PDA

View Full Version : google trojan



Chame1eon
06-06-2007, 02:49 PM
Maybe a year ago in the ebaums world forums I saw a post about someone who was taken to adult freind finder every few times he went to ebaums world via the google link. I googled ebaums world and maybe every 5th time i clicked the link i was taken to someipaddress/aff which took me to something resembling the adult freind finder adds you see on some web pages.
When i went back to the forum his post was deleted. So i made one and that was deleted. I kind of forgot about it untill recently while looking for more information about this fine product (http://emuse.ebaumsworld.com/video/watch/95).
Maybe every 5th time I click on the link I'm taken to http://85.255.117.**,
frequently, but not always http://85.255.117.36/riff_last.bin where nod32 blocks a download of a variant of Win32/TrojanDownloader.Ani.Gen trojan.
Sometime times there is a different form of malware.
That ip adress is on a list of false dns servers.
this is the adress maxthon saved when i closed the browser:
http://85.255.117.36/ind.htm?src=28&surl=ebaumsworld.com&sport=80&suri=%2F
If I type Ebaumsworld.com into the address bar I am always taken to one of thier address eg 8.7.232.0.
When I first discovered this i scanned with nod32 adaware symantec security check , houscall, spybot and hijack this.
My pc has no symptoms of a malware infection.
This has apperently been going on for a while.
I don't understand why I am taken to a completely different ip address from google than I am if I jsut type the adress.
Any ideas?

slim150
06-06-2007, 03:29 PM
Is there anything suspicious in your hosts file? The location of this file is: C:\WINDOWS\system32\drivers\etc and open it in notepad.

If you aren't sure you can paste the contents here.


Also you can download a the program hijackthis and run it
http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10379544.html?tag=lst-0-8

That should create a logfile you can paste that here too.
Also you theres a website that can analyze that logfile for you here:
http://www.hijackthis.de/
Just paste the log into that site.

Chame1eon
06-06-2007, 08:44 PM
There is nothing in my hosts file, and I tried hijack this. I don't think there is anything on my pc, which just makes this weirder.

Kuberr
06-07-2007, 10:34 PM
What about trying a free scan from Spyware Doctor?

Chame1eon
06-07-2007, 11:58 PM
Do i have to install it?