12-31T22:34:35+00:00

    The popup with the telephone number you are seeing is the malware/adware issue on your computer. It's a new wrinkle on the cold call scams and the fake antimalware programs that were previously being installed on computers that we have heard about for years.  Now the scammers are trying to get you to call them....

    Instead of calling you on the phone they've managed to get an ad into your browser (probably during a freeware download) and if you call them then they'll want a large fee to fix your computer or they’ll try to sell you an antivirus program (one that may or may not work) or some other unneeded service.  It's nothing but a scam to get your money and credit card info.  Some of them use what appears to be a local number but in reality the scam may be from a country which will not cooperate with law enforcement agencies trying to identify the scammers.  

    Here's some articles about the phone scams - circumstances are similar but the scammers are now using fake ads to get you to call them:

    http://www.microsoft.com/security/online-privacy/avoid-phone-scams.aspx

    http://askleo.com/i\_got\_a\_call\_from\_microsoft\_and\_allowed\_them\_access\_to\_my\_computer\_what\_do\_i\_do\_now/?awt\_l=Bg3x\_&awt\_m=JK7z9\_UOFJdfbL

    https://krebsonsecurity.com/2012/08/tech-support-phone-scams-surge/

    Once again let’s look for malware on your computer:

    Download and run Adwcleaner and Malwarebytes Free.

    See: http://www.bleepingcomputer.com/download/adwcleaner/

    And

    Go to http://www.malwarebytes.org/products/malwarebytes\_free/ and download, install, update and run the free version – just follow the prompts.  

    And/Or

    Try the Kaspersky Virus Removal Tool: http://www.kaspersky.com/antivirus-removal-tool?form=1If necessary you can download the program to another computer, put the removal tool on a flash drive and then run the removal tool on the infected computer.

    Did you run Hitman Pro (trial version) as recommended in the previous link?  Very surprised it did not identify and eliminate this malware.

    You may need to completely uninstall Chrome (do not save any settings) and then install a fresh copy.

    And you may need to revert to IE-10 from IE-11 - if so, see the Answer of PA Bear MS MVP in this thread: http://answers.microsoft.com/en-us/ie/forum/ie11-windows_7/windows-7-roll-back-of-ie-11-to-ie-10/80c12ee9-cd96-4821-a438-6c773f762d9c

    Alternatively - - - you may wish to try System Restore (that may or may not eliminate your issue and remember to be sure you’ve backed up any documents, pictures, music, etc you wish to save before trying it).  Or - - - you can reformat/reinstall the operating system, restore to factory settings if that’s an option with your computer or take your computer to a repair tech.

    Good luck…

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2014-12-31T22:06:04+00:00

    Hi,

    Thank you for your suggestion, I tried everything in that link and yet I have the same problem. However I've found something interesting, as I mentioned before every time I'm redirected to a different webpage but there is a webpage that appears frequently with a completely scam type message (look at the picture below)

    Tnx

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2014-12-31T05:42:25+00:00

    See if this free removal guide helps: 

    http://malwaretips.com/blogs/remove-browser-redirect-virus/

    Good luck...

    Was this answer helpful?

    0 comments No comments