<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Google has been hi-jacked</title>
	<link>http://ask.metafilter.com/110164/Google-has-been-hijacked/</link>
	<description>Comments on Ask MetaFilter post Google has been hi-jacked</description>
	<pubDate>Sun, 28 Dec 2008 10:50:16 -0800</pubDate>
	<lastBuildDate>Sun, 28 Dec 2008 10:50:16 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: Google has been hi-jacked</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked</link>	
		<description>Help please. My Google search has been hi-jacked. The first 15 or so returns look promising until you see the website you will be directed to if you click on the link. For example, searching &quot;Anne Bolyen&quot; returns these links: bestweb choices, strikingoffers, freescan.antivirus, web-antivirus, teens-searcher, lowpriceshopper, and findstuff to name a few. &lt;br /&gt;&lt;br /&gt; I am using windows xp along with Firefox 3.0.5. I have run Ad-aware and spybot. They both showed some spyware, which I&apos;ve cleaned up using the respective programs. Trying to google a solution is impossible.</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2008:site.110164</guid>
		<pubDate>Sun, 28 Dec 2008 10:45:06 -0800</pubDate>
		<dc:creator>JujuB</dc:creator>
		
			<category>search</category>
		
			<category>hijack</category>
		
			<category>resolved</category>
		
	</item> <item>
		<title>By: k8t</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked#1585590</link>	
		<description>Have you deleted all of your cookies and cleared your cache?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.110164-1585590</guid>
		<pubDate>Sun, 28 Dec 2008 10:50:16 -0800</pubDate>
		<dc:creator>k8t</dc:creator>
	</item><item>
		<title>By: DWRoelands</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked#1585595</link>	
		<description>Google&apos;s page on this issue (http://www.google.com/support/bin/answer.py?answer=8091) suggests using the two software packages you already mentioned, and also &lt;a href=&quot;http://www.malwarebytes.org/mbam.php&quot;&gt;MalwareBytes&lt;/a&gt;.  Other folks reporting this problem have recommended Malwarebytes, saying it cleared the issue.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.110164-1585595</guid>
		<pubDate>Sun, 28 Dec 2008 10:54:06 -0800</pubDate>
		<dc:creator>DWRoelands</dc:creator>
	</item><item>
		<title>By: Justinian</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked#1585596</link>	
		<description>Have you run a true antivirus program rather than anti-spyware?  I believe Trend Micro will run a free scan from http://housecall.trendmicro.com/ .  Since it is run from software on their server it is more difficult for whatever virus you picked up to fool with it.&lt;br&gt;
&lt;br&gt;
Can you start the task manager and see if there are any weird processes running?  Or just post all the running processes if you don&apos;t know which ones would qualify as weird.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.110164-1585596</guid>
		<pubDate>Sun, 28 Dec 2008 10:54:30 -0800</pubDate>
		<dc:creator>Justinian</dc:creator>
	</item><item>
		<title>By: dejah420</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked#1585641</link>	
		<description>If looking at your processes gets you discombobulated, take a look at &lt;a href=&quot;http://www.processlibrary.com/processscan/&quot;&gt;Process Scanner&lt;/a&gt;.  It&apos;ll list all the processes that are running, and rank them as to their virus potential.  (I found it via lifehacker.)&lt;br&gt;
&lt;br&gt;
Seconding running the TrendMicro scanner.  That thing takes a long time, but it&apos;s very effective.  &lt;br&gt;
&lt;br&gt;
There&apos;s also the possibility that there&apos;s a problem with your registry.  I won&apos;t recommend editing it unless you&apos;re pretty comfortable with the knowledge that registy edits can mean that you have to nuke the box from space, reformat and reinstall if you do it wrong.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.110164-1585641</guid>
		<pubDate>Sun, 28 Dec 2008 11:47:09 -0800</pubDate>
		<dc:creator>dejah420</dc:creator>
	</item><item>
		<title>By: sevenstars</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked#1585662</link>	
