Results 1 to 11 of 11

Thread: Possible google redirect proxy??

  1. #1
    Member
    Join Date
    Dec 2009
    Posts
    134
    Thanks
    12
    Thanked
    6 times in 6 posts
    • abs_rio's system
      • Motherboard:
      • Asus X99-A
      • CPU:
      • Intel Core i7 5820K @ 4.4ghz + Corsair H80
      • Memory:
      • 16GB Corsair DDR4 Vengeance LPX
      • Storage:
      • 250GB Samsung 850 EVO SSD + Western Digital 3TB HDD
      • Graphics card(s):
      • Gigabyte NVIDIA GeForce GTX 1070 XTREME GAMING
      • PSU:
      • EVGA SuperNOVA Gold 2 850W
      • Case:
      • Silverstone Fortress FT02-W
      • Operating System:
      • Windows 10 Pro 64 Bit
      • Monitor(s):
      • Dell U2711

    Possible google redirect proxy??

    I've suddenly noticed that my google searches are appearing in a different format (underlined). Bing search produces a grey screen with no searches appearing whatsoever. I've tried chrome and internet explorer with both giving the same result. I've ran malwarebytes and ESET scanner but it has made no difference. The other thing I've noticed is that windows is using some sort of proxy server. I've attached images below:

    http://postimg.org/image/fxx2hlvbn/
    http://postimg.org/image/ba3jcl5uz/
    http://postimg.org/image/z322lq3rh/

    I would greatly appreciate any advice? I'm using windows 8.1 pro. Thanks in advance.

  2. #2
    Senior Member Peter Parker's Avatar
    Join Date
    Jan 2008
    Location
    London
    Posts
    348
    Thanks
    98
    Thanked
    62 times in 47 posts
    • Peter Parker's system
      • Motherboard:
      • ASUS Z170 Pro Gaming
      • CPU:
      • i5-6600K
      • Memory:
      • 16GB DDR4
      • Storage:
      • Kingston 128GB SSD + 2x3TB
      • Graphics card(s):
      • GTX970
      • PSU:
      • SilverStone ST50EF
      • Case:
      • Silverstone Grandia GD01S-MXR
      • Operating System:
      • Fedora 33

    Re: Possible google redirect proxy??

    Assuming you've tried disabling the proxy and it keeps coming back?

    Thanks for reminding me why I run Linux. Sorry, that doesn't help you, but these might :-

    1) Regedit
    The registry key is given in this PUM.bad.proxy wiki page
    And here's a YT vid suggesting safe-mode before you run regedit. Win 7 in the vid, but it might be the same?

    2) Other tools
    http://www.malwareremovalguides.info...removal-guide/

  3. #3
    Senior Member
    Join Date
    Feb 2008
    Posts
    925
    Thanks
    4
    Thanked
    161 times in 148 posts
    • smargh's system
      • Motherboard:
      • Gigabyte GA-EP45-UD3P
      • CPU:
      • Xeon E5450 with 775-to-771 Mod
      • Memory:
      • 16GB Crucial
      • Storage:
      • Intel X25-M G2 80GB/Adaptec 3405 4x 2TB Ultrastar RAID1 / 1x 6TB Hitachi He6 / Dying 2TB Samsung
      • Graphics card(s):
      • GTX 750 Ti
      • PSU:
      • Seasonic X-560
      • Case:
      • Lian-Li PC-A71
      • Operating System:
      • Windows 7 Ultimate 64bit
      • Monitor(s):
      • BenQ G2400WD
      • Internet:
      • Really Crap ADSL2 <3Mbit

    Re: Possible google redirect proxy??

    There are many possible tools to use, but the first point of call is generally Autoruns: https://technet.microsoft.com/en-gb/.../bb963902.aspx - it has a feature to check file signature and also submit & query files automatically with Virustotal.

    Perhaps tcpview will tell you which process is actually listening on that proxy port: http://live.sysinternals.com/tcpview.exe

    If you have the ability to do so, it's often useful to remove the drive and scan it while plugged in to a second PC, using a couple of different trial AV applications.

  4. #4
    Not a good person scaryjim's Avatar
    Join Date
    Jan 2009
    Location
    Gateshead
    Posts
    15,196
    Thanks
    1,231
    Thanked
    2,291 times in 1,874 posts
    • scaryjim's system
      • Motherboard:
      • Dell Inspiron
      • CPU:
      • Core i5 8250U
      • Memory:
      • 2x 4GB DDR4 2666
      • Storage:
      • 128GB M.2 SSD + 1TB HDD
      • Graphics card(s):
      • Radeon R5 230
      • PSU:
      • Battery/Dell brick
      • Case:
      • Dell Inspiron 5570
      • Operating System:
      • Windows 10
      • Monitor(s):
      • 15" 1080p laptop panel

    Re: Possible google redirect proxy??

