Has GOOGLE been hijacked???

Closed Thread
Thread Tools
  #1  
Old 01-03-2009, 02:34 PM
homeball's Avatar
homeball homeball is offline
Senior Member
Join Date: Nov 2008
Location: Village of Hemingway
Posts: 158
Thanks: 0
Thanked 0 Times in 0 Posts
Default Has GOOGLE been hijacked???

For the last month or so, whenever I try to do a search on GOOGLE, the links given by the search do not match the search I was doing. For example when I search "The Villages" I get links for BIZRATE.com and other shopping and ad websites, etc. Only happens on one of my computers. The other one is fine. Has anyone else experienced this problem. Is there a solution. I've run Norton antivirus and AdAware anti spyware on the computer where this happens but I still get redirected.

Thanks.

-Dave-
  #2  
Old 01-03-2009, 03:13 PM
Russ_Boston's Avatar
Russ_Boston Russ_Boston is offline
Sage
Join Date: Jul 2007
Location: Buttonwood
Posts: 4,844
Thanks: 0
Thanked 1 Time in 1 Post
Default

Yes your search engine has been hijacked. Normal anti spyware programs will not kill it no matter what they say - I tried!

I ended up using some very powerful but basic kill programs (Hijack this, Killbox etc.) that will get rid of them but these programs are not for the novice and they do not work automagically like the others.

I'd suggest that you contact the midstate PC guy on this thread to help you out or just save your personal files and kill your hard drive and reload Windows etc. Again not for the novice!

Russ
  #3  
Old 01-03-2009, 03:36 PM
Midge538's Avatar
Midge538 Midge538 is offline
Senior Member
Join Date: Nov 2007
Posts: 320
Thanks: 0
Thanked 1 Time in 1 Post
Default

Most likley 'not' a virus but the Google site may have been hijacked. Use freeware like "NoScrihttp://noscript.netpt" ... which works with the browser 'Firefox' ... to control these malicious scripts.

http://noscript.net/
  #4  
Old 01-03-2009, 03:42 PM
homeball's Avatar
homeball homeball is offline
Senior Member
Join Date: Nov 2008
Location: Village of Hemingway
Posts: 158
Thanks: 0
Thanked 0 Times in 0 Posts
Default

Quote:
Originally Posted by Russ_Boston View Post
Yes your search engine has been hijacked. Normal anti spyware programs will not kill it no matter what they say - I tried!

I ended up using some very powerful but basic kill programs (Hijack this, Killbox etc.) that will get rid of them but these programs are not for the novice and they do not work automagically like the others.

I'd suggest that you contact the midstate PC guy on this thread to help you out or just save your personal files and kill your hard drive and reload Windows etc. Again not for the novice!

Russ
Thanks, Russ, for the info. I'm not an IT but can work around computers. Who is the midstate PC guy on this thread?

-Dave-
  #5  
Old 01-03-2009, 03:45 PM
homeball's Avatar
homeball homeball is offline
Senior Member
Join Date: Nov 2008
Location: Village of Hemingway
Posts: 158
Thanks: 0
Thanked 0 Times in 0 Posts
Default

Quote:
Originally Posted by Midge538 View Post
Most likley 'not' a virus but the Google site may have been hijacked. Use freeware like "NoScrihttp://noscript.netpt" ... which works with the browser 'Firefox' ... to control these malicious scripts.

http://noscript.net/
That's what I suspected. A highjacking should affect both computers not just one though. I'll try that link you sent me. Thanks.

-Dave-
  #6  
Old 01-03-2009, 05:13 PM
homeball's Avatar
homeball homeball is offline
Senior Member
Join Date: Nov 2008
Location: Village of Hemingway
Posts: 158
Thanks: 0
Thanked 0 Times in 0 Posts
Default

Quote:
Originally Posted by Russ_Boston View Post
Yes your search engine has been hijacked. Normal anti spyware programs will not kill it no matter what they say - I tried!

I ended up using some very powerful but basic kill programs (Hijack this, Killbox etc.) that will get rid of them but these programs are not for the novice and they do not work automagically like the others.

I'd suggest that you contact the midstate PC guy on this thread to help you out or just save your personal files and kill your hard drive and reload Windows etc. Again not for the novice!

Russ
Russ,

I found the midstatePC website. Also found the "hijack this" web site. If you run HIGHJACK THIS just for a scan, you will get a list. How did you find out what was malware on that list? Is there a reference web site that tells you what to look for?
Thanks.

-Dave-
  #7  
Old 01-03-2009, 07:11 PM
Russ_Boston's Avatar
Russ_Boston Russ_Boston is offline
Sage
Join Date: Jul 2007
Location: Buttonwood
Posts: 4,844
Thanks: 0
Thanked 1 Time in 1 Post
Default

I remember just doing enough searches to find the name of the malware that caused this type of mislead. I then searched my PC for the .exe listed and found it. The tough part was killing it. You couldn't just delete because it reinstalled itself. That's when I used the Killbox freebie application to permanently remove it.

Without being there it's hard for me to know which search hijacker it is.
  #8  
Old 01-04-2009, 01:27 PM
midstatepc midstatepc is offline
Member
Join Date: Nov 2008
Posts: 36
Thanks: 0
Thanked 0 Times in 0 Posts
Default

I have been in contact with Dave through email. I offerd to review the list generated by hijackthis! and report back any entries that looked suspicious.
I also recommend to anyone the program "spybot search and destroy" I've used it for years and It has saved many a computer from the "reinstall shuffle"

http://www.safer-networking.org
  #9  
Old 01-04-2009, 04:51 PM
Russ_Boston's Avatar
Russ_Boston Russ_Boston is offline
Sage
Join Date: Jul 2007
Location: Buttonwood
Posts: 4,844
Thanks: 0
Thanked 1 Time in 1 Post
Default

Thanks for the recommendation of that program. Best of all it is FREE!

I didn't have the problem mentioned in this thread but it did notice others and cleaned them up.

Russ
  #10  
Old 01-04-2009, 05:55 PM
golfnut's Avatar
golfnut golfnut is offline
Soaring Eagle member
Join Date: Jul 2007
Location: Belvedere
Posts: 2,285
Thanks: 9
Thanked 31 Times in 24 Posts
Default

If you've only had the problem for a few weeks or so can't you do a system restore to a date 4 to 6 weeks ago??? Just a thought....GN
__________________
Village of Belvedere
  #11  
Old 01-04-2009, 09:16 PM
homeball's Avatar
homeball homeball is offline
Senior Member
Join Date: Nov 2008
Location: Village of Hemingway
Posts: 158
Thanks: 0
Thanked 0 Times in 0 Posts
Default

Quote:
Originally Posted by golfnut View Post
If you've only had the problem for a few weeks or so can't you do a system restore to a date 4 to 6 weeks ago??? Just a thought....GN
I thought of that. But before that, I scanned the hard drive with Ad-Aware and it found these three malwares and deleted them.


Deep scanning and examining files (C)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Win32.Rootkit.Agent Object Recognized!
Type : File
Data : A0088412.sys
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP559\

FileDescription : System Audio WDM Filter


Win32.Trojan.Agent Object Recognized!
Type : File
Data : A0090373.pmt
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP567\



Win32.Rootkit.Agent Object Recognized!
Type : File
Data : A0090426.sys
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP568\

FileDescription : System Audio WDM Filter

The malware appeared to be hidden in the directory that System Restore uses.

Tried to use System Restore for a restore point six weeks ago but it reported that it could not restore to that point. So I don't know if Ad-Aware, when it deleted those files, compromised the system restore function.

-Dave-
  #12  
Old 01-04-2009, 09:21 PM
midstatepc midstatepc is offline
Member
Join Date: Nov 2008
Posts: 36
Thanks: 0
Thanked 0 Times in 0 Posts
Default

If you have spybot installed, try that. it may need to scan at startup, so you will have to go through it twice. but it has a chance of killing it.
  #13  
Old 01-04-2009, 09:29 PM
homeball's Avatar
homeball homeball is offline
Senior Member
Join Date: Nov 2008
Location: Village of Hemingway
Posts: 158
Thanks: 0
Thanked 0 Times in 0 Posts
Default

Quote:
Originally Posted by midstatepc View Post
If you have spybot installed, try that. it may need to scan at startup, so you will have to go through it twice. but it has a chance of killing it.
Thanks. That's my next plan of attack, using SPYBOT. Meanwhile, SYSTEM RESTORE doesn't seem to be able to restore to an earlier point. It functions OK then reports back that it can't restore. All of this stuff was funtioning normally a month ago. Ad-Aware scans were OK up to yesterday when it found those three malwares. Otherwise, it was just finding data mining cookies only.

-Dave-
  #14  
Old 01-05-2009, 04:31 PM
salpal's Avatar
salpal salpal is offline
Veteran member
Join Date: Dec 2008
Posts: 658
Thanks: 3
Thanked 30 Times in 14 Posts
Default MalwareBytes

You might want to also give a look-see at MalwareByes.org -- their software is great at cleaning up various malware/trojans. I've found Ad-Aware to not be as up-to-date as their product.

The other great source for all things evil and their fixes on the internet is the BleepingComputer forums.

They have a tool - ComboFix - that is also specifically designed to fix DNS hijacking but it too is not meant to be used by the faint of heart as it is pretty sophisticated.

Good luck!
  #15  
Old 01-05-2009, 11:43 PM
homeball's Avatar
homeball homeball is offline
Senior Member
Join Date: Nov 2008
Location: Village of Hemingway
Posts: 158
Thanks: 0
Thanked 0 Times in 0 Posts
Default

Quote:
Originally Posted by midstatepc View Post
If you have spybot installed, try that. it may need to scan at startup, so you will have to go through it twice. but it has a chance of killing it.
Hi Ted,

I installed and ran SPYBOT as you suggested.

It scanned and found several cookies and also found WildTangent both in the windows directory and registry. It deleted these items.

After all this, I still have the same problem with the GOOGLE search engine.

So that's where things stand right now.

-Dave-

Last edited by homeball; 01-06-2009 at 12:04 AM.
Closed Thread


You are viewing a new design of the TOTV site. Click here to revert to the old version.

All times are GMT -5. The time now is 12:33 PM.