Problems with Google searching

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by TKH, Sep 28, 2008.

  1. TKH

    TKH Private E-2

    I'm not sure if this is the correct forum to post this, but I'm having problems searching using Google. (Yahoo works just fine.) The search results look legitimate--searching "Martha Stewart" will return the first result titled "Martha Stewart Living" which states "Official site, with links to personal information, Martha's Scrapbook, television highlights, radio guide, virtual studio, recipes, live chat" but the URL is *pronto.com. The second search result is titled "Martha Stewart - Wikipedia, the free encyclopedia" and it states "Martha Stewart (born Martha Helen Kostyra; August 3, 1941) is an American business magnate, television host, author, and magazine publisher..." but the URL is *cheapflights.com. This started Thursday or so of last week.

    I've read the Read & Run Me First malware removal guide, and I've completed the Win XP cleaning procedure and am attaching the logs (hope these are the right ones).

    Any help you can provide would be appreciated since I use Google for work and would really love to get it working again.
     

    Attached Files:

    Last edited by a moderator: Sep 29, 2008
  2. TKH

    TKH Private E-2

    Problems with Google searching Part 2

    Here is the MGlogs.zip attachment.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There are just a few things we can try:

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Tell me what problems you are having.
     
  4. TKH

    TKH Private E-2

    Hi, TimW. Thanks for answering my post. Did all the stuff you recommended, and Google sadly is still not working. A search for "Martha Stewart" showed *newyorker.com as the first URL in the results list, and *smarter.com as the second, easyapproval.novacarcredit.com as the third, etc, etc. (Hope that makes sense. Would love to attach a screen shot, but I don't know how.)

    Any ideas? Should I try to install Firefox or something to circumvent IE and try to get on Google that way?
     
    Last edited by a moderator: Sep 30, 2008
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you run Spybot and if so could you attach a log? You should also have it restore the hosts file.
     
  6. TKH

    TKH Private E-2

    I ran Spybot on 9/28 when I did all the other scans as part of the Windows XP cleaning. Dumb question: I can't find the log--what is it called, and where might it be? Or did you want me just to run it again & post that log?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go ahead and run it again..:)
     
  8. TKH

    TKH Private E-2

    Hi, TimW. Sorry about the delay in responding. I just ran Spybot again. It said, "Congratulations! No immediate threats were found," next to a big, green checkmark. Again, I can't find a log to attach for you. Where do I look? And also, I can't find a way to tell it to restore the host files. Any ideas how to do this?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  10. TKH

    TKH Private E-2

    I figured out I had to go to Mode on the Spybot toolbar and select "Advanced Mode" to get to the Settings. I tracked down a few logs--here are the two with today's date. Let me know if they're not what you need.

    I'm not sure how to "restore" host files--the tutorial didn't help w/ this. I can go into Tools in Spybot and enable "Hosts files" which then shows a long list of websites that are blocked by Spybot, but I'm pretty sure this is not "restoring my host files." How do I do this?
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have any in the hosts list that DO NOT point to 127.0.0.1?


    download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
     
  12. TKH

    TKH Private E-2

    No, I don't have any that don't point to 127.0.0.1.

    HostsXpert downloaded and run.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you cleared your browser cache? Have you flushed your DNS server? Can you get in safe mode w/networking and does it happen there also?

    Give this rootkit detector a run and attach the log: AVG Anti-Rootkit.
     
    Last edited: Oct 6, 2008
  14. TKH

    TKH Private E-2

    Cleared browser cache, cookies & history. Do this every few days anyway.

    Got into safe mode w/ networking; Google doesn't work there, either. A search for "Martha Stewart" this time returned www.thegoodcook.com, www.boostmobile.com and other such non-related URLs.

    What is a DNS server, and how do I flush it? Tried to look this up using Yahoo, but the explanations make no sense to me.

    Your link for that rootkit is returning a blank Major Geeks page--nothing to download there. Am I looking in the wrong place, or is that link not working?
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Bad link.....try this:
    Download Blacklight Beta.

    * Download blbeta.exe and save it to the Desktop.
    * Once saved... double click blbeta.exe to install the program.
    * Click accept agreement and Click scan
    This app too may fire off a warning from antivirus. Let the driver load.
    Wait for it to finish.
    * If it displays any items...don't do anything with them yet. Just hit exit (close)
    * It will drop a log on Desktop that starts with fsbl....big number

    Please post contents of the BlackLight log.

