redirect/hijack of searches

G

Guest

I have a bug that causes my search results to be hijacked or redirected. When
I use Google or any other search engine and click on a result I get
redirected/hijacked to another product. Clicking FORD.COM sends me to a
general used car lot or some loan company. I have tried every adware cleaning
program I can find (noadware,x-cleaner,hijack this, spy hunter ……….to name a
few ) .This failure only happens with INTERNET EXPLORER v6 and v7. The
problem does not happen with MOZILLA.
 
G

Galen

In RETAKS had this to say:

My reply is at the bottom of your sent message:
I have a bug that causes my search results to be hijacked or
redirected. When I use Google or any other search engine and click on
a result I get redirected/hijacked to another product. Clicking
FORD.COM sends me to a general used car lot or some loan company. I
have tried every adware cleaning program I can find
(noadware,x-cleaner,hijack this, spy hunter ....to name a few )
.This failure only happens with INTERNET EXPLORER v6 and v7. The
problem does not happen with MOZILLA.

Here you go:

Malware Cleaners and Repair:
http://kgiii.info/windows/all/general/malwarefix.html

--
Galen - MS MVP - Windows (Shell/User & IE)
http://dts-l.org/
http://kgiii.info/

"At present I am, as you know, fairly busy, but I propose to devote my
declining years to the composition of a textbook which shall focus the
whole art of detection into one volume." - Sherlock Holmes
 
G

Guest

--
retaks


Galen said:
In RETAKS had this to say:

My reply is at the bottom of your sent message:


Here you go:

Malware Cleaners and Repair:
http://kgiii.info/windows/all/general/malwarefix.html

--
Galen - MS MVP - Windows (Shell/User & IE)
http://dts-l.org/
http://kgiii.info/

"At present I am, as you know, fairly busy, but I propose to devote my
declining years to the composition of a textbook which shall focus the
whole art of detection into one volume." - Sherlock Holmes
i have tried all those malware removal tools, the do not detect anything. i
do not think i have a winsock problem because i can access the internet any
way i want with my favorite and with MOZILLA. its just that the result of a
search is redirected to a URL that malware wants to go to not google (or any
search engine) wants to go to.
 
G

Guest

Hi there Retaks,

Do you have any type of anti-spyware/ad-ware software installed? If not,
download either Ad-Aware from download.com or the Microsoft Windows Defender
from microsoft.com, and then run it in safe mode. Clean off any
spyware/adware/malware that the software finds and reboot the machine.

Hope this Helps!

Best Regards,

~Will
 
G

Guest

I have tried ad-aware,defender,and about 15 other spyware progs. none of them
have detected this bug! the symptoms are, if i use I.E 7 or I.E. 6 the
results of search are hijacked/redirected to another site. usually EBAY. any
search engine will be hijacked/redirected. however i have no trouble browsing
or navigating or vectoring using I.E. Mozilla v1.5.0.2 works fine in
every way. If there is malware why does it not show up in WINDOWS TASK
MANAGER?
retaks
 
G

Guest

Hi there RETAKS,

It could be set up in the form of a plug in built to IE. If you are using
Internet Explorer 7, you may want to go to Tools>Manage Add-Ons and start by
disabling add ons that have no publisher associated. If the problem
persists, continue disabling them one at a time to see if the issue goes away
with one of them.

Hope this Helps!

Best Regards,

~Will
 
G

Galen

In RETAKS had this to say:
i have tried all those malware removal tools, the do not detect
anything. i do not think i have a winsock problem because i can
access the internet any way i want with my favorite and with MOZILLA.
its just that the result of a search is redirected to a URL that
malware wants to go to not google (or any search engine) wants to go
to.

The only other rational answer is to check your hosts file.

--
Galen - MS MVP - Windows (Shell/User & IE)
http://dts-l.org/
http://kgiii.info/

"At present I am, as you know, fairly busy, but I propose to devote my
declining years to the composition of a textbook which shall focus the
whole art of detection into one volume." - Sherlock Holmes
 
G

Guest

i tried 3 more spyware prog. no help
i dont know what HOSTS files are.
i tried elimanating all plug in/ad-ons, no help.
i think it might be due this flaky IP LIGHTNINGSPEED.NET i am using
 
S

support

I have the same symptoms as the original message. I've checked the
HOSTS file and it is empty. I've also run McAfee, Adaware, CCleaner,
etc and none of these detect what is happening.

Basically if I do a search and the results are displayed in Google, if
I click on the link I am redirected to a similar page but not the one I
am looking for. It follows the same pattern each time: the first time
is redirected, click back. Second time is redirected to a different
page, click back. Third time works - I am taken to the page I intended
to go to.

I am running IE 6 SP2 on Windows XP SP2. It's more annoying than
anything else; just would like to know how to clean it. I do not
believe this is a 302 redirect issue. It is hijacking searches and
displaying other pages for all types of webpages. Any info is
appreciated. :)

Kv
 
A

anders

I had and still have the same problem. I found that the following
Registry Key value were modified,
HKLM\System\CCS\Services\Tcpip\interfaces\{102DA901-56D9-4445-9C8D-194FFE2CE9B1}:
NameServer = 85.255.114.40, 85.255.112.144

No anti-spyware software has found the trick, and could therefore not
fix it.
The IP addresses that causes the problems are, 85.255.114.40,
85.255.112.144. Of course this name server trick made my computer to
re-direct from Google or any other search engine. Last night it was OK,
but today it's back again.