    OK, first thing I note is that you've got some horrendous Norton safe banner thing on your browser. My first step would be uninstalling that, tbh. Norton's a notorious resource hog and IMNSHO isn't far off being malware itself. I wouldn't be at all surprised if Norton had installed a proxy for doing websafe checking, and that could quite easily be messing with your browsing.

    Otherwise you need to track down what program is running that proxy server - might be worth looking the both the processes tab and the services tab of task manager to spot anything that looks likely.

  5. #5
    Member
    Join Date
    Dec 2009
    Posts
    134
    Thanks
    12
    Thanked
    6 times in 6 posts
    • abs_rio's system
      • Motherboard:
      • Asus X99-A
      • CPU:
      • Intel Core i7 5820K @ 4.4ghz + Corsair H80
      • Memory:
      • 16GB Corsair DDR4 Vengeance LPX
      • Storage:
      • 250GB Samsung 850 EVO SSD + Western Digital 3TB HDD
      • Graphics card(s):
      • Gigabyte NVIDIA GeForce GTX 1070 XTREME GAMING
      • PSU:
      • EVGA SuperNOVA Gold 2 850W
      • Case:
      • Silverstone Fortress FT02-W
      • Operating System:
      • Windows 10 Pro 64 Bit
      • Monitor(s):
      • Dell U2711

    Re: Possible google redirect proxy??

    Quote Originally Posted by smargh View Post
    There are many possible tools to use, but the first point of call is generally Autoruns: https://technet.microsoft.com/en-gb/.../bb963902.aspx - it has a feature to check file signature and also submit & query files automatically with Virustotal.

    Perhaps tcpview will tell you which process is actually listening on that proxy port: http://live.sysinternals.com/tcpview.exe

    If you have the ability to do so, it's often useful to remove the drive and scan it while plugged in to a second PC, using a couple of different trial AV applications.
    I'm using tcpview but not sure what to look for exactly ----> http://postimg.org/image/lfojtaa6h/

    I've tried the youtube method but that doesn't work. Also, tried disabling norton toolbar but again makes no difference.

  6. #6
    Senior Member Peter Parker's Avatar
    Join Date
    Jan 2008
    Location
    London
    Posts
    348
    Thanks
    98
    Thanked
    62 times in 47 posts
    • Peter Parker's system
      • Motherboard:
      • ASUS Z170 Pro Gaming
      • CPU:
      • i5-6600K
      • Memory:
      • 16GB DDR4
      • Storage:
      • Kingston 128GB SSD + 2x3TB
      • Graphics card(s):
      • GTX970
      • PSU:
      • SilverStone ST50EF
      • Case:
      • Silverstone Grandia GD01S-MXR
      • Operating System:
      • Fedora 33

    Re: Possible google redirect proxy??

    Quote Originally Posted by abs_rio View Post
    I'm using tcpview but not sure what to look for exactly ---->

    I've tried the youtube method but that doesn't work. Also, tried disabling norton toolbar but again makes no difference.
    But what exactly didn't work? Did the proxy setting keep coming back? Before leaving safe mode or after?

    Some more thoughts that might help :

    1. Backup your data and create a Windows restore point, if you haven't already ! When messing around with the registry it's possible to make your operating system unbootable. Or at least it used to be and I assume still is.
    2. That isupdate.exe process looks very dodgy to me:
      1. For example, Chrome is Process ID (PID) 4868. It connects out to a "remote" address of localhost:8080 which is the proxy.
      2. isupdate.exe is listening on 3XSCarbon:8080 - I assume 3XSCarbon is your PC name, and thus the same as localhost (sort of).
      3. The incoming connections to the proxy's local port (8080) have a "remote" port (still really on your machine though), e.g. 51769.
      4. The same isupdate.exe process then creates another local port on the next sequential number (51770), which finally connects out to the internet on an HTTP connection to some cloud IP.
      5. The sent/received bytes and packets seem to match up for these processes and ports.


    Google tells me isupdate.exe could be the Install Shield Updater, but ... I don't think it should be acting as a proxy for Chrome!

    For some reason process 0 (Windows "system idle" process?!) also looks like a proxy. That's odd too.

    Looks like there's a person with a similar problem - http://www.bleepingcomputer.com/foru...h-compromised/

    Sadly I'm not up to date on the best malware removers. I used to use Hijack This but it's been a while. Seems to be still updated though.

    Good luck!

