searching problems

J

Jason

yeah...my internet is working just fine, but when i try
to use a search engine to search for anything, either
nothing happens or an "action canceled" page comes up.
this happens with all search engines on my computer,
yahoo, lycos, altavista...and so on. i can type any web
address into my address bar and it goes to that page with
out a problem, unless that address if of a search engine
website....if i type www.google.com....the action
canceled page pops up. my room mate, who uses the same
internet connection as i do, is not having this problem.
i need to be able to use search engines, what is the deal?
 
C

charlie R

It's a trojan. Read countless posts from earlier this evening on same
subject.


I'm having this same problem with search engines!!
Anyone know what's up??

-Dave
 
D

Douglas

Funny we all have the same problem, saw the last night at
9:45 pm Event ID: 11050 happened with the dns cache.
looked every where for info. I have 25 other wks with win
2K as well and no problems.
If you guys find out how to repair this please email me.

Thank you
Douglas
 
Y

YoKenny

Douglas said:
Funny we all have the same problem, saw the last night at
9:45 pm Event ID: 11050 happened with the dns cache.
looked every where for info. I have 25 other wks with win
2K as well and no problems.
If you guys find out how to repair this please email me.

I posted the answer already if you had bothered to read topic "Can't access
Google or other search engines?"

It is a trojan called Delude or QHosts-1.
http://www.imilly.com/google.htm
http://www.europe.f-secure.com/v-descs/delude.shtml
http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.html
 
H

H Leboeuf

Virus/Trojan alert!

http://www.f-secure.com/v-descs/delude.shtml

NAME: Delude
ALIAS: Trojan.BAT.Startpage.a
Delude is a trojan that is available on a web page. The web page contains a
code that uses a vulnerability in the Internet Explorer (MS03-032) to
execute.
More information about the vulnerability, including a fix, is available from
Microsoft at:
http://www.microsoft.com/security/security_bulletins/ms03-032.asp
VARIANT: Delude.A
The HTA code available on a web page downloads a file "partyboy.exe" from an
ftp site and runs it. This file is is packed with UPX. It is a batch file
which was compiled to executable binary (".exe") using a BatToExe tool.
When executed, it changes the Internet Explorer start page to find-now.info.
It prevents access to the most major search engines such as Google, Yahoo,
Lycos, MSN and AltaVista. To do this it replaces the following file:



http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.html
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top