PDA

View Full Version : search hijacks


Devlin Carnet
6th Sep 2008, 16:25
A strange one,
I'm really having fun with this PC lately.
Homepage is Google,
..fine
I do a search..
..Fine
I click on one of the return matches to the search..
I get a "ringtones4u" or other such marketing website in my browser.
I have run a superantispyware, and Nod32 antivirus/malware scan which return nothing.
Anyone had this, I expect not, seems I'm having a bad weekend. :ugh:

Saab Dastard
6th Sep 2008, 16:55
Search is your friend! There was a thread on this not long ago - perhaps this (http://www.pprune.org/computer-internet-issues-troubleshooting/337702-google.html) may be of use.

SD

Devlin Carnet
8th Sep 2008, 08:06
Thanks Saab, that does look like the same problem.

frostbite
8th Sep 2008, 11:47
Be very careful when searching at the moment, especially searching for AV stuff.

An item on R4 You & Yours suggests that such a search can currently land you with exactly what you're NOT looking for!

Devlin Carnet
8th Sep 2008, 16:35
Thanks for the heads up Frostbite, A little late for me though.
I cant believe any of the better AV/anti spyware programs cant find it though.

Raven30
9th Sep 2008, 15:57
I have just spent a day trying to recover from a similar attack to the one mentioned above. Tried 4 different anti spyware applications but the problem remained. In desperation I rang a friend in the computer business to see if he had any ideas how to proceed and he emailed me a small application called combofix. Unzipped it to the desktop, ran it and 20 minutes later my machine is back to normal. Cracking little program. It might just solve your problem. Its freeware and readily available on the net.

Good luck

Raven

Devlin Carnet
10th Sep 2008, 08:07
Raven,
Yep, you are spot on, I'd already found combofix and it cleaned the infestation out, it was tdssdata - a trojan agent. that was the problem.
It mentioned in the log about it being a rootkit.
Thanks for the info though.

Raven30
10th Sep 2008, 10:02
Obviously the same trojan that zapped me as those were the files reported on my machine!