Aug

30

Recently we’ve encountered a really nasty trojan that hijacks both Google and Yahoo.

Since we found it diffifcult to remove - it evades many malware utilities - we thought we would share a simple solution THAT WORKS!

Noticing that one of our PC’s was behaving strangely we found that every search result on Google.co.uk was jumping off to an advertiser page. No matter what we did the click jumped to a random advertiser. It was IMPOSSIBLE to do anything.

We took leave from our web development projects to investigate and it was one of the most annoying pieces of code ever to have ever written. Even downloading a fix was impossible because we couldn’t use Google. Thinking we could quickly outsmart it we went to Yahoo and used the Yahoo Search - we were outsmarted! It hijacked Yahoo too!!!

We did notice that direct typing of URLs in the address bar was not affected but this wasn’t helping us to find a solution.

We checked out NOD32 antivirus licence, which was fully uptodate, and was showing now problems. So it must be some MALWARE!

** If you see analitic-checks.google.com when you are browsing you probably have this MALWARE **

When we tried to access many security sites our ‘Connection was reset” - the malware was filtering our internet access and any threat to it was being killed before we could get to a solution. What a pesky trojan, someone has obviously gone to lengths to prolong the life of this annoyance.

We launched SpyBot Search and Destroy - it FAILED. We updated updated - it FAILED

We jumped on another machine to research a solution … and after doing some research we found that a few other were finding a similar problem. Following a suggestion posted on Suggestafix forum we found the solution :

THE SOLUTION - MALWAREBYTES ANTI-MALWARE

We had heard good noises about this malware remover before and after reading the thread on suggestafix we downloaded it on another machine (the infected machine is blocked from accessing the site) we emailed it to the machine and installed it.

THANK HEAVENS for MALWAREBYTES ANTI-MALWARE!

after 5 minutes of scanning it found a lot of dssadw.dll, tdssl.dll tdssserf.dll + many others that had been hijacked.

It fixed the problems and then did an automatic reboot.

Woohooo! Joy .. Firefox and IE were both behaving normally and also Google and Yahoo.


-> Link to the awesome MALWAREBYTES ANTI-MALWARE


Comments

Name (required)

Email (required)

Website

Speak your mind

6 Comments so far

  1. Mania on September 3, 2008 1:37 pm

    I success to delete this trojan with MALWAREBYTES ANTI-MALWARE.

    If you search a fix, using Blackle.com if Google and Yahoo have been hijacked.

    Mania

  2. Andrew on September 8, 2008 5:45 pm

    Thank you! This trojan was causing me some real headaches. Tried 4 different anti virus/spyware programs, all with no result. So thanks for pointing me to malwarebytes.

    P.s the new google chrome browser was unaffected by the hijacks so i used that to search. still looks ugly though imo.

  3. Placid on September 9, 2008 10:18 am

    hail to malwarebytes, got rid of it :)

    I also tried several other programs but no luck.

  4. Kathy on September 17, 2008 4:18 pm

    My computer was completely taken down by this virus. Even after getting the Malwarebytes program and several others, it would not even allow me to install them, it blocked the installation program. After trying everything known to man to get rid of this thing, I finally gave up. :-(

  5. Amy on September 22, 2008 11:12 am

    Kathy, you couldn’t even install in safe mode? I swear, I am so pissed off by this thing but I’ll get rid of it, I don’t see the fucking point of these, what is the POINT?!

  6. Thomas R. on September 25, 2008 3:56 pm

    Malwarebytes worked for me too. Problem was antivir didn’t find anything and I couldn’t get the Anti-Malware-Program, because this particular malware stopped me from getting to the official Malwarebytes-site. Blackle.com didn’t work for me either, as did all the other searchengines I tried. Even this site was only reachable through the “Cache”-function of google. This Mirror helped though:

    http://www.download.com/3001-8022_4-10878968.html?spi=d5414836945841ec9d9e4be56103edf3

    (from download.com)
    Downloading and installing the Anti-Malware-Programm was no problem once I used download.com. I hopefully got completely rid of it.

    Good Luck!