Google redirects to another search engine

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cooperg, Dec 30, 2010.

  1. cooperg

    cooperg Private E-2

    Hi, I have a problem with some sort of malware that is causing any use of google to be blocked or redirect to a fake search engine.

    This started around christmas day. I first noticed that if I try to use the google.co.uk or google.com quick search engine in firefox, any search resulted in the following page being displayed -

    Not Found

    The requested URL /search was not found on this server.

    Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.


    If I then actually type in the google URL in the address bar, I get a search engine that looks like google, and even retains the google.co.uk/.com URL in the address bar, but it isn't google. The site appears to be called 'The Search' and provides a 'powered by google' entry field so that you can still carry out a google search from the page.

    Having dug around a bit I think that the actual host of this search site is www.mavideniz.gen.tr.

    I've followed the READ ME and the malwarebytes scan did appear to find some stuff linked to mavideniz, but even after cleaning this all up, I'm still get the problems. I've attached logs below. I couldn't run combofix as I couldn't get to the download site.

    Any help much appreciated!

    Cheers,

    Steve
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program

    Now download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Now how are things working?
     
  3. cooperg

    cooperg Private E-2

    Hi...thanks a lot for the speedy reply.

    I've run the HostsExpert and that appears to have sorted the redirect issues. I can now use the google quick search engine in firefox and I can type in google.co.uk/.com URLs and successfully get to those sites.

    I downloaded TDSSkiller as well but when I run it I get the little windows error popup saying 'TDSS rootkit removing tool has encoutered a problem and needs to close. We are sorry for the inconvenience'. If I go into the extra info a about the error its a big dump of stuff relating to dlls and loads of hex.

    Is it essential to run TDSSkiller to make sure I've cleansed my machine properly, and if so, any ideas why it might be bombing out when I run it?

    Thanks again...much appreciated!

    Cheers,

    Steve
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If everything is okay now you don't need to run it. Not sure why it is crashing. It could be due to having both Symantec Client Security and Webroot Spy Sweeper running. And by the way, you really should not have Spy Sweeper installed. You already have antispyware and antivirus protection with Symantec. Having both can cause conflicts and will also slow your PC down.

    We have a couple minor things to do.

    You should uninstall the below very outdated IBM Java which is a security risk. You already have the current Sun Java installed:
    IBM 32-bit Runtime Environment for Java 2, v5.0

    Delete the below file:
    C:\WINDOWS\Tasks\at1.job

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O16 - DPF: {1ACECAFE-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http://
    O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http://

    After clicking Fix, exit HJT.

    Now if you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  5. cooperg

    cooperg Private E-2

    Ok...have applied the minor fixes and done all the cleanup and all seems to be fine.

    Thanks a lot for your help....it really is very much appreciated.

    Happy new year!

    Cheers,

    Steve
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.

    Happy New Year!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds