Author Topic: MY safe zone browser hijacked! goes to fake google  (Read 75858 times)

0 Members and 1 Guest are viewing this topic.

k.u.r.t

  • Guest
Re: MY safe zone browser hijacked! goes to fake google
« Reply #75 on: April 13, 2011, 03:57:40 PM »
Windows wont let me delete/overwrite SZ folder.. Folder/File access denied.. Tried running windows explorer as admin still wont let me overwrite the files..

1. Disable avast self protection

Offline DraKuL

  • Sr. Member
  • ****
  • Posts: 392
Re: MY safe zone browser hijacked! goes to fake google
« Reply #76 on: April 13, 2011, 03:58:08 PM »
DraKuL, you can send me the latest minidump (\Windows\Minidump folder) to my email, I'll see if it was already fixed or not.

Quote
blue screens are related to drivers... no idea why you had one... not sure if Avast loads drivers for virtualization.
aswSnx.sys

the minidump folder is empty  :-\
ASUS ROG Mobo - AMD Ryzen 7 3700X| RAM 32.00GB | 4TB HDD +1TB SSD | ATI Radeon RX 5700 XT 8GB
Windows 10 Pro 64bit |Avast One Individual | MBAM PRO - RealTime | SUPERAntiSpyware PRO |CC Cleaner | Chrome | Firefox |(The Latest Release of all the Software)

Offline Gopher John

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2098
Re: MY safe zone browser hijacked! goes to fake google
« Reply #77 on: April 13, 2011, 03:59:30 PM »


But how could this lead to SZ redirecting to fake sites?  :-\

And not affect non SZ connections?
[/quote]

Since SafeZone uses a different DNS server than Windows has configured, perhaps the patch now considers it as hijacked.  However, why it would redirect to the wrong (fake) site instead of Windows putting up an alert is weird.
AMD A6-5350M APU with Radeon HD Graphics, 8.0GB RAM, Win7 Pro SP1 64bit, IE11
i7-3610QM 2.3GHZ, 8.0GB Ram,  Nvidia GeForce GT 630M 2GB, Win7 Pro SP1 64bit, IE 11
Common to both: Avast Premium Security 19.7.2388, WinPatrol Plus, SpywareBlaster 5.5, Opera 12.18, Firefox 68.0.2, MBam Free, CCleaner

Offline DraKuL

  • Sr. Member
  • ****
  • Posts: 392
Re: MY safe zone browser hijacked! goes to fake google
« Reply #78 on: April 13, 2011, 04:00:31 PM »
Windows wont let me delete/overwrite SZ folder.. Folder/File access denied.. Tried running windows explorer as admin still wont let me overwrite the files..

1. Disable avast self protection

I'm assuming you mean all the real-time shields by self protection which I did.. right click Avast icon on taskbar >> disable all shields
ASUS ROG Mobo - AMD Ryzen 7 3700X| RAM 32.00GB | 4TB HDD +1TB SSD | ATI Radeon RX 5700 XT 8GB
Windows 10 Pro 64bit |Avast One Individual | MBAM PRO - RealTime | SUPERAntiSpyware PRO |CC Cleaner | Chrome | Firefox |(The Latest Release of all the Software)

disPlay

  • Guest
Re: MY safe zone browser hijacked! goes to fake google
« Reply #79 on: April 13, 2011, 04:02:44 PM »
Open Settings>Troubleshooting>Disable self protection 

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48541
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: MY safe zone browser hijacked! goes to fake google
« Reply #80 on: April 13, 2011, 04:06:37 PM »
Open Settings>Troubleshooting>Disable self protection 
Or simply do the procedure in Safe Mode. :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline DraKuL

  • Sr. Member
  • ****
  • Posts: 392
Re: MY safe zone browser hijacked! goes to fake google
« Reply #81 on: April 13, 2011, 04:07:06 PM »
Ok did all the steps and the issue is fixed. However, 30mins ago it was fine too.. I experienced the problem a few hours ago, then after sometime it worked, then again it was redirecting.. So anyway now its fine but not sure if its because of the patch or whether its like what happened earlier..
ASUS ROG Mobo - AMD Ryzen 7 3700X| RAM 32.00GB | 4TB HDD +1TB SSD | ATI Radeon RX 5700 XT 8GB
Windows 10 Pro 64bit |Avast One Individual | MBAM PRO - RealTime | SUPERAntiSpyware PRO |CC Cleaner | Chrome | Firefox |(The Latest Release of all the Software)

disPlay

  • Guest
Re: MY safe zone browser hijacked! goes to fake google
« Reply #82 on: April 13, 2011, 04:07:24 PM »
Open Settings>Troubleshooting>Disable self protection 
Or simply do the procedure in Safe Mode. :)

Yeah another quick and easy method.  :D

Offline DraKuL

  • Sr. Member
  • ****
  • Posts: 392
Re: MY safe zone browser hijacked! goes to fake google
« Reply #83 on: April 13, 2011, 04:16:44 PM »
Ok so I just copy pasted the old files and still it works fine.. So I'm not sure if it was resolved because I patched the files.. Like I said this happens on and off I think..
ASUS ROG Mobo - AMD Ryzen 7 3700X| RAM 32.00GB | 4TB HDD +1TB SSD | ATI Radeon RX 5700 XT 8GB
Windows 10 Pro 64bit |Avast One Individual | MBAM PRO - RealTime | SUPERAntiSpyware PRO |CC Cleaner | Chrome | Firefox |(The Latest Release of all the Software)

Offline pk

  • Avast team
  • Super Poster
  • *
  • Posts: 2078
Re: MY safe zone browser hijacked! goes to fake google
« Reply #84 on: April 13, 2011, 04:18:46 PM »
DraKuL, remember that before switching files, you have to click on "Turn Off" button in SafeZone. Please use downloaded version (where mailshell's DNS is disabled), then we can be sure if it's caused by mailshell DNS or somewhere else.

Offline pk

  • Avast team
  • Super Poster
  • *
  • Posts: 2078
Re: MY safe zone browser hijacked! goes to fake google
« Reply #85 on: April 13, 2011, 04:20:44 PM »
Ok so I just copy pasted the old files and still it works fine.. So I'm not sure if it was resolved because I patched the files.. Like I said this happens on and off I think..

DNS records are usualy cached, you can use: "ipconfig /flushdns"

Offline DraKuL

  • Sr. Member
  • ****
  • Posts: 392
Re: MY safe zone browser hijacked! goes to fake google
« Reply #86 on: April 13, 2011, 04:21:42 PM »
DraKuL, remember that before switching files, you have to click on "Turn Off" button in SafeZone. Please use downloaded version (where mailshell's DNS is disabled), then we can be sure if it's caused by mailshell DNS or somewhere else.

Yeah I did that. It works fine. Then I used the old files I had, still works fine.. So I'm not sure whether it was fixed by the patching of files or not..

ASUS ROG Mobo - AMD Ryzen 7 3700X| RAM 32.00GB | 4TB HDD +1TB SSD | ATI Radeon RX 5700 XT 8GB
Windows 10 Pro 64bit |Avast One Individual | MBAM PRO - RealTime | SUPERAntiSpyware PRO |CC Cleaner | Chrome | Firefox |(The Latest Release of all the Software)

Offline DraKuL

  • Sr. Member
  • ****
  • Posts: 392
Re: MY safe zone browser hijacked! goes to fake google
« Reply #87 on: April 13, 2011, 04:24:31 PM »
Ok so I just copy pasted the old files and still it works fine.. So I'm not sure if it was resolved because I patched the files.. Like I said this happens on and off I think..

DNS records are usualy cached, you can use: "ipconfig /flushdns"

Sadly I lost the backup files.. I drag and dropped them to the SZ folder, and repatched the new files.. So when I drag and dropped they were moved.. Is it possible to post a link to download the old files for the SZ ?
ASUS ROG Mobo - AMD Ryzen 7 3700X| RAM 32.00GB | 4TB HDD +1TB SSD | ATI Radeon RX 5700 XT 8GB
Windows 10 Pro 64bit |Avast One Individual | MBAM PRO - RealTime | SUPERAntiSpyware PRO |CC Cleaner | Chrome | Firefox |(The Latest Release of all the Software)

Offline pk

  • Avast team
  • Super Poster
  • *
  • Posts: 2078
Re: MY safe zone browser hijacked! goes to fake google
« Reply #88 on: April 13, 2011, 04:27:34 PM »
Quote
Sadly I lost the backup files.. I drag and dropped them to the SZ folder, and repatched the new files.. So when I drag and dropped they were moved.. Is it possible to post a link to download the old files for the SZ ?

http://public.avast.com/~kurtin/x7_old.zip

Offline DraKuL

  • Sr. Member
  • ****
  • Posts: 392
Re: MY safe zone browser hijacked! goes to fake google
« Reply #89 on: April 13, 2011, 04:32:26 PM »
flushed DNS, patched the old files, SZ works fine..  :-\
ASUS ROG Mobo - AMD Ryzen 7 3700X| RAM 32.00GB | 4TB HDD +1TB SSD | ATI Radeon RX 5700 XT 8GB
Windows 10 Pro 64bit |Avast One Individual | MBAM PRO - RealTime | SUPERAntiSpyware PRO |CC Cleaner | Chrome | Firefox |(The Latest Release of all the Software)