Problems with Google and Browser Hijacking

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by slo_life, Feb 23, 2011.

  1. slo_life

    slo_life Private E-2

    I've done all of the readme's in the FAQ, I started last week before my laptop fan crashed and finished up today.

    The problem that I'm having is when I search google and click on a result, some of the time I am redirected to a site, related to the site I intended to enter.
    These sights look like a squeeze page typical of google adwords site. Also when I try and go to certain websites in my browser such as godaddy.com, I am often redirected momentarily through another site I can only briefly catch the name as rss2search.com. I think the rss2search.com might be associated with hotspotshield, but Is google click hijacking related to that also? I've removed hotspot shield and the problems continue.

    When I try to log onto the cpanel for my shared hosting it redirects to an ask.com search as if it can't find the webpage.
    I use firefox and https://server25.web-hosting.com:2083/ shows up in the ask search box.

    I've attached the logs, and help would be much appreciated.
     

    Attached Files:

  2. slo_life

    slo_life Private E-2

    More Logs
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
    Are you still being redirected after reboot?

    Did you setup the below proxyserver?
    ProxyServer REG_SZ 68.234.11.156:52931
     
  4. slo_life

    slo_life Private E-2

    I ran that at the beginning, and I was still redirected, I forgot about that log here it is.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That log is from 8 days ago. I want to see a log from a current scan to be sure of your status now.

    Please answer my question abou the proxy server. If you did not set it up, please see the below to remove it.

    Proxy Server - Changing Settings


    I'll be back tomorrow evening. Time for some sleep now.
     
  6. slo_life

    slo_life Private E-2

    Thank You I really appreciate your help. I had no idea i was connecting through a proxy. Once I disabled that and rebooted, the problem went away.

    Is there a program that will keep reconfiguring me to connect through a proxy.

    I attached the new log also. But the problem seems to be fixed. Crazy I haven't used my computer in 8 days I guess thats what you get when it takes 7 days for IBM to "Overnight" your new fan.

    Thank you again.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No your logs are clean. However if you had your network configuration locked or registry changes being intercepted/blocked by any protection software, it could come back after a reboot due to your protection software not recognizing the change that you made as being valid.

    Are you currently having any other malware problems?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds