Google Searches Redirect to searchfindsite.com

Discussion in 'Malware Help (A Specialist Will Reply)' started by Case3688, Dec 20, 2009.

  1. Case3688

    Case3688 Private E-2

    Hey guys,

    I believe I have malware that causes my Firefox searches to redirect to spam some sites. Some info:

    -When I click on a result, sometimes I'm redirected to a site called searchfindsite.com and other times I get a blank page.
    -When I right click anywhere on the page, I get another blank page.
    -This only occurs on Firefox. I've testing using Chrome and IE 8 and haven't had the same issue.
    -This also has seemed to affect other processes on my computer. It's caused other programs to stall to the point where I've had to power down or reset the computer.
    -I'm running Windows XP, Service Pack 3.

    I first tried to fix this myself. Here are a few of the things I've done.

    -Downloaded several malware programs: Malwarebytes Anti-Malware, HiJack This, Spybot Search & Destroy, Lavasoft AdAware, and Windows Defender. Ran full scans for each. Got only tracking cookies except for Anti-Malware showed something called "Worm.Autorun.B", which I fixed.
    -Tried disabling then removing all Firefox extensions.
    -Tried uninstalling Firefox, deleting all associated files, and clearing all associated registry keys.
    -Run complete scans and boot time scans with Avast Anti-Virus. This discovered a Trojan that I believe is unrelated. It was removed and no longer shows up.

    After all of this it's still happening. Anybody have any ideas?

    Any help would be greatly appreciated. I'll include a little more information in a reply below.
     

    Attached Files:

  2. Case3688

    Case3688 Private E-2

    I've included 2 more attachments with a little more info.

    The first is:

    hijacked_google.png - this is what Google looks like when it redirects. The only visible difference is the main logo, which looks like it doesn't have its CSS applied (it shows the whole sprite).

    GooredFix.txt - When searching about this problem I heard about GooredFix.exe. As you can see, I no longer have any extensions, etc.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. You have an MBR infection. I will give you a set of instructions in my next post.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Why are you using this machine without anti-virus installed? You are leaving yourself wide open to infections by surfing unprotected.

    We will ensure that you install some in a little while, first let's get started with malware removal....

    Are these something you know about?:

    • C:\Documents and Settings\chris.CHRISDESK\Desktop\new_site.html
    • C:\hitters.html
    • C:\pitchers.html


    Combofix is now back up and running, please download it and run it as per the instructions at the below link and make sure that when it asks you to install the Recovery Console that you indeed do!

    Windows XP Cleaning Procedure

    Attach the log it generates into your next reply here.

    Thanks
    Kes13!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds