1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Search results being redirected IE and Firefox

Discussion in 'Malware and Virus Removal Archive' started by carab, 2010/06/19.

Thread Status:
Not open for further replies.
  1. 2010/07/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Absolutely nothing here.

    I don't recall...
    Do you use modem AND router, or is it modem/router combo?
     
  2. 2010/07/11
    carab

    carab Inactive Thread Starter

    Joined:
    2010/06/19
    Messages:
    55
    Likes Received:
    0
    modem and router
     

  3. to hide this advert.

  4. 2010/07/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    OK. Turn computer off.
    Get the router out of the picture.
    Disconnect modem from the power source and from the internet (disconnect coaxial cable) for 1 minute.
    Connect computer straight to the modem.
    Power everything up and check for redirection.
     
  5. 2010/07/11
    carab

    carab Inactive Thread Starter

    Joined:
    2010/06/19
    Messages:
    55
    Likes Received:
    0
    It still does it. HOwever, when I use bing.com, it doesn't seem to redirect. I haven't tried any other search engines (w/ bing.com i went to about 20 different links to make sure it wasn't happening so i ran out of patience to try other search engines).

    I usually only use google. So the redirecting happens with google, whether i go to google.com or if i use the search box at the top of the browser. With bing, i can go directly to the website, or i can use the search box in the browser, and i dn't get any redirection.

    Is it possible that GOOGLE is doing this??
     
  6. 2010/07/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I don't see, how it'd be possible.
    Let's try one more thing.
    Let's start with IE.
    In IE, go Tools>Internet options>Advanced tab and click on "Reset" button.
    Restart IE and see, if you have same problem with Google.
     
  7. 2010/07/11
    carab

    carab Inactive Thread Starter

    Joined:
    2010/06/19
    Messages:
    55
    Likes Received:
    0
    Still happens with google, still doesn't with bing.
     
  8. 2010/07/11
    carab

    carab Inactive Thread Starter

    Joined:
    2010/06/19
    Messages:
    55
    Likes Received:
    0
    yahoo seems to be fine too
     
  9. 2010/07/11
    carab

    carab Inactive Thread Starter

    Joined:
    2010/06/19
    Messages:
    55
    Likes Received:
    0
    aol DOES redirect
     
  10. 2010/07/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    This is a total mystery...

    Download the MBR Rootkit Detector: http://www2.gmer.net/mbr/mbr.exe to your desktop.

    * Doubleclick mbr.exe and follow prompts (Vista users: right click on mbr.exe and click "Run As Administrator ").
    * A black DOS window will quickly appear then disappear.
    * When mbr.exe is finished it will create a log on your desktop.
    * Copy and paste contents of that log (mbr.log) file to your next reply.
     
  11. 2010/07/11
    carab

    carab Inactive Thread Starter

    Joined:
    2010/06/19
    Messages:
    55
    Likes Received:
    0
    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

    device: opened successfully
    user: MBR read successfully
    kernel: MBR read successfully
    user & kernel MBR OK
     
  12. 2010/07/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Just for the heck of it....

    If you have Vista DVD...

    start with step 2

    If you don't have Vista DVD...

    1. Create Vista Recovery Disc.

    Option 1:
    http://www.c4consulting.com.au/soluctions/vista/VISTA SOLUCTIONS.htm

    Option 2:
    Download Vista Recovery Disc iso image: http://neosmart.net/blog/2008/windows-vista-recovery-disc-download/
    Burn it to CD, or DVD: http://neosmart.net/wiki/display/G/Burning+ISO+Images+to+a+CD+or+DVD

    2. Boot from created disk.
    At first screen click on Repair your computer:
    [​IMG]
    This will bring you to a new screen where the repair process will look for all Windows Vista installations on your computer. When done you will be presented with the System Recovery Options dialog box:
    [​IMG]
    After this, it will present you with a list of options including startup repair, system restore and command prompt:
    [​IMG]
    Select Command Prompt

    Type in:
    bootrec /FixMbr
    and then press Enter

    Once completed then type Exit, press Enter and restart computer.

    Check for redirections.
     
  13. 2010/07/11
    carab

    carab Inactive Thread Starter

    Joined:
    2010/06/19
    Messages:
    55
    Likes Received:
    0
    That sounds fun... so fun that I'm going to save it for tomorrow. :)

    I'm back on wireless... hopefully that's ok. Goodnight!

    Thanks for not giving up on me, yet.
     
  14. 2010/07/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I'll be getting ready for bed pretty soon, so no rush.

    You know, I hate unsolved mysteries. I had some tough cases in the past and somehow I was able to solve them, but this case is something else, unless....we're dealing with some kind of new bad guy on the block, I'm not aware of yet.

    I'll check on you tomorrow after work :)
     
  15. 2010/07/13
    carab

    carab Inactive Thread Starter

    Joined:
    2010/06/19
    Messages:
    55
    Likes Received:
    0
    I haven't gotten around to doing the restore yet, but wanted to let you know that it IS doing it with bing.com now....
     
  16. 2010/07/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    OK. I'll waiting...
     
  17. 2010/07/14
    carab

    carab Inactive Thread Starter

    Joined:
    2010/06/19
    Messages:
    55
    Likes Received:
    0
    i thought it had worked, but as soon as i used the google search toolbar, it started happening again.
     
    Last edited: 2010/07/14
  18. 2010/07/14
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Upload following files to http://www.virustotal.com/ for security check:
    - explorer.exe located @ C:\Windows
    - userinit.exe and svchost.exe located @ C:\Windows\System32
    Post scans results.
     
  19. 2010/07/15
    carab

    carab Inactive Thread Starter

    Joined:
    2010/06/19
    Messages:
    55
    Likes Received:
    0
    Explorer:
    MD5: 37440d09deae0b672a04dccf7abf06be
    First received: 2009.02.12 14:12:33 UTC
    Date: 2010.07.13 17:09:35 UTC [+1D]
    Results: 0/42
    Permalink: analisis/c8ecd4bd0c167fe28e73219b6c366b2386472c78858d3b8448c5126df72aac45-1279040975

    userinit
    MD5: 22027835939f86c3e47ad8e3fbde3d11
    First received: 2009.02.23 01:15:34 UTC
    Date: 2010.07.07 07:37:21 UTC [>8D]
    Results: 0/41
    Permalink: analisis/24eec90e3b04c2d8d9861ea795d6178b1c4a66c9896029838149deda6a07dcaf-1278488241

    svchost
    MD5: 10da15933d582d2fedcf705efe394b09
    First received: 2008.03.02 11:24:16 UTC
    Date: 2010.07.11 12:26:34 UTC [>4D]
    Results: 0/41
    Permalink: analisis/9b1619ac80379456c6d51780409e3c418dd5aa38d0a62b7f47dcd6fc3a947926-1278851194
     
  20. 2010/07/15
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    At this point, I'm out of tools and ideas.
    It never happened to me to give up on a malware issue, but I'm about to.

    I just emailed a friend to take a look at this thread.
    She's a very busy person and I'm not sure, how soon it's going to happen.
    I'll wait fir her reply and I'll post back, as soon, as I know something.
     
  21. 2010/07/15
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    My friend gave me one more idea...

    Please download Profiles by noahdfear.

    * Save it to your desktop.
    * Double-click profiles.exe and post its log when you reply.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.