    To flush the DNS....go to start / run / type "cmd" without quotes....at the command prompt, type "ipconfig/flushdns" without qoutes.....then hit enter then you can type exit to get out of the command prompt.
     
  16. TKH

    TKH Private E-2

    Here's the Blacklight log. It said it didn't find anything :(

    Did the steps re: DNS flushing. Got this message: "Windows IP Confirguration successfully flushed the DNS Resolver Cache."

    Google's still not working.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    One more shot....download but do not install IE7 (or 8)....go to your program folders and right click and delete the Internet Explorer folder, then reboot and install IE7. See if that works.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Additionally:
    Open one browser window of IE and one browser window of FireFox. Then run C:\MGtools\GetLogs.bat to get a new MGlogs.zip file.

    Also let's see if this is something related to just those two browsers somehow by having him download and install Opera Run it and see it the samething happens.

    Reboot and log into the other user accounts ( not by doing a switch user, but logging out and doing a reboot) one by one after a reboot and tell me if the same thing happens.

    Do you have another PC in the house that can be hooked up to see if the problem also occurs there?


    * What kind of internet connection (cable, DSL,..etc)do you have?
    * Do you use a router?
    * Have you power cycled any modem and also router if being used?

    If a router is being used and power cycling it and the modem do not help, I would recommend a direct connection from the PC to the modem just to see what happens.

    Please attach this log:
    Code:
    "C:\Documents and Settings\Tess\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\"
    mbam-l~1.txt  Sep 26 2008        8641  "mbam-log-2008-09-26 (09-49-59).txt"
    
    What is the below file on the Desktop
    Code:
    "C:\Documents and Settings\Tess\Desktop\"
    ~             May 13 2008      177559  "~"
    
     
  19. TKH

    TKH Private E-2

    I want to deal w/ yesterday's message about downloading a new IE, but I'm very nervous about deleting my old IE folder in case something goes off the rails & I can't install the new IE. Will your process have the same effect if I just rename my old IE folder instead of deleting it?
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Deleting the folder will put it in the recycle bin....so you can retrieve it if need be. But hold off on that until we explore the other questions in my last post. :)
     
  21. TKH

    TKH Private E-2

    Open one browser window of IE and one browser window of FireFox. Then run C:\MGtools\GetLogs.bat to get a new MGlogs.zip file.
    Log attached

    Also let's see if this is something related to just those two browsers somehow by having him (her) download and install Opera Run it and see it the samething happens.

    Opera works great. Successful searching.
    Firefox, the first time I enter a search term--doesn't matter what it is--I get related URLs returned. But every search thereafter, no matter what the search term, returns useless URLs. Logged out & rebooted twice to test this theory, and it happened every time. Firefox works great once, and then returns garbage. Oddly, Firefox worked properly every time for the other two users on my computer.



    Reboot and log into the other user accounts ( not by doing a switch user, but logging out and doing a reboot) one by one after a reboot and tell me if the same thing happens.

    User 2
    Opera: successful searching
    Firefox: successful searching
    IE: totally unrelated URLs returned for every search term entered (tried five different ones - Starbucks, LL Bean, Lehman Brothers, Martha Stewart, Nike)

    User 3
    Opera: successful searching
    Firefox: successful searching
    IE: totally unrelated URLs returned for every search term entered

    I find it interesting for these users that Firefox is using a Google search and it works, yet the Google search on IE doesn't work. Weird.


    Do you have another PC in the house that can be hooked up to see if the problem also occurs there?
    Sadly, no

    * What kind of internet connection (cable, DSL,..etc)do you have?
    high-speed cable
    * Do you use a router?
    no
    * Have you power cycled any modem and also router if being used?
    yes, to no avail

    If a router is being used and power cycling it and the modem do not help, I would recommend a direct connection from the PC to the modem just to see what happens.
    No router

    Please attach this log:

    Code:
    "C:\Documents and Settings\Tess\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\"
    mbam-l~1.txt Sep 26 2008 8641 "mbam-log-2008-09-26 (09-49-59).txt
    Log attached

    "What is the below file on the Desktop

    Code:
    "C:\Documents and Settings\Tess\Desktop\"
    ~ May 13 2008 177559 "~"

    I'm not entirely sure, but I think it's an old Word document. Can't get it open to double check.
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Add those URLs to your Restricted Zone. In addition, you should try adding the below to your C:\windows\system32\drivers\etc\hosts file

    127.0.0.1 goodcook.com
    127.0.0.1 newyorker.com
    127.0.0.1 novacarcredit.com
    etc.

    After adding the above to your hosts file and also adding those URLs and IP to your Restricted Zone you should reboot to see if there is an change.

    If not, go here and download SysClean:

    http://www.trendmicro.com/download/dcs.asp

    You will need to download two additional files, one for viruses and the other for spyware. Instructions for which ones to download are found here:

    http://www.trendmicro.com/ftp/products/tsc/readme.txt

    After running SysClean, attach the log from it.
     
  23. TKH

    TKH Private E-2

    127.0.0.1 goodcook.com
    127.0.0.1 newyorker.com
    127.0.0.1 novacarcredit.com
    etc.


    What do you mean by "etc?" I can't add every URL that comes up every time I do a search in Google--there are millions of them. And sometimes the URLs are legitimate. Newyorker.com will take you to the home page for The New Yorker magazine, for instance. Which is fine--I just don't want it showing up as my first result when I do a search for "Martha Stewart." And sears.ca will take you to Sears, which is a website I do visit, so again I don't want to block it. I just don't want sears.ca showing up when I search for "Starbucks."

    I'm not sure I know what you mean by adding "those URLs" to my restricted zone and hosts file. There's not a specific set of URLs that show up every time I do a search; they're different ones every time...
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Gotcha.....was thinking they were mis-directs....go ahead and do the sysclean and get that log.
     
  25. TKH

    TKH Private E-2

    Here's sysclean.log. There's also a report.log, but I can't get it to upload--it just times out. It's 21,544 KB. Do you need that one, too?
     

    Attached Files:

  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It cleaned up some infected cookies....:(

    Are you still having the same problems?
     
  27. TKH

    TKH Private E-2

    Yep.

    Do you still want me to try to reinstall IE? We put that idea aside to work on some others...
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What version are you running and what version did you download?
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    One more question that we should have asked long ago......did you disable all add-ons and remove all toolbars in all user accounts that have the problems?
     
  30. TKH

    TKH Private E-2

    Hi, TimW. Sorry for the delay in responding. Hope you didn't think my silence meant the problem was resolved. No such luck!

    I did disable all add-ons and remove all toolbars as suggested, but it made no difference. Google is still not working.

    I downloaded IE7 to my desktop to install later, and when I tried to delete my current version of IE (don't know what version--how do I find that out?) it said it couldn't be deleted b/c it was being used by another person or program. Which is odd, b/c I had nothing open at the time, so how could IE be in use? I checked Task Manager, and there didn't appear to be any open copies of iexplorer.exe...

    Any thoughts?
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just go ahead and install IE7. Don't allow it to import anything if it asks to.
     
  32. TKH

    TKH Private E-2

    Hi, TimW.

    I installed IE 7, and there was no change. Google still didn't return URLs that matched the search results.

    But....

    Today I was told by my computer that my trial version of AVG had expired. I downloaded a trial version? Huh? I remember uninstalling it at one point b/c I thought it might be the culprit, and then reinstalling it, and I guess I reinstalled a trial version by accident instead of the full-blown free version.

    Anyway, I had two choices: buy the version I was using to continue to use it, or uninstall it, and I uninstalled it...

    And now Google works!

    (I uninstalled AVG 8.0 Build 169, for what that's worth.)

    I have no idea if Google working corresponds w/ the uninstalling of AVG, but it's awfully co-incidental. What's your opinion on the two being related?

    So, now I need your professional advice on what anti-virus I should install, and it should preferably be free (although I'll pay for something if you think it's really, really worth it), and it should preferably not be anything AVG related b/c I'm kind of gun-shy of that product right now.

    I also need your professional advice on what I can clean off my desktop in terms of all these scanning programs I've installed, and any other final clean-up stuff I need to do.

    I think I'll go Google some stuff, just b/c I can...
     
  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok...now that got me laughing.....:-D

    Our top freeware picks include either Avast or Avira....many of us have switched from AVG to Avast without incident.

    Go google it.....:-D or just go HERE.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds