Hacked by Godzilla

Bit of a newbie so may be behind the times. Have “Hacked by Godzilla” appearing suddenly in the internet explorer toolbar. What is it & what to do about it? Thanks.

What Operating System are you using ? is it up to date ?

A google search returns many hits, http://www.google.com/search?q="Hacked+by+Godzilla" and this is just one of them, http://howto.redcomputer.net/windows/hacked_by_godzilla.php also http://www.able2know.com/forums/about87979.html.

If you haven’t already got this software (freeware), download, install, update and run it, preferably in safe mode.

  1. Ewido, a.k.a. avg anti-spyware If using winXP. or a-Squared free if using win98/ME.

Running Win XP Pro; latest updates OK.
Ran AVG anti-spyware & picked up worm.solow.a in the WINDOWS\MS32DLL.dll.vbs files on C & D drives & in System Volume Information_restore files on both drives. Recommended action was quarantine. On rebooting the system does not recognise ethernet controller…

Well a file with a double file extension (MS32DLL.dll.vbs) is suspicious to me and again a google search returns many hits.

I don’t know why your ethernet controller isn’t recognised, though there are some malware infections that get embedded in your connection settings, perhaps that might be what has happened here (but I doubt it). You could try a search for worm.solow.a (http://www.sophos.com/security/analyses/vbssolowa.html) and see what the symptoms might be, if it might effect the ethernet controller not recognised issue.

Again my friend google returns many hits for “ethernet controller not recognis(z)ed” http://www.google.com/search?q=ethernet+controller+not+recognized&spell=1

The c:\System Volume Information folder is a part of the system restore function and as such is protected by windows, the only way to clean infected _restore points is to disable system restore and reboot. This will clear ALL _restore points. Once you have disabled system restore, reboot, scan your PC again and if clear enable system restore.
Win XP - How to disable System Restore

Thanks for the help. All clear and last step was to go in and edit the title text in IE’s title bar which seems to have worked painlessly. Cheers.

No problem, glad I could help.

Welcome to the forums.

Windows and IE make for a very dangerous computing environment; look at how
many third party programs you need just to do some very basic tasks, such
as web browsing.

Do your self a favor, go to your local computer store, buy either SuSE or
Mandrake Linux or Mac and switch operating systems. Whichever distribution you
select, you will have no regrets.

Below are some links that can help you get started.
http://www.apple.com/
http://www.suse.com
http://www.redhat.com
http://www.lindows.com
http://www.turbolinux.com
http://www.linuxhq.com/vendors/
http://www.nvu.com/

Hi flygirl,

When do you think the turning point will come when people start to make the transition to an alternate OS rather than M$. Well you know it is question of habits, the OS that came already programmed on your home pc’s, and the machine to work with at the job, the way to contact uncle Harry and aunt Mary. It is so hard to give it up… What do you think is the turning point for the “sheople” to jump? Is it really that difficult?

polonus

I found something interesting about M$ at http://sillydog.org/msbad.php . I looked into it and I thought about switching my system for another OS.

Can avast detect this virus? I have a variant of this virus ( http://www.sophos.com/security/analyses/vbssolowb.html ), and up to now, avast still can’t detect it. Information about the ‘Hacked by Godzilla’ variant here: http://www.sophos.com/security/analyses/vbssolowa.html

If you have a variant that is undetected then either email or add it to the virus chest and the sample to avast, see below.

Send the sample to virus@avast.com zipped and password protected with password in email body and false positive/undetected malware in the subject. Or you can also add the file to the User Files (File, Add) section of the avast chest where it can do no harm and send it from there (select the file, right click, email to Alwil Software). No need to zip and PW protect when the sample is sent from chest.