Have you been noticing âstrangeâ search results when youâre surfing the web? Have your search results been taking longer than usual to appear? You may have been infected by a new, very clever bit of malware known as Redirector.Paco.
There are actually two flavors of this malicious software, the key differences between them is that one version sets up a proxy server on your local machine to serve the phony search results, while the other routes your search inquiry through a server that the hackers control, elsewhere on the ânet.
In both cases, what you get are search results generated by the hackersâ custom search engine. They do this because theyâre spring boarding off of Googleâs Adsense For Search, which is used by legitimate website owners, worldwide. If youâve ever used the search bar on any website youâve visited, youâve seen Adsense for Search. The site owner makes money when you click on the search results generated by the search bar on their site.
In this case, the hackers have co-opted that process and display their search results, so every time you think youâre doing a search on Google, Yahoo, or Bing, they are making money with each link you click on the search results page. Unfortunately, the malware is notoriously well-designed, spoofing certificates such that once itâs installed, your computer has no idea that anything is amiss.
To date, the malware has infected nearly a million computers worldwide by hiding in modified versions of installers for popular programs like YouTube Downloader, WinRAR, KMSPico, and Stardockâs Start8.
Depending on which version is installed on your machine, you may notice that your search results take significantly longer than they used to, in order to display. If thatâs the case, pay close attention to your browserâs status bar. You may see something like, âdownloading proxy script,â or âwaiting for proxy tunnel.â If so, then youâve been infected.
So far, there arenât many antivirus programs or anti-malware suites that can remove this for you, but rest assured that updates are coming, now that this latest threat has been identified. If youâd rather not wait, and want to take action now, give one of our knowledgeable team members a call. We can inspect the machines on your network and determine whether or not youâve been impacted.