		<description>Maybe these are set up to catch common misspellings, as in &quot;Bolyen&quot; for &quot;Boleyn&quot;?  I remember what happened when a neighbor boy misspelled &quot;google&quot; on our computer--a porn site I couldn&apos;t get away from.  My husband had to reset our home page.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.110164-1585662</guid>
		<pubDate>Sun, 28 Dec 2008 12:18:56 -0800</pubDate>
		<dc:creator>sevenstars</dc:creator>
	</item><item>
		<title>By: Lyn Never</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked#1585666</link>	
		<description>This happened to a coworker on Friday, it was an adware cookie.  He caught it with one of the usual scanners.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.110164-1585666</guid>
		<pubDate>Sun, 28 Dec 2008 12:25:09 -0800</pubDate>
		<dc:creator>Lyn Never</dc:creator>
	</item><item>
		<title>By: JujuB</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked#1585679</link>	
		<description>Cleared the cache and cookies. I ran MalwareBytes which detected 7 objects, Trojan.Agent and Hijack.startmenu in the registry key and data key. I deleted them and restarted as per instructions. Google is still having problems. &lt;br&gt;
&lt;br&gt;
I am now running Housecall that Justinan recommend. Looks like it is going to take awhile. I&apos;ll reply when it is finished, keeping my fingers crossed.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.110164-1585679</guid>
		<pubDate>Sun, 28 Dec 2008 12:40:47 -0800</pubDate>
		<dc:creator>JujuB</dc:creator>
	</item><item>
		<title>By: vaguelyweird</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked#1585717</link>	
		<description>a friend had something similar: all google searches would be redirected to nonsense websites via a go.google redirect. also, certain &quot;helpful&quot; domains would be inaccessible.&lt;br&gt;
&lt;br&gt;
I don&apos;t know if this is the problem you&apos;re having (called TDSS), but I used malwarebytes (renamed install, renamed run) in safe mode, followed by sdfix and combofix.&lt;br&gt;
&lt;br&gt;
if this *is* the problem, you can use a free web-proxy to circumvent it &amp;amp; get better info (or, different computer, boot disk, dual-boot, recovery partition w/ networking, etc. i unfortunately had only that computer to work with). i copied &amp;amp; pasted the text of the link (since the actual link was hijacked).</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.110164-1585717</guid>
		<pubDate>Sun, 28 Dec 2008 13:28:42 -0800</pubDate>
		<dc:creator>vaguelyweird</dc:creator>
	</item><item>
		<title>By: vaguelyweird</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked#1585721</link>	
		<description>hmm considering that housecall has been blocked for you, it&apos;s probably not the same thing.&lt;br&gt;
&lt;br&gt;
anyway, good luck.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.110164-1585721</guid>
		<pubDate>Sun, 28 Dec 2008 13:30:43 -0800</pubDate>
		<dc:creator>vaguelyweird</dc:creator>
	</item><item>
		<title>By: vaguelyweird</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked#1585722</link>	
		<description>*hasn&apos;t been blocked*, not &quot;has&quot;.&lt;br&gt;
woops!</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.110164-1585722</guid>
		<pubDate>Sun, 28 Dec 2008 13:32:36 -0800</pubDate>
		<dc:creator>vaguelyweird</dc:creator>
	</item><item>
		<title>By: Chocolate Pickle</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked#1585831</link>	
		<description>I&apos;ve seen reports that OpenDNS hijacks the google domains. Are you using OpenDNS?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.110164-1585831</guid>
		<pubDate>Sun, 28 Dec 2008 15:33:43 -0800</pubDate>
		<dc:creator>Chocolate Pickle</dc:creator>
	</item><item>
		<title>By: xenophile</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked#1585838</link>	
		<description>I had this happen too. I couldn&apos;t download spyware protection til I got rid of it manually. I had to disable the &quot;backdoor&quot; by the following steps. Make sure you boot in Safe Mode when you do this to minimize the likelihood of any more Trojans downloading.&lt;br&gt;
&lt;br&gt;
To boot up in Safe Mode, press the F8 key over and over as the computer starts, then select Safe Mode without networking using the arrow keys. When it boots up, select HP Owner and make sure you click on the box that asks if you really want to use Safe Mode.&lt;br&gt;
&lt;br&gt;
Go to Start &amp;gt; Control Panel &amp;gt; System &amp;gt; Hardware &amp;gt; Device Manager &amp;gt; View &amp;gt; Show Hidden Devices.&lt;br&gt;
&lt;br&gt;
Under Hidden Devices, go down to Non-plug and Play Drivers. Click the plus sign to show those drivers.&lt;br&gt;
&lt;br&gt;
Find TDSSserv.sys. This is the Trojan Horse malware that keeps making your searches go to &quot;go.google.&quot;&lt;br&gt;
&lt;br&gt;
Right click on it and select Disable. Don&apos;t uninstall it because it will reinstall every time you start the computer up. &lt;br&gt;
&lt;br&gt;
Restart your computer, and immediately go online to download several really good, free spyware programs. I use Avast!, SuperAntiSpyware, and MalwareBytes. I also use CCleaner every time I browse, to clean up cookies and temp files.&lt;br&gt;
&lt;br&gt;
You should run full scans with each of these programs immediately. Trojans can let other malware into a system. I once had more than 80 of these nasty things, but I regularly run these programs and haven&apos;t had a problem since.&lt;br&gt;
&lt;br&gt;
Good luck! Trojans are a bitch.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.110164-1585838</guid>
		<pubDate>Sun, 28 Dec 2008 15:38:19 -0800</pubDate>
		<dc:creator>xenophile</dc:creator>
	</item><item>
		<title>By: JuiceBoxHero</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked#1585844</link>	
		<description>My father-in-law&apos;s computer had something strange going on with it too. Not quite the same symptoms, but certain pages wouldn&apos;t load right. His DNS had been hacked. &lt;br&gt;
&lt;br&gt;
Check your DNS:&lt;br&gt;
Go to Start-&amp;gt;Control Panel-&amp;gt;Network Connections-&amp;gt;Local Area Connection (or wireless, if you&apos;re using it)-&amp;gt;Properties-&amp;gt;Click &quot;TCP/IP&quot; and then &quot;Properties&quot;&lt;br&gt;
&lt;br&gt;
At the bottom of that window should be a section where you can put in your own DNS servers. See if there&apos;s anything in there. If so, you can try clearing it out and clicking OK. If you&apos;re using a static IP setup with no DHCP, just leave it alone though.&lt;br&gt;
&lt;br&gt;
The hijacked DNS started with 85.255.x.x</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.110164-1585844</guid>
		<pubDate>Sun, 28 Dec 2008 15:45:09 -0800</pubDate>
		<dc:creator>JuiceBoxHero</dc:creator>
	</item><item>
		<title>By: patnok</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked#1585871</link>	
		<description>lots of nasty stuff going around. malwarebytes (on a stick) fixed me up several weeks ago. HAD to use the usb stick. could not go to the web site on the infected pc. stuff got on my external HD also but not much.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.110164-1585871</guid>
		<pubDate>Sun, 28 Dec 2008 16:13:41 -0800</pubDate>
		<dc:creator>patnok</dc:creator>
	</item><item>
		<title>By: EmpressCallipygos</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked#1585939</link>	
		<description>Cool Web Shredder.  In case you&apos;re not able to find it yourself, I&apos;ve linked to it &lt;a href=&quot;http://us.trendmicro.com/us/products/personal/CWShredder&quot;&gt;here.&lt;/a&gt; It&apos;s a freeware trojan-removing product that targets a particular family of trojans that do the things your computer is doing -- try that.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.110164-1585939</guid>
		<pubDate>Sun, 28 Dec 2008 17:50:48 -0800</pubDate>
		<dc:creator>EmpressCallipygos</dc:creator>
	</item><item>
		<title>By: JujuB</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked#1586076</link>	
		<description>I am still having the same problem with my searches being re-directed. &lt;br&gt;
&lt;br&gt;
xenophile, I was able to view the hidden devices in safe mode, but did not see TDSSser.sys.&lt;br&gt;
&lt;br&gt;
I checked my DNS, it is not open, I have a static IP setup.&lt;br&gt;
&lt;br&gt;
The free scan of TrendMicro Scanner showed 3 vulnerabilities, all related to MS excel, I download the patches. Second scan shows 0 threats. I downloaded the 30 day trial version of Trend Micro AntiVirus. I was able to update to the latest release. Ran a new scan, it showed 16 threats, those were deleted by TrendMicro. &lt;br&gt;
&lt;br&gt;
Hijack This shows all of this is running, but warns some is good and some may be bad. I am now over my head, here is the results from the Hijack This program:&lt;br&gt;
&lt;br&gt;
Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;
Scan saved at 9:56:17 PM, on 12/28/2008&lt;br&gt;
Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br&gt;
MSIE: Internet Explorer v7.00 (7.00.6000.16762)&lt;br&gt;
Boot mode: Normal&lt;br&gt;
&lt;br&gt;
Running processes:&lt;br&gt;
C:\WINDOWS\System32\smss.exe&lt;br&gt;
C:\WINDOWS\system32\winlogon.exe&lt;br&gt;
C:\WINDOWS\system32\services.exe&lt;br&gt;
C:\WINDOWS\system32\lsass.exe&lt;br&gt;
C:\WINDOWS\system32\svchost.exe&lt;br&gt;
C:\WINDOWS\System32\svchost.exe&lt;br&gt;
C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;
C:\WINDOWS\System32\wltrysvc.exe&lt;br&gt;
C:\WINDOWS\System32\bcmwltry.exe&lt;br&gt;
C:\WINDOWS\system32\LEXBCES.EXE&lt;br&gt;
C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;
C:\WINDOWS\system32\LEXPPS.EXE&lt;br&gt;
C:\WINDOWS\Explorer.EXE&lt;br&gt;
C:\WINDOWS\system32\WLTRAY.exe&lt;br&gt;
C:\WINDOWS\RTHDCPL.EXE&lt;br&gt;
C:\WINDOWS\system32\SysMonitor.exe&lt;br&gt;
C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe&lt;br&gt;
C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br&gt;
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe&lt;br&gt;
C:\Program Files\Lexmark 4200 Series\lxbmbmon.exe&lt;br&gt;
C:\Program Files\iTunes\iTunesHelper.exe&lt;br&gt;
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe&lt;br&gt;
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe&lt;br&gt;
C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe&lt;br&gt;
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe&lt;br&gt;
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe&lt;br&gt;
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe&lt;br&gt;
C:\Program Files\Common Files\Sonic Shared\CineTray.exe&lt;br&gt;
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br&gt;
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;
C:\Program Files\Bonjour\mDNSResponder.exe&lt;br&gt;
C:\WINDOWS\system32\nvsvc32.exe&lt;br&gt;
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe&lt;br&gt;
C:\PROGRA~1\AVG\AVG8\avgrsx.exe&lt;br&gt;
C:\WINDOWS\system32\svchost.exe&lt;br&gt;
C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;
C:\Program Files\Trend Micro\BM\TMBMSRV.exe&lt;br&gt;
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;br&gt;
C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;
C:\WINDOWS\system32\wuauclt.exe&lt;br&gt;
&lt;br&gt;
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us6.hpwis.com/&lt;br&gt;
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us6.hpwis.com/&lt;br&gt;
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local&lt;br&gt;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll&lt;br&gt;
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY&lt;br&gt;
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE&lt;br&gt;
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE&lt;br&gt;
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE&lt;br&gt;
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup&lt;br&gt;
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install&lt;br&gt;
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit&lt;br&gt;
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\WINDOWS\system32\SysMonitor.exe&lt;br&gt;
O4 - HKLM\..\Run: [Lexmark 4200 Series] &quot;C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe&quot;&lt;br&gt;
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe&lt;br&gt;
O4 - HKLM\..\Run: [ZoneAlarm Client] &quot;C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe&quot;&lt;br&gt;
O4 - HKLM\..\Run: [QuickTime Task] &quot;C:\Program Files\QuickTime\QTTask.exe&quot; -atboottime&lt;br&gt;
O4 - HKLM\..\Run: [iTunesHelper] &quot;C:\Program Files\iTunes\iTunesHelper.exe&quot;&lt;br&gt;
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe&lt;br&gt;
O4 - HKLM\..\Run: [UfSeAgnt.exe] &quot;C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe&quot;&lt;br&gt;
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;
O4 - Global Startup: Acer Empowering Technology.lnk = ?&lt;br&gt;
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe&lt;br&gt;
O4 - Global Startup: Sonic CinePlayer Quick Launch.lnk = C:\Program Files\Common Files\Sonic Shared\CineTray.exe&lt;br&gt;
O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000&lt;br&gt;
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;
O9 - Extra &apos;Tools&apos; menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;br&gt;
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;br&gt;
O9 - Extra &apos;Tools&apos; menuitem: S&amp;amp;end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll&lt;br&gt;
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL&lt;br&gt;
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;
O9 - Extra &apos;Tools&apos; menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;
O9 - Extra &apos;Tools&apos; menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1203469796312&lt;br&gt;
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll&lt;br&gt;
O20 - AppInit_DLLs: avgrsstx.dll&lt;br&gt;
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe&lt;br&gt;
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe&lt;br&gt;
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe&lt;br&gt;
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe&lt;br&gt;
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe&lt;br&gt;
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe&lt;br&gt;
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe&lt;br&gt;
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE&lt;br&gt;
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe&lt;br&gt;
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe&lt;br&gt;
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe&lt;br&gt;
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe&lt;br&gt;
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe&lt;br&gt;
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe&lt;br&gt;
&lt;br&gt;
--&lt;br&gt;
End of file - 7304 bytes&lt;br&gt;
&lt;br&gt;
Does anybody see anything that looks suspicious?&lt;br&gt;
&lt;br&gt;
Thanks for all the help so far, I&apos;ve tried everything recommended, but can&apos;t get rid of this thing that has taken over my searches.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.110164-1586076</guid>
		<pubDate>Sun, 28 Dec 2008 20:17:41 -0800</pubDate>
		<dc:creator>JujuB</dc:creator>
	</item><item>
		<title>By: telstar</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked#1586182</link>	
		<description>jujuBe, nothing in particular jumps out at me as suspicious, but you are running a lot of stuff.  &lt;br&gt;
&lt;br&gt;
Have you tried &lt;a href=&quot;http://www.neuber.com/taskmanager/index.html&quot;&gt;Security Task Manager&lt;/a&gt;?  This package has found dangerous stuff running on windows boxes for me more than once.   The pay version supposedly provides more info, but I&apos;ve only needed to use the free version so far.  Good luck.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.110164-1586182</guid>
		<pubDate>Sun, 28 Dec 2008 21:57:50 -0800</pubDate>
		<dc:creator>telstar</dc:creator>
	</item><item>
		<title>By: dejah420</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked#1587408</link>	
		<description>Do the domains resolve correctly if you boot up in safe mode with networking?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.110164-1587408</guid>
		<pubDate>Mon, 29 Dec 2008 20:12:38 -0800</pubDate>
		<dc:creator>dejah420</dc:creator>
	</item><item>
		<title>By: JujuB</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked#1587449</link>	
		<description>The domains did not load correctly in safe mode.&lt;br&gt;
&lt;br&gt;
Well, I never could find the insidious thing that took over my google and yahoo. I could boot up in normal mode and safe mode. The main symptom was redirection of google and yahoo searches. Altavista was not affected and I was able to use it to find the  programs that I needed.&lt;br&gt;
&lt;br&gt;
I threw in the towel and restored to early December start point. All is well now!</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.110164-1587449</guid>
		<pubDate>Mon, 29 Dec 2008 20:41:44 -0800</pubDate>
		<dc:creator>JujuB</dc:creator>
	</item><item>
		<title>By: dejah420</title>
		<link>http://ask.metafilter.com/110164/Google-has-been-hijacked#1588773</link>	
		<description>That is so weird.  The steps you followed should have gotten rid of it.  &lt;br&gt;
&lt;br&gt;
For the record; these guys are top notch at solving malware problems.  Here&apos;s &lt;a href=&quot;http://forums.techguy.org/malware-removal-hijackthis-logs/746850-go-google-redirect-virus.html&quot;&gt;a thread where&lt;/a&gt; they&apos;ve fixed the go.google redirect problem, should you find yourself facing it again.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.110164-1588773</guid>
		<pubDate>Tue, 30 Dec 2008 20:12:58 -0800</pubDate>
		<dc:creator>dejah420</dc:creator>
	</item>
	</channel>
</rss>