These registry entries has been deleted as they are by HiJackThis
regarded as malware or equivalent.
O4 - HKCU\..\Run: [panel_its] SysEntry.exe
O4 - HKCU\..\Run: [bingo9] NsCplTray.exe
O4 - HKCU\..\Run: [dePloy] qwe.exe

Also a whole series with IP-addresses that point to a random selected
site has been identified. According to Internic they point at
http://www.estdomains.com. Strange, isn't it?

However, I would also need some tips and trick in this subject to get
this re-direct out of my system. Any ideas someone?


anders
 
W

Wesley Vogel

You have been hijacked.

Update your antivirus software and run a full system scan.

Update whatever anti-spyware applications that you have and run a full
system scan with each one.

You might want to start in Safe Mode to run your antivirus and anti-spyware
software.

Running a full system antivirus scan or anti-spyware scan in Safe Mode can
be a good idea. Some viruses and other malware like to conceal themselves
in areas Windows protects while using them. Safe mode will prevent those
applications access and therefore unprotect the viruses or other malware
allowing for easier removal.

How to start Windows in Safe Mode Windows XP
http://www.bleepingcomputer.com/forums/index.php?showtutorial=61#winxo

SysEntry.exe This is an undesirable program.
Part of the Wareout infection
http://www.bleepingcomputer.com/startups/SysEntry.exe-14215.html

NsCplTray.exe This is an undesirable program.
Part of the Wareout infection
http://www.bleepingcomputer.com/startups/NsCplTray.exe-14125.html

qwe.exe This is an undesirable program.
Added by the Troj/Lineage-F TROJAN!
http://www.bleepingcomputer.com/startups/qwe.exe-8181.html

Wareout infection
http://www.spywareguide.com/product_show.php?id=1818

Wareout Removal Instructions
http://www.spywareremove.com/removeWareout.html

Troj/Lineage-F
http://www.sophos.com/virusinfo/analyses/trojlineagef.html

85.255.114.40 85.255.112.144
OrgName: RIPE Network Coordination Centre
OrgID: RIPE
Address: P.O. Box 10096
City: Amsterdam
StateProv:
PostalCode: 1001EB
Country: NL

ReferralServer: whois://whois.ripe.net:43

NetRange: 85.0.0.0 - 85.255.255.255
CIDR: 85.0.0.0/8
NetName: 85-RIPE
NetHandle: NET-85-0-0-0-1
Parent:
NetType: Allocated to RIPE NCC
NameServer: NS-PRI.RIPE.NET
NameServer: NS3.NIC.FR
NameServer: SEC1.APNIC.NET
NameServer: SEC3.APNIC.NET
NameServer: SUNIC.SUNET.SE
NameServer: TINNIE.ARIN.NET
NameServer: NS.LACNIC.NET
Comment: These addresses have been further assigned to users in
Comment: the RIPE NCC region. Contact information can be found in
Comment: the RIPE database at http://www.ripe.net/whois
RegDate: 2004-04-01
Updated: 2004-04-06

# ARIN WHOIS database, last updated 2006-05-02 19:10

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
anders said:
I had and still have the same problem. I found that the following
Registry Key value were modified,
HKLM\System\CCS\Services\Tcpip\interfaces\{102DA901-56D9-4445-9C8D-194FFE2CE
9B1}:
NameServer = 85.255.114.40, 85.255.112.144

No anti-spyware software has found the trick, and could therefore not
fix it.
The IP addresses that causes the problems are, 85.255.114.40,
85.255.112.144. Of course this name server trick made my computer to
re-direct from Google or any other search engine. Last night it was OK,
but today it's back again.

These registry entries has been deleted as they are by HiJackThis
regarded as malware or equivalent.
O4 - HKCU\..\Run: [panel_its] SysEntry.exe
O4 - HKCU\..\Run: [bingo9] NsCplTray.exe
O4 - HKCU\..\Run: [dePloy] qwe.exe

Also a whole series with IP-addresses that point to a random selected
site has been identified. According to Internic they point at
http://www.estdomains.com. Strange, isn't it?

However, I would also need some tips and trick in this subject to get
this re-direct out of my system. Any ideas someone?


anders

I have the same symptoms as the original message. I've checked the
HOSTS file and it is empty. I've also run McAfee, Adaware, CCleaner,
etc and none of these detect what is happening.

Basically if I do a search and the results are displayed in Google, if
I click on the link I am redirected to a similar page but not the one I
am looking for. It follows the same pattern each time: the first time
is redirected, click back. Second time is redirected to a different
page, click back. Third time works - I am taken to the page I intended
to go to.

I am running IE 6 SP2 on Windows XP SP2. It's more annoying than
anything else; just would like to know how to clean it. I do not
believe this is a 302 redirect issue. It is hijacking searches and
displaying other pages for all types of webpages. Any info is
appreciated. :)

Kv
 
S

support

Thank you for the suggestions. I had the exact same symptoms..
registry keys with the IP address that the searches were being directed
to, etc.

I went into safe mode and did a full system scan with McAfee which only
found one file. I also did a full scan with AdAware which found some
files and removed them. Now the searches are working again for the
time being. We'll see if it lasts! Thanks!

Kv
 
G

Guest

Yes, thanks guys for your time in posting. I also had the same problems. I
had to do them all, but it finally worked.

One, P
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top