Author Topic: Redirect issues.  (Read 1069 times)

0 Members and 1 Guest are viewing this topic.

Offline techb

  • Soy Sauce Feeler
  • Global Moderator
  • King
  • *
  • Posts: 2350
  • Cookies: 345
  • Aliens do in fact wear hats.
    • View Profile
    • github
Redirect issues.
« on: September 26, 2012, 01:03:25 am »
I am trying to help a friend troubleshoot his searches. No matter the browser, google links redirect to other "unknown" sites. It is only Google that does this; Bing, Yahoo, Dogpile, etc does not redirect.


I have tried ComboFix, Malwarebytes, hard reset all browsers, Max Security scan (F-secure product), and all in safe-mode.


Any other suggestions? I was going to have him run a HighJackThis and look at the logs, but if you guys could throw something in there I haven't tried yet would be great.


Haven't done a system restore yet and suggested that today. Windows 7.
>>>import this
-----------------------------

Offline Daemon

  • VIP
  • Baron
  • *
  • Posts: 845
  • Cookies: 153
  • A wise man fears a gentle mans anger
    • View Profile
Re: Redirect issues.
« Reply #1 on: September 26, 2012, 02:26:10 am »
I had the same problem on xp awhile back...trying to remember exactly what I did to removie it...

When you ran mbam did you do it in safe mode? I want to say that's how I fixed mine, I put mbam install file on a usb as well as firefox install both downloaded on another ccomputer. Then I made sure to delete firefox and mbam from my computer, after that I booted in safe mode, reinstalled mbam and found the virus then installed firefox.
Mbam is malwarebytes btw.

Ill look into it some more tonight, dig up those memories for ya. If their still needed that is...

And come to think of it, I may not have reinstalled ff. That could've been.from a diff problem at a diff time...shite I need to buy a voice recorder >.<
This lifestyle is strictly DIY or GTFO - lucid

Because sexploits are for h0edays - noncetonic


Xires burns the souls of HF skids as a power supply

Offline techb

  • Soy Sauce Feeler
  • Global Moderator
  • King
  • *
  • Posts: 2350
  • Cookies: 345
  • Aliens do in fact wear hats.
    • View Profile
    • github
Re: Redirect issues.
« Reply #2 on: September 26, 2012, 04:32:06 am »
I had the same problem on xp awhile back...trying to remember exactly what I did to removie it...

When you ran mbam did you do it in safe mode? I want to say that's how I fixed mine, I put mbam install file on a usb as well as firefox install both downloaded on another ccomputer. Then I made sure to delete firefox and mbam from my computer, after that I booted in safe mode, reinstalled mbam and found the virus then installed firefox.
Mbam is malwarebytes btw.

Ill look into it some more tonight, dig up those memories for ya. If their still needed that is...

And come to think of it, I may not have reinstalled ff. That could've been.from a diff problem at a diff time...shite I need to buy a voice recorder >.<


All scans, etc where done in safe mode. I think the real problem is that I didn't do it myself, going off of what someone told me... I REALLY think a restore would fix the issue. As said before though, going off what your saying, un-installing firefox and re-installing it wont help because it is cross-browser. As in it effects more than fire fox.


Again, this is troubleshooting a friend. I have to go off of what he says. I tried to get him to join, but no luck as of yet. Just looking for input, and thank you Daemon, IDK why your not VIP yet.
>>>import this
-----------------------------

Offline Daemon

  • VIP
  • Baron
  • *
  • Posts: 845
  • Cookies: 153
  • A wise man fears a gentle mans anger
    • View Profile
Re: Redirect issues.
« Reply #3 on: September 26, 2012, 06:13:08 am »

All scans, etc where done in safe mode. I think the real problem is that I didn't do it myself, going off of what someone told me... I REALLY think a restore would fix the issue. As said before though, going off what your saying, un-installing firefox and re-installing it wont help because it is cross-browser. As in it effects more than fire fox.


Again, this is troubleshooting a friend. I have to go off of what he says. I tried to get him to join, but no luck as of yet. Just looking for input, and thank you Daemon, IDK why your not VIP yet.

Hmm...interesting...and yea realized the ff comments were off haha. I don't think a restore will help though, the restore always leaves certain things alone and it's always the ones you need changed lol. But might as well give it a shot i suppose. Im thinking it has to be a registry value somewhere...im on it techb!

And yea, me either :P

edit* ugh, some stuff came up and im not going to be able to look for it tonight. i hope you find it before tomorrow, but if not then when i have some free time ill keep looking.
 
« Last Edit: September 26, 2012, 08:24:14 am by Daemon »
This lifestyle is strictly DIY or GTFO - lucid

Because sexploits are for h0edays - noncetonic


Xires burns the souls of HF skids as a power supply

Offline p_2001

  • Royal Highness
  • ****
  • Posts: 684
  • Cookies: -64
    • View Profile
Re: Redirect issues.
« Reply #4 on: September 26, 2012, 06:17:25 am »
A restore is unlikely to fix it if it is a malware...
Most infect them too
"Always have a plan"

Offline ca0s

  • VIP
  • Sir
  • *
  • Posts: 432
  • Cookies: 53
    • View Profile
    • ka0labs #
Re: Redirect issues.
« Reply #5 on: September 26, 2012, 12:23:58 pm »
- Have you looked at the hosts file?
- Look at the browser's executable modules (.exe, .dll) last modify date.
- Look at the loaded modules and compare them with those loaded in a clean system.
- Look at the traffic. See if there's something extrange, some "unwanted" coneections.