My Google Has Gone Rogue!

Discussion in 'Malware Help (A Specialist Will Reply)' started by techtitan, Jan 10, 2016.

  1. techtitan

    techtitan Specialist

    Earlier this week during a routine Google search, I noticed something extremely strange. When trying to find out a good port to make outgoing calls with Skype, I found my results returned from Google were completely erratic. The first several at the top of the page we're almost as if the system had returned some kind of hi-jacked adware page. However, if you scrolled down just a bit, it would pick up the normal search results. I did some tests and found this happens in the BOTH Internet Explore and Google Chrome, but not in Firefox (also using other search quarries besides the one relating to Skype).

    I know this may be hard to follow from the description above, so allow me to illustrate things.

    When typing the phrase "best port for Skype" into the Google search bar using Firefox, it gives me a normal results page like so:

    http://i288.photobucket.com/albums/ll185/mrbucket_bls/google_firefox_zpswejipj8o.jpg

    Now, if I were to type that exact phrase into the same Google search via either Internet Explorer or Google Chrome, I get the following results instead:

    http://i288.photobucket.com/albums/ll185/mrbucket_bls/google_ie-chrome_zpsp3muuwmx.jpg

    Also, I should note Google itself is not functioning properly. Any time I click on the "Search Tools" to try and add date filters to narrow my search, it does not load the tool drop-down. It just reloads back to the main Google homepage (as if I hit back on the browser). Again, this happens in all cases except via Firefox.

    Finlay, the last anomaly is that the colorful "Gooooogle" icons at the bottom where the page numbers are seem to be missing. This definitely seems strange, as you can you can see here:

    http://i288.photobucket.com/albums/ll185/mrbucket_bls/google_ie-chrome2_zpsmsgcjbti.jpg

    You should also know I doublet this is due to some malware or other harmful virus I picked up via careless internet browsing. I do regular scans with Spybot/MarlwareBytes/SuperSpyware and the 2015 version of AVG total security. Most importantly, I have a lifetime license to Sandboxie and force 100% of my internet usage into a sandbox (which is automatically felted upon close). I tried running these tests out the sandbox with it and all tracking protection lists (like fanboy) disabled), but to no avail. Finlay, I run NOTHING unless I'm sure it's safe and can be verified. So to say I'm a cautious user would be an understatement.

    Needless to say I'm stumped. This is a recent development in the last two-three weeks. I have been doing some system maintenance and updating recently, so I'm not sure if a wire has gotten crossed somewhere. However, the fact that it affects only two of my three browsers does seem like a strange mystery.

    But if there is anyone I know can solve said mystery, it's the Geeks! Any help is much appreciated.
     
  2. Anon-9aee479f8f

    Anon-9aee479f8f Anonymized

  3. techtitan

    techtitan Specialist

    Yes, I actually just completed all the necessary steps in both guides today and have attached my logs for review. Most of the scans came back negative (meaning nothing malicious was found), which is why I didn't think this was a malware issue initially since I run all these scans/sandbox day-to-day. Otherwise I would have started in that forum. However, do you think I should have this moved to that area and follow up there or can we move forward as-is? I'm willing to do whatever's necessary to get to the bottom and resolve it.

    Here's my logs. Thanks for the help/input! ;)

    UPDATE:

    Looks like I'll have to upload the logs in two parts do to the five-max attachment restriction. Here is log upload part 1:
     

    Attached Files:

  4. techtitan

    techtitan Specialist

    And log upload part 2...
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may have unknowingly installed some addons into IE and Chrome that need to be disabled/removed. Some time you can resolved this by backing up you favorites/bookmarks and then just reset the browsers to defaults. Other times with Chrome, a complete uninstall ( which means uninstall, delete all related files, folders, shortcuts, and possible registry keys ) followed by a reboot a reinstall can be necessary.

    Try the below as a start:

    Reset Chrome to Defaults

    Reset Internet Explorer 9, 10, and 11 to Defaults
     
  6. techtitan

    techtitan Specialist

    First off, thank you very much for following up with my issue. The help is much appreciated.

    Second, I had considered that when trying to trouble shoot this issue myself. However, I did run a test using the "Internet Explorer (No Add-Ons)" shortcut under System Tools, but it returned the same results without change. That's why I gave up on that idea originally. I'm willing to go back and try again, but is there a reason why using this shortcut would not have eliminated the issue (if it is add-on based)?

    Thanks!
     
  7. techtitan

    techtitan Specialist

    Also, it's probably worth noting that the only extension I'm currently running in Chrome was Google Docs and it returns these results as well.
     
  8. techtitan

    techtitan Specialist

    UPDATE:

    OK, I can confirm that after resetting IE it appears to have resolved the issue. Looks like my search results are back to normal. However, I'm still left with two questions that puzzle me (which I'd appreciate your input on):
    1. Why didn't this work when I used the "Internet Explorer (No Add-Ons)" shortcut found in the System Tools menu? Seems like it should have disabled whatever was causing the problem, but it didn't. What is the shortcut even used for if not this?
    2. When I reset things in IE, my Google Chrome also started working normal without me touching it. How is that possible? Why would clearing something in IE affect a completely unrelated browser?
    Thanks!
     
  9. techtitan

    techtitan Specialist

    Just as a follow up, I tried Googling answers to this mystery on my own but I'm having trouble finding anyone with quite the exact situation. Are there any thoughts on that add-on issue and correlation between the two browsers? I know staffers can only look at these so quickly, so I'm willing to wait my turn for answers of course.

    Also, could I get confirmation on my logs above (that there's nothing more I need to do on the malware front)? I'm stuck in the step of the "Malware Removal Guide" that tells me to wait for instructions from the forum so I can then go back and undo some things and finish up (like resetting my UAC Controls back to default and turning my emulator drivers back on). Don't want to jump the gun here if there is anything else I should do.

    Thanks!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Chrome use various network settings from IE. See this: https://support.google.com/chrome/answer/96815?hl=en

    Your logs showed no malware issues. Your issues were purely due to changes made within your browsers.

    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  11. techtitan

    techtitan Specialist

    UPDATE:

    Unfortunately I may have spoken too soon. Even after the reset (that cleared out all my accelerators, disabled all my addons and reset everything else), the weird search results are still popping up. Only now, it only happens occasionally. Sometimes things will load normally, others I get the weird results and the broken search page buttons. Needless to say, this is perplexing. Could it perhaps be due to some other installed internet related issue? I tried removing the late version of Speckie I just installed about a month ago, but that has not changed anything. There must be a root cause I can track down somewhere. I would truly appreciate any help getting to the bottom of this (now that we've established it's not a malware issue and I've followed all those steps to completion).

    Also, speaking of the "Malware Removal Guide," I now have a new issue as a result (in addition to the previous one). When I ran the guide and reset things, it completely FUBARed my IE11. As you can see in the images I've attached, pages are no longer loading correctly. Please see the attached images for reference:

    IE11_probs.jpg IE11_probs2.jpg

    I'm at a loss and am in major need of assistance on both these fronts. I await your tutelage.
     
  12. techtitan

    techtitan Specialist


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds