Windows 10: Google redirection localhost.world

Discus and support Google redirection localhost.world in AntiVirus, Firewalls and System Security to solve the problem; Nah... still not gotten rid of it... *Mad Malwarebytes Anti-Malware found some more unwated stuff; works for now*Redface Discussion in 'AntiVirus, Firewalls and System Security' started by flavien317, Oct 19, 2015.

  1. nakiel Win User

    Google redirection localhost.world


    Nah... still not gotten rid of it... *Mad

    Malwarebytes Anti-Malware found some more unwated stuff; works for now*Redface
     
    nakiel, Nov 4, 2015
    #16
  2. Borg 386 Win User

    You might want to check you host file to see if that's been altered or corrupted.

    Also, wouldn't hurt to flush your DNS.

    Flush DNS - What's My DNS?
     
    Borg 386, Nov 4, 2015
    #17
  3. pnrao1948 Win User
    After using almost all antivirus, spyware and malware removing programs and crashing one computer, I found out a work around.
    And that is to delete the infected account and start a new account.
     
    pnrao1948, Dec 7, 2015
    #18
  4. mixolyd Win User

    Google redirection localhost.world

    BTW; I also updated the firmware for my Asus-router...[/quote] Having same issue. Did it come back for you? It just came back for me, I saw in proxy settings that localworld was setup again. I ran ZHPCleaner and fixed everything a couple of days ago but it didn't stick.

    BTW the virus that caused this for me is Backdoor:MSIL/Bladabindi -- this is a pretty annoying virus. Windows Defender caught it immediately but I guess there are still traces left. I ran everything recommended in this thread (Rogue killer, TDS killer, Eset online scan, ZHP cleaner, MBAR)
     
    mixolyd, Dec 12, 2015
    #19
  5. nakiel Win User
    It came back! Currently been testing "HitmanPro" for a couple of days; no relapse yet...

    Found this in registry:
    Code: Windows Registry Editor Version 5.00 [HKEY_CURRENT_USER\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings] "AutoConfigURL"="http://localhost.world/localhost.host"[/quote]
     
    nakiel, Dec 13, 2015
    #20
  6. simrick Win User
    Might want to consider changing your passwords...

    MSILBladabindi
     
    simrick, Dec 13, 2015
    #21
  7. mixolyd Win User
    [/quote] Thanks! I scanned w/ HitmanPro and it found nothing. I did find that registry key though. I think that was the last trace of this virus (hopefully)

    Yeah I thought about that.. but Windows Defender found the virus as soon as I opened the file and immediately quarantined it, so I really don't think it had time to do anything except create this annoying proxy which just redirects google to this IP. I do not think (at least hopefully) the backdoor was active at any point. Thanks though
     
    mixolyd, Dec 13, 2015
    #22
  8. vgchat Win User

    Google redirection localhost.world

    Play around with windows firewall. You should easily be able to setup a new rule to block connections to the site/ip if it's still trying to redirect you.
     
    vgchat, Dec 13, 2015
    #23
  9. mixolyd Win User
    [/quote] After deleting that registry key, my proxy settings have stayed default. Today I saw a blank command prompt window open for a second and then Chrome was closed. I opened Chrome settings and saw this message: Chrome detected that some of your settings were corrupted by another program and reset them to their original defaults.

    Your system still running fine? I did run HitmanPro but it only found cookies on my system. What did it find on yours?
     
    mixolyd, Dec 14, 2015
    #24
  10. vgchat Win User
    vgchat, Dec 14, 2015
    #25
  11. Maintown Win User
    I am also having this EXACT problem. I have the same registry key listed above and cleared it just now (thanks, this is the only thing I have missed so far), otherwise I have run all the suggested fixes and tools to no avail. Glad I found this thread and that I am not the only one with the issue. I will update on the status of what happens with mine.
     
