Spy Bouncer hijacked google.com

Discussion in 'Malware Help (A Specialist Will Reply)' started by JB15426, Jul 4, 2005.

  1. JB15426

    JB15426 Private E-2

    When I try to go to google.com my browser is taken over by spy bouncer and I get 5-6 popup ads for spyware and virus protection. How can you sponsor a company that does that? Ad-aware doesn't remove it. How can I get rid of this pest? Spy Bouncer isn't installed and I don't want to install it. This is total crap!
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I apologize for any problems you may be experiencing, I wasnt aware that this program was on the list of rogue/suspect antispyware programs.

    The company that owns this application is SRC Technologies, which also has another application called GuardBar which has been thought to be rogue as well. One thing I wanted to point out is that SRC Technologies the company that owns this program has an affiliate thats owns a domain goggle.com. In some cases users mix up this domain for the legit domain google.com. The same company also owns a domain PostalManager.com that has had numerous complaints about spam, the company states its a email list management and delivery service. So basically what all of this means is that SpyBouncer & GuardBar are completely useless and should be avoided!

    For your current problems, lets start by getting a HJT log.

    http://www.majorgeeks.com/images/grenade.gif Download HijackThis 1.99.1

    http://www.majorgeeks.com/images/grenade.gif Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    http://www.majorgeeks.com/images/grenade.gif Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    http://www.majorgeeks.com/images/grenade.gifBefore running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    http://www.majorgeeks.com/images/grenade.gifRun HijackThis and save your log file.

    http://www.majorgeeks.com/images/grenade.gif Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    http://www.majorgeeks.com/images/grenade.gifNeed help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  3. JB15426

    JB15426 Private E-2

    Now I'm embarrased! I can't spell google! This is a work computer shared by 30 people and when I ran Ad-aware it found over 900 critical objects. Our IT dept doesn't care about spyware or trojans. I'll fixed tomorrow even though I'm not supposed to.

    But why is Spybouncer a featured download on Major Geeks? You guys have always had total disgust of rogue programs and beat them up in your forums. :confused:
     
  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Like bjgarrick, we were unaware.

    Im concerned about the goggle spelling hijack (deceptive advertising) and am checking into it. Not as concerned about false positives, this exists in most programs that tag cookies as spyware as a scare tactic. Odds are we will remove it, thanks to you.

    Remember, its people like yourself who are a huge asset to making sure we keep safe tools online since it is hard for us to check on software regularly after it is added.

    Thanks.
     
  5. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Clarification after talking to my partner, Jim:

    We do not know when they made the rogue list and we were unaware they were on it. There is a GOOD possibility an advertiser they are affiliated with is doing this and SpyBouncer is unaware of it. It has happened to us through our advertising affiliates on a few occasions, we personally reject advertising as soon as we are aware it is inappropriate. Jim has contacts at SpyBouncer and will call them tommorow. If we can not get a happy resolution from the phone call, it will be removed immediately.
     
  6. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    As Tim said -- I'll call them first thing in the morning. We have dealt personally with them on oand off for several months and they are pretty good guys. I’m rather shocked actually. Near as I remember the PostalManger.com thing the problem was with users of their service -- Not the service itself. Meaning someone was abusing it and they got caught in the mosh.

    They were not on the rogue list when we added SpyBouncer here. We specifically check that list before adding anything.
    It does appear they are getting a bad rap because of an advertiser they are doing business with, however if they are going to continue to do business with a hijacker – I’m not sure that makes them any better than the hijacker.
     
  7. JB15426

    JB15426 Private E-2

    Thanks for the support :) . When I get into trouble the first thing I type is majorgeeks.com :) You guys helped me bail myself out of trouble this time last year. You know one of the best I did was add the enhanced host file! I got the cws virus a few months ago and my computer slowed down and my browser begin acting funny. I stopped everything and ran all of my spyware and virus software and cleaned up the cws beast. It couldn't get out to the internet so did no real damage :) . I was impressed!

    Take care ;)

    John
     
  8. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    Glad to help. We were the first download site to take a stance against spyware and we e figure if we list a product it reflects on our reputation, so we take it very seriously.

    Been doing a little research. The product itself works fine… I just double checked it. Is it best of breed? No. But it is useful.

    The product definitely was added to the rogue list after it was added here. The reason is almost 100% because of that goggle site, which we did not know about. The false positives were attributed to their guardbar product that was in a pretty early beta stage. I’m oit sure that is a fair assessment, but no one at spyware warrior has looked at it again since last year.. The google site installs an OCX from spy bouncer to run on “online scan” of the software, that will send a lot of people into a panic, but it’s very similar to what trend micro does – I don’t see any hijack.

    There are a LOT of pop ups from ads.revenue.net. Yikes! Revenue.net is owned by oversee.net --- oversee.net seems to have some real history problems installing malware. The pop ups themselves may be the hijack problem – Sorry I didn’t have the guts to install the software they were pushing. I have better things to do than reformat my machine today. ;)

    Also, as an FYI - Goggle is owned by a company whose address is a UPS store and phone number is disconnected. Not a good sign.

    But all in all, looks like 100% a guilt by association thing. We are reserving judgment until I speak with Joe, (Spy Bouncer guy) – But if they have knowledge that they are doing business with these sorts, I’d have to agree with Spyware Warrior on this one.
     
  9. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    As an update -- Just got off the phone with Joe from SpyBouncer.

    While we agree with him that there is technically wrong with the ads, we all agree that there is clearly a perception problem with what is being done.

    Nothing is hijacked, people just think they are being hijacked because they mistyped something. However by dropping in active x competent and pop ups on a mistype… You clearly have the appearance of impropriety.

    Joe is working to correct the problem now with goggle as well as with Spyware Warrior.,
    We have removed them as a feature until it is resolved, but have left them listed as a valid product in the meantime; as we are certain this will be corrected quickly.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds