HELP - Google redirecting to somewhere odd
Miscellaneous Forums/General Discussion/HELP - Google redirecting to somewhere odd
Having just turned on my PC I can't access the usual google page - it's showing an odd search engine page I've never seen before.
The same is happening on both my PCs (connected to the same connection via one router) but every other page loads just fine, email works etc..
Any ideas anyone?
Is it the Firefox google page?
sounds like a btowser hirjack.
i can't read any of scoot shavers posts cos i'm too drunk. so hes probally telling you teh sa,me.
Hmm, so how can I go about finding out what the problem is and removing it?
By writing me a cheque for £4million.
Alternatively, try AdAware/S&D etc.
open your HOSTS file,
which can be found here:
windows\system32\drivers\etc
and look for any odd stuff :)
If you're using IE and somebody put a shortcut on your desktop to the unfamiliar site and called it www.google.com, you would automatically be redirected. So you could check your desktop for shortcuts with that name. Its a bit of a long shot admittedly.
For possible browser hijackers, I don't think you can beat Hijack This!
http://www.download.com/HijackThis/3000-8022_4-10379544.html
No, my hosts file just contains this:
# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
what I'm gettting is this:
IE redirect to www.ju*****.com's random sites auto
my IE cant launch some sites I want to go and it will redirect to the www.ju*****.com random sites automatically ~ I tried to down the AVG7.5 ~ also did one step as following :
1. Use HijackThis to fix the following entries:
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
補充時間:2006-11-23 00:48:04
2. Use Notepad or any other text editor to open the file C:\WINDOWS\System32\drivers\etc\hosts. Delete everything in it except for the line 127.0.0.1 localhost
BUT I don't have this registry key and
and the Hijack this logfile:
HELP!!!!!!
removed this as it's too big
AHHHH HAA!
Fixed it - it seems my second PC was carrying the registry keys to redirect the internet service - Hijack this removed them and now Google works on my main PC.
However is it normal for one PC on a shared connection to be able to redirect the other one? They are both going through the same router.
Everything else looks ok, but I don't know what software you have installed. If all the applications sound right to you, then they probably are.
MrtStub.exe stands out for it's location, but it's legit software so unless you have reason to think it may be something else pretending to be MrtStub, you should probably leave it be.
Dunno.. I assume you've tried restarting the router?
what's MrtStub.exe? I have no folder on my F drive called "7bc9eac50dcfdd8e13569802".
Well it's part of Microsoft's Malicious Software Removal tool. But some malware can disguise itself as MrtStub.exe as well. Since you don't have the folder ( make sure it's not hidden! ) it won't hurt to let HijackThis remove it ( if it can ) and if not, run a scan with your preferred spyware software ( Spybot, Windows Defender, etc. )
Thanks, just did another HijackThis scan and it's gone. I did download the MS Malicious sw removal tool earlier so I think it was supposed to be there.
All seems normal again now (wipes brow)
thanks for your help :)
I had this problem as well, I found out some DNS settings had been changed.
To remedy under networking, properties, make sure obtain DNS server automatically is checked.
However is it normal for one PC on a shared connection to be able to redirect the other one? They are both going through the same router.
It depends on what yo umean by a "shared" connection. Do you have one PC sharing it's internect connection? That means it's acting as a DHCP server. It also means that the DHCP client machine uses the server for dns lookup, so something messing up the primary machine will be reflected throughout the DHCP network.
What neilo said was (assumedly) the source of one of the best practical jokes ever at one of my schools. Imagine everyone in campus housing or in the labs or using wifi trying to go to the school site, but only finding hardcore midget pron videos.
Classic. Even if it was discovered within an hour and fixed.
I don't know for sure that this is how they did it. But I always thought it was the most likely means.
Hijack This! has a "legend" button somewhere on the form. That button tells you what all of the codes mean (the "02", "04", etc in the left column)
Look for anything that has an ID code classified as a redirect. (Can't remember what # it is off the top of my head)
It depends on what yo umean by a "shared" connection
I have 2 PCs plugged into a single router, which is setup for my internet connection, so they can both access the net at the same time using the router.
Seems like only one PC had managed to aquire this trojan (or whatever it was that had added the registry keys to redirect from Google) but it was making the other PC do the same, even though the other PC didn't have the registry changes.
Very odd. At least next time I'll know what to do, although both PCs are now loaded-up with anti-virus and anti-spyware programs. I see that Spybot has settings to automatically protect against these redirects, which is nice.