<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Adware Detection &#187; Main Search Page</title>
	<atom:link href="http://AdwareDetection.com/blog/tag/main-search-page/feed/" rel="self" type="application/rss+xml" />
	<link>http://AdwareDetection.com</link>
	<description>AdwareDetection.com</description>
	<lastBuildDate>Mon, 21 May 2012 02:17:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>How do locate the source of Google hijacking?</title>
		<link>http://AdwareDetection.com/blog/how-do-locate-the-source-of-google-hijacking/</link>
		<comments>http://AdwareDetection.com/blog/how-do-locate-the-source-of-google-hijacking/#comments</comments>
		<pubDate>Fri, 12 Jun 2009 20:53:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Fwlink]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google Bar]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Main Search Page]]></category>

		<guid isPermaLink="false">http://AdwareDetection.com/blog/how-do-locate-the-source-of-google-hijacking/</guid>
		<description><![CDATA[D-Scan asked: Ever since spyware was installed the other day (and I removed it), Google has been redirecting to other spyware websites, and it says &#8216;analitic-checks.google.com&#8217; in the status bar. I have used every spyware removal program under the sun. Here is my process report from HijackThis: R0 &#8211; HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://wapp.verizon.net/bookmarks/bmredir.asp?region=all&#38;bw=fiber&#38;cd=7.0unattached&#38;bm=ho_central R1 [...]]]></description>
			<content:encoded><![CDATA[<div style="float:left;padding: 12px"><a href="/files/cc/adware_detection51.jpg"><img src="/files/cc/adware_detection51.jpg" alt='adware detection' /></a></div>
<div><em><strong>D-Scan</strong> asked: </em></p>
<p>Ever since spyware was installed the other day (and I removed it), Google has been redirecting to other spyware websites, and it says &#8216;analitic-checks.google.com&#8217; in the status bar. I have used every spyware removal program under the sun.</p>
<p>Here is my process report from HijackThis:</p>
<p>R0 &#8211; HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://wapp.verizon.net/bookmarks/bmredir.asp?region=all&amp;bw=fiber&amp;cd=7.0unattached&amp;bm=ho_central<br />
R1 &#8211; HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157<br />
R1 &#8211; HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896<br />
R1 &#8211; HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896<br />
R1 &#8211; HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank<br />
R1 &#8211; HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080<br />
F2 &#8211; REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe<br />
O2 &#8211; BHO: (no name) &#8211; {02478D38-C3F9-4efb-9B51-7695ECA05670} &#8211; (no file)<br />
O2 &#8211; BHO: Adobe PDF Reader Link Helper &#8211; {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} &#8211; C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br />
O2 &#8211; BHO: Verizon Broadband Toolbar &#8211; {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} &#8211; C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLL<br />
O2 &#8211; BHO: PCTools Site Guard &#8211; {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} &#8211; C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll<br />
O2 &#8211; BHO: SSVHelper Class &#8211; {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} &#8211; C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll<br />
O2 &#8211; BHO: NAV Helper &#8211; {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} &#8211; C:\Program Files\Norton AntiVirus\NavShExt.dll<br />
O3 &#8211; Toolbar: Norton AntiVirus &#8211; {C4069E3A-68F1-403E-B40E-20066696354B} &#8211; C:\Program Files\Norton AntiVirus\NavShExt.dll<br />
O3 &#8211; Toolbar: Verizon Broadband Toolbar &#8211; {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} &#8211; C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLL<br />
O4 &#8211; HKLM\..\Run: [Dell AIO Printer A940] &#8220;C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe&#8221;<br />
O4 &#8211; HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe<br />
O4 &#8211; HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent<br />
O4 &#8211; HKLM\..\Run: [QuickTime Task] &#8220;C:\Program Files\QuickTime\QTTask.exe&#8221; -atboottime<br />
O4 &#8211; HKLM\..\Run: [SSC_UserPrompt] &#8220;C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe&#8221;<br />
O4 &#8211; HKLM\..\Run: [NAV CfgWiz] &#8220;C:\Program Files\Norton AntiVirus\CfgWiz.exe&#8221; /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE &#8220;REBOOT&#8221;<br />
O4 &#8211; HKLM\..\Run: [ISTray] &#8220;C:\Program Files\Spyware Doctor\pctsTray.exe&#8221;<br />
O4 &#8211; HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br />
O4 &#8211; HKCU\..\Run: [DriverUpdaterPro] C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe -t<br />
O4 &#8211; HKCU\..\Run: [MSMSGS] &#8220;C:\Program Files\Messenger\msmsgs.exe&#8221; /background<br />
O4 &#8211; Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE<br />
O6 &#8211; HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present<br />
O8 &#8211; Extra context menu item: E&amp;xport to Microsoft Excel &#8211; res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000<br />
O9 &#8211; Extra button: AIM &#8211; {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} &#8211; C:\Program Files\AIM\aim.exe<br />
O9 &#8211; Extra button: (no name) &#8211; {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} &#8211; (no file)<br />
O9 &#8211; Extra button: (no name) &#8211; {e2e2dd38-d088-4134-82b7-f2ba38496583} &#8211; C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 &#8211; Extra &#8216;Tools&#8217; menuitem: @xpsp3res.dll,-20001 &#8211; {e2e2dd38-d088-4134-82b7-f2ba38496583} &#8211; C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br />
O9 &#8211; Extra button: Messenger &#8211; {FB5F1910-F110-11d2-BB9E-00C04F795683} &#8211; C:\Program Files\Messenger\msmsgs.exe<br />
O9 &#8211; Extra &#8216;Tools&#8217; menuitem: Windows Messenger &#8211; {FB5F1910-F110-11d2-BB9E-00C04F795683} &#8211; C:\Program Files\Messenger\msmsgs.exe<br />
O9 &#8211; Extra button: WeatherBug &#8211; {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} &#8211; C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)<br />
O16 &#8211; DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) &#8211; https://activatemyfios.verizon.net/sdcCommon/download/FIOS/Verizon%20FiOS%20Installer.cab<br />
O16 &#8211; DPF: {1011E032-5CF3-4795-B751-3AA5E008CCA6} &#8211; http://download.verizon.net/sfp/Cabs/max_update/VOLUpdate_1-0-0.cab<br />
O16 &#8211; DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} &#8211; http://pictures04.aim.com/ygp/aol/plugin/upf/AOLUPF.en-US-AIM.9.5.1.8.cab<br />
O16 &#8211; DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} &#8211; http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab<br />
O16 &#8211; DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) &#8211; https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab<br />
O20 &#8211; Winlogon Notify: RunOnceEx &#8211; C:\WINDOWS\<br />
O23 &#8211; Service: Lavasoft Ad-Aware Service (aawservice) &#8211; Lavasoft &#8211; F:\Programs\adware\aawservice.exe<br />
O23 &#8211; Service: Automatic LiveUpdate Scheduler &#8211; Symantec Corpor</p>
<p><a href=''></a></div>
]]></content:encoded>
			<wfw:commentRss>http://AdwareDetection.com/blog/how-do-locate-the-source-of-google-hijacking/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

