“Google Hijack” — Google Search Gets Redirected

AID: 3299
  • Status: Published

31325 points

  • Byrpggamergirl
  • TypeGeneral
  • Posted on2010-06-22 at 06:59:30
Awards
  • Community Pick
  • Experts Exchange Approved
  • Editor's Choice
These are on the increase and getting more common these days. Users who use the Google search engine may complain of having their search redirected to unwanted sites, regardless of what browser is used.
This happens when the system is infected with any of these variants; Trojan Win32/Daonol.A/B, Trojan.JSRedir/Trojan.Gumblar, Win32.Alureon, Win32.Olmarik, Trojan.generic, TDSS rootkits, Backdoor.Tidserv!.inf.
Some variants of TDSS rootkit TDL3 also patched system drivers e.g., iaStor.sys, atapi.sys, iastorv.sys, cdrom.sys etc.


ISSUES:

  • clicking on the link of a Google search result redirects to random sites.
  • disabled utilities such as cmd and regedit, or running cmd or regedit command may reset Explorer.
  • error popup message “DCOM server protocol launcher server terminated”.


SOLUTION:

Older variants that hijack the valuedata of the HKLM\software\microsoft\windows nt\currentversion\drivers32 key like Trojan.JSRedir, Daonol and Gumblar are easily removed using MalwareBytes, but recent ones, especially variant of TDSS/TDL3 that MBAM fails to remove can be taken care of using TDSSKiller, so I suggest you go straight for TDSSKiller.

Download TDSSKiller , extract and run the TDSSKiller.exe

Additional info on how to remove malware belonging to the family of Rootkit.Win32.TDSS
http://support.kaspersky.com/viruses/solutions?qid=208280684



FireFox Only Hijacker:

Google Search redirects that affect only Firefox browser but NOT Internet Explorer.
Other hijackers are only targeting Firefox browser.  Searches are redirected via domains e.g., resultsad2.doubleclicker.net, goored, zfsearch.com and goougly.com, googlesearchserver.net, 66.230.188.* and others displaying unwanted search results. Some of these variants may target Chrome as well.


SOLUTION:

Thanks to malware Expert/Developer jpshortstuff for creating a tool that handles this infection.
Just download GooredFix.exe to your Desktop.
Make sure all Firefox windows are closed then double-click the executable or right-click and "Run As Administrator" in Vista.

If the problem persists, use ComboFix, and ask a question in the Virus & Spyware sub-zones and attached the ComboFix log, as there are other infections that also caused search engine redirects.
Recently, there's an infection doing the rounds patching either one of these files “ws2_32.dll” and “user32.dll” where you need to replace the file to stop the redirects.
As was the case with this recent question on EE.

I hope you find this article helpful.
Asked On
2010-06-22 at 06:59:30ID3299
Tags

Google hijack

,

browser redirect

Topic

Latest Threats

Views
8832

Comments

Expert Comment

by: younghv on 2010-06-27 at 02:38:38ID: 16202

rpggamergirl:
A lot of really solid technical advice here that many of our Members will be able to use.
Thank you for putting it together.

"Yes" vote above.

Author Comment

by: rpggamergirl on 2010-06-27 at 03:06:20ID: 16204

younghv,

Thanks for the "Yes" vote.

Expert Comment

by: hotecha on 2010-07-06 at 09:41:20ID: 16639

Worked perfectly, thank you.

Expert Comment

by: WBierley on 2010-08-02 at 06:28:18ID: 17725

I wanted to mention another utility that I found helpful. The makers of Spybot Search and Destroy have come out with a method for building a WINPE disk that allows you to run Search and Destroy and also access the Registry and File areas that are typically impacted by malware. In order to perform the build of the disk you will need to have the Windows Automated Installation Kit installed on your PC where you are performing the build and also download and install Spybot Search and Destroy, RunAlyzer and RegAlyzer. More information is available at http://forums.spybot.info/showthread.php?t=21313.

In my particular case I was able to use RegAlyzer to look at the Internet Explorer Add-Ins and delete the ones that had GUID names.

Expert Comment

by: T0DD on 2010-09-07 at 23:33:33ID: 19189

Just saw a TDL3 variant that changed the DNS servers to 93.188.162.78 & 93.188.161.11
Hitman Pro was able to detect it, but I had to first change back the DNS servers to default in order to run updates on HMP.  

Expert Comment

by: jasfout on 2010-10-06 at 18:23:11ID: 20304

Excellent!

Expert Comment

by: labops on 2011-02-15 at 09:43:13ID: 23886

thanks voted yes, fixed my issue

Expert Comment

by: Jonvee on 2011-06-24 at 12:28:29ID: 29096

Excellent advice, as always!  Thank you.

Voted "Yes" above.

Author Comment

by: rpggamergirl on 2011-06-24 at 20:19:15ID: 29110

WBierley, thank you for sharing that info I'm sure it will help someone.

TODD, HitmanPro is a good scanner and good with TDL3, but it is not too good for infections that patch system files. TDL4 has been on the rise and this one modifies mbr. I don't think HitmanPro has been great on this one afaik. Thanks for your input.

To everyone who voted Yes or commented(or both) thanks for your support on this article.

Expert Comment

by: Jsmply on 2011-07-07 at 13:09:42ID: 29560

Voted yes, very helpful!

Expert Comment

by: wasimibm on 2012-01-01 at 08:27:44ID: 34049

superb... !!

Expert Comment

by: normsrv on 2012-04-14 at 11:15:42ID: 49816

As always, the best help on the web is right here on Experts Exchange and people like you are the reason why.  I read all sorts of possible solutions before logging into E.E.  I went right to this post, downloaded the suggested program and solved the problem.  Maybe 10 minutes start to finish!

Thanks

Add your Comment

Please Sign up or Log in to comment on this article.

Join Experts Exchange Today

Gain Access to all our Tech Resources

Get personalized answers

Ask unlimited questions

Access Proven Solutions

Search 3.2 million solutions

Read In-Depth How-To Guides

1000+ articles, demos, & tips

Watch Step by Step Tutorials

Learn direct from top tech pros

And Much More!

Your complete tech resource

See Plans and Pricing

30-day free trial. Register in 60 seconds.

Loading Advertisement...

Top Latest Threats Experts

  1. rpggamergirl

    4,150

    0 points yesterday

    Profile
    Rank: Genius
  2. younghv

    4,034

    0 points yesterday

    Profile
    Rank: Genius
  3. Russell_Venable

    2,832

    0 points yesterday

    Profile
    Rank: Wizard
  4. willcomp

    1,244

    0 points yesterday

    Profile
    Rank: Genius
  5. SSharma

    1,200

    0 points yesterday

    Profile
    Rank: Genius
  6. tzucker

    600

    0 points yesterday

    Profile
    Rank: Wizard
  7. joyofsharing

    400

    0 points yesterday

    Profile
  8. kpoineal

    200

    0 points yesterday

    Profile

Hall Of Fame