  7. Received thanks from:

    abs_rio (18-02-2015)

  8. #7
    Not a good person scaryjim's Avatar
    Join Date
    Jan 2009
    Location
    Gateshead
    Posts
    15,196
    Thanks
    1,231
    Thanked
    2,291 times in 1,874 posts
    • scaryjim's system
      • Motherboard:
      • Dell Inspiron
      • CPU:
      • Core i5 8250U
      • Memory:
      • 2x 4GB DDR4 2666
      • Storage:
      • 128GB M.2 SSD + 1TB HDD
      • Graphics card(s):
      • Radeon R5 230
      • PSU:
      • Battery/Dell brick
      • Case:
      • Dell Inspiron 5570
      • Operating System:
      • Windows 10
      • Monitor(s):
      • 15" 1080p laptop panel

    Re: Possible google redirect proxy??

    Any idea what isupdate.exe is? AFAICT that's the one that's listening on port 8080, and it's also making lots of http/https requests suggesting it's handling all the browsing traffic (which would be right for a proxy server). That's your strongest suspect out of that list....

  9. #8
    Splash
    Guest

    Re: Possible google redirect proxy??

    KMS Server Service.exe also looks pretty suspect - this shouldn't be running on a client OS.

    So it seems you have something that is running at startup which is resetting your proxy settings - if you open MSConfig and select "diagnostic startup" then reboot do you still see the same issue? Also what do you have listed in the Startup tab in Task Manager, and if you open Task Scheduler do you see any odd tasks set to run at startup?

  10. #9
    Senior Member
    Join Date
    Dec 2013
    Location
    Cymru
    Posts
    309
    Thanks
    152
    Thanked
    47 times in 45 posts
    • satrow's system
      • Motherboard:
      • ASRock Z77E-ITX
      • CPU:
      • Ivy Xeon 1230 v2/Be Quiet Shadow Rock Topflow
      • Memory:
      • GSkill 2x8GB DDR3 2400Mhz
      • Storage:
      • 3x 256GB SSDs, 2x 1TB 2.5" HDDs.
      • Graphics card(s):
      • Asus blower GTX 1060 6GB
      • PSU:
      • Seasonic 360W Gold
      • Case:
      • BitFenix Prodigy/2x 120mm fans
      • Operating System:
      • W7x64 Pro
      • Monitor(s):
      • Dual (/triple) Dell U2412M 1900x1200
      • Internet:
      • TalkTalk FTTC ~14Mbps

    Re: Possible google redirect proxy??

    MBAM: http://www.bleepingcomputer.com/down...-anti-malware/
    AdwCleaner: http://www.bleepingcomputer.com/download/adwcleaner/
    Junkware Removal Tool: http://www.bleepingcomputer.com/down...-removal-tool/

    Save the logs, zip and attach them later!

    Reset all browsers to their defaults, from the BC topic earlier: http://www.bleepingcomputer.com/foru.../#entry3628560

  11. #10
    Member
    Join Date
    Dec 2009
    Posts
    134
    Thanks
    12
    Thanked
    6 times in 6 posts
    • abs_rio's system
      • Motherboard:
      • Asus X99-A
      • CPU:
      • Intel Core i7 5820K @ 4.4ghz + Corsair H80
      • Memory:
      • 16GB Corsair DDR4 Vengeance LPX
      • Storage:
      • 250GB Samsung 850 EVO SSD + Western Digital 3TB HDD
      • Graphics card(s):
      • Gigabyte NVIDIA GeForce GTX 1070 XTREME GAMING
      • PSU:
      • EVGA SuperNOVA Gold 2 850W
      • Case:
      • Silverstone Fortress FT02-W
      • Operating System:
      • Windows 10 Pro 64 Bit
      • Monitor(s):
      • Dell U2711

    Re: Possible google redirect proxy??

    Thanks for all the advice guys. I followed the steps in this post http://www.bleepingcomputer.com/foru...sed/?p=3630748

    Problem solved, at least for now! Still don't what caused the problem in the first place!

  12. #11
    root Member DanceswithUnix's Avatar
    Join Date
    Jan 2006
    Location
    In the middle of a core dump
    Posts
    12,986
    Thanks
    781
    Thanked
    1,588 times in 1,343 posts
    • DanceswithUnix's system
      • Motherboard:
      • Asus X470-PRO
      • CPU:
      • 5900X
      • Memory:
      • 32GB 3200MHz ECC
      • Storage:
      • 2TB Linux, 2TB Games (Win 10)
      • Graphics card(s):
      • Asus Strix RX Vega 56
      • PSU:
      • 650W Corsair TX
      • Case:
      • Antec 300
      • Operating System:
      • Fedora 39 + Win 10 Pro 64 (yuk)
      • Monitor(s):
      • Benq XL2730Z 1440p + Iiyama 27" 1440p
      • Internet:
      • Zen 900Mb/900Mb (CityFibre FttP)

    Re: Possible google redirect proxy??

    I saw this on my father in law's laptop not long ago. I spent a few minutes looking, and recommended a Windows re-install.

    I presume malware can arrange to survive if you restore to an earlier restore point.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •