# I've been Googlejacked!

**URL:** <https://boards.straightdope.com/t/ive-been-googlejacked/205510>\
**Category:** Factual Questions\
**Created:** [October 4, 2003, 5:29am UTC](https://boards.straightdope.com/t/ive-been-googlejacked/205510 "2003-10-04T05:29:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![The\_Raven\_1](https://avatars.discourse-cdn.com/v4/letter/t/7993a0/32.png) [@The\_Raven\_1](https://boards.straightdope.com/u/The_Raven_1)\
**Post date:** [October 4, 2003, 5:29am UTC](https://boards.straightdope.com/t/ive-been-googlejacked/205510/1 "2003-10-04T05:29:07Z")

</div>

Howyadoin,

My browser has been freaked out somehow… If I try to go to [google.com](http://google.com) or [altavista.com](http://altavista.com) my browser tries to go to 207.44.194.56, which goes to someone called [cPanel.net](http://cPanel.net). I tried flushing my DNS cache with ipconfig /flushdns, cycled power to the router and DSL modem and PC. Nothing funny in the HOSTS file. Other sites I’ve tried ([alltheweb.com](http://alltheweb.com), [f-prot.com](http://f-prot.com), [verisign.com](http://verisign.com)) seems OK. The computer is using Win2K w/SP3, IE 5.5 w/SP2.

I have another computer (Win98SE, IE5-ish) connected to the same router that is running fine.

Any ideas? I’m sthumped…

-Rav

---

<div class="post-metadata">

**Author:** ![Leaper](https://avatars.discourse-cdn.com/v4/letter/l/4bbf92/32.png) [@Leaper](https://boards.straightdope.com/u/Leaper)\
**Post date:** [October 4, 2003, 5:41am UTC](https://boards.straightdope.com/t/ive-been-googlejacked/205510/2 "2003-10-04T05:41:09Z")

</div>

Sounds like the problem described in [this thread](http://boards.straightdope.com/sdmb/showthread.php?threadid=215267). Might want to try the suggestions there.

---

<div class="post-metadata">

**Author:** ![Hauky](https://avatars.discourse-cdn.com/v4/letter/h/0ea827/32.png) [@Hauky](https://boards.straightdope.com/u/Hauky)\
**Post date:** [October 4, 2003, 5:49am UTC](https://boards.straightdope.com/t/ive-been-googlejacked/205510/3 "2003-10-04T05:49:24Z")

</div>

See my posts in [this thread](http://boards.straightdope.com/sdmb/showthread.php?s=&threadid=214530) for a fix. The short version: You got a Trojan horse and you have to clean it up manually.

---

<div class="post-metadata">

**Author:** ![The\_Raven\_1](https://avatars.discourse-cdn.com/v4/letter/t/7993a0/32.png) [@The\_Raven\_1](https://boards.straightdope.com/u/The_Raven_1)\
**Post date:** [October 4, 2003, 5:57am UTC](https://boards.straightdope.com/t/ive-been-googlejacked/205510/4 "2003-10-04T05:57:37Z")

</div>

Howyadoin,

I’d done the HOSTS file mod for that sitefinder hijack a couple days ago… Thanks for the trend-micro recommendation. I tried F-Prot and it didn’t find anything, neither did Spybot or Ad-Aware. Man, it’s been a loong time since I got whacked with a trojan. Time to look into Opera, methinks.

Thanks guys, you all rock! Should have known someone would have seen this one before. Sorry, mods, for the dupe thread. Feel free to close this.

-Rav

---

<div class="post-metadata">

**Author:** ![John\_Kentzel-Griffin](https://avatars.discourse-cdn.com/v4/letter/j/ccd318/32.png) [@John\_Kentzel-Griffin](https://boards.straightdope.com/u/John_Kentzel-Griffin)\
**Post date:** [October 4, 2003, 7:52am UTC](https://boards.straightdope.com/t/ive-been-googlejacked/205510/5 "2003-10-04T07:52:09Z")

</div>

> [@](#):
>
> \*Originally posted by \*\*\*The\_Raven \*\*
> 
> Sorry, mods, for the dupe thread. Feel free to close this.

No problem. This is closed.

**DrMatrix** - GQ Moderator
