3dfx Archive
http://www.falconfly.de/cgi-bin/yabb2/YaBB.pl
This & That >> This & That >> HELP!
http://www.falconfly.de/cgi-bin/yabb2/YaBB.pl?num=1222069600

Message started by paulpsomiadis on 22.09.08 at 10:46:40

Title: HELP!
Post by paulpsomiadis on 22.09.08 at 10:46:40
Okay guys, I got a problem...

Some REALLY nasty spyware has hijacked BOTH I.E.7 and Firefox.

It seems to have "overlayed" itself on top of Google searches.

Each link (if you hover the pointer on it) now says:

//go.google.com/(some random letters)711.691.111.46

Every time you click a link in your search results you see it "cycling" random pages in the status bar at the bottom of Firefox.

Then it will usually just load an ad-page or a blank page, etc...

Also, there seems to be an "iexplore.exe" process running by itself from time to time - but no internet explorer window to correspond to it.

In Firefox I have also noticed that some of the "search result" links come from the files:

c.php
rej.php
(but these don't exist on my PC!!!)

I am also trying to screen cap. some of the I.P. addresses this bugger is using:

64.111.196.117
66.154.9.30

Since I'm pretty stuck without Google...can you guys look around and see what you can find about this.

D@MN this thing is annoying!

(At least I can still post on the forum!)

Title: Re: HELP!
Post by paulpsomiadis on 22.09.08 at 12:00:23
Well I've been lucky...

I just repaired the PSU for my Torrenting machine yesterday afternoon (it had a leaky capacitor).

I used my torrenting machine and found this:

http://forums.techguy.org/malware-removal-hijackthis-logs/746850-go-google-redirect-virus.html

So I scanned with MalwareBytes' Anti-malware...and...

I'M BACK BABY!

WOOT!

Some more details on the "infection" as it was:

TYPE: Trojan - Malware - Redirector
SYMPTOMS: Redircts all MSN and Google links to "go.google.com" and "go.msn.com" - basically will not let you search.
SOLUTION: Do a quick scan with MalwareBytes' Anti-Malware

3dfx Archive » Powered by YaBB 2.4!
YaBB © 2000-2009. All Rights Reserved.