    Maintown, Dec 16, 2015
    #26
  12. mixolyd Win User
    I spent the better part of my afternoon the other day trying to get these rescue disks to work. They are a real pain in the butt. Could not get Kaspersky to run at all. I got Comodo to work finally using Yumi and did a full scan of my system, found nothing. I also ran a full scan with Spybot on monday and it found some minor stuff, probably unrelated. My only issue now is that sometimes Chrome will be closed when I come back to my computer. One time I witnessed it happening where a blank command line window opened and Chrome closed. I would love to delete the program that's causing that to happen
     
    mixolyd, Dec 16, 2015
    #27
  13. simrick Win User

    Google redirection localhost.world

    Please download and run ADWCleaner. There is a way to save the scan so you can post it here for me (can't remember the steps exactly, but you'll be able to figure it out easily) - do this BEFORE cleaning. ADWCleaner is a powerful program and sometimes it will flag things for deletion that you don't want deleted. So, I'd like to have a look at the scan results before you do any cleaning.

    EDIT: Click on the REPORT button after running the scan and post that logfile here in the thread (not as an attachment).
     
    simrick, Dec 17, 2015
    #28
  14. mixolyd Win User
    I ran ADWcleaner several days ago. It only found cookies, I think. Pretty sure I fixed everything it found. I found the logfile from that. Not sure what Report button you are talking about? Here is the log:

    # AdwCleaner v5.025 - Logfile created 13/12/2015 at 12:24:11
    # Updated 13/12/2015 by Xplode
    # Database : 2015-12-13.2 [Server]
    # Operating system : Windows 10 Pro (x64)
    # Username : Michael - MOTHERSHIP
    # Running from : D:\Michael\Downloads\adwcleaner_5.025.exe
    # Option : Cleaning
    # Support : Forum - ToolsLib


    ***** [ Services ] *****




    ***** [ Folders ] *****


    [-] Folder Deleted : C:\Program Files\Common Files\Speedbit
    [-] Folder Deleted : C:\ProgramData\Speedbit
    [-] Folder Deleted : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam
    [-] Folder Deleted : C:\Users\Michael\AppData\Roaming\Speedbit


    ***** [ Files ] *****


    [-] File Deleted : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pbjikboenpfhbbejgkoklgkhjpfogcam_0.localstorage
    [-] File Deleted : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pbjikboenpfhbbejgkoklgkhjpfogcam_0.localstorage-journal
    [-] File Deleted : C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pbjikboenpfhbbejgkoklgkhjpfogcam


    ***** [ DLLs ] *****




    ***** [ Shortcuts ] *****




    ***** [ Scheduled tasks ] *****




    ***** [ Registry ] *****


    [-] Key Deleted : HKCU\Software\Classes\CLSID\{AD4409E5-23C2-412B-849D-8FC0635B4073}
    [-] Key Deleted : HKCU\Software\Classes\CLSID\{AEE9D70C-6C9E-4B27-9F2C-8F14E95BEEF6}
    [-] Key Deleted : HKCU\Software\Classes\CLSID\{DD20920E-515A-4342-85E3-FC9A9FDA55C2}
    [-] Key Deleted : HKCU\Software\Classes\CLSID\{92FDEF05-B35E-4806-B87F-8B66AB649997}
    [-] Key Deleted : HKCU\Software\Classes\CLSID\{9F0BF664-B611-4C53-AEEA-FDBFCE6E3CA3}
    [-] Key Deleted : HKCU\Software\Classes\CLSID\{A8BD93E8-F6AE-4F02-828D-DE47FEC4D375}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0DC81A74-1FBD-4EF6-82B2-DE3FA05E8233}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1B26E4A2-7F09-4365-9AB8-13E6891E42CB}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{21402197-BB5B-476C-AA1D-3FFED8ED813A}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{42E8D680-A18B-4CAA-ACE0-18EA05E4A056}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{454A4044-16EC-4D64-9069-C5B8832B7B55}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4FEB1BAD-35AD-4A08-B6EC-E6D832F1ED4D}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8F2B3016-17D4-447A-B207-FFA8957A834A}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E66B63B0-49F8-47E3-A9BA-799287B59E87}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F8FA5B48-B7A2-4BC6-8389-9587643A4660}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}
    [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0DC81A74-1FBD-4EF6-82B2-DE3FA05E8233}
    [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1B26E4A2-7F09-4365-9AB8-13E6891E42CB}
    [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{21402197-BB5B-476C-AA1D-3FFED8ED813A}
    [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{42E8D680-A18B-4CAA-ACE0-18EA05E4A056}
    [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{454A4044-16EC-4D64-9069-C5B8832B7B55}
    [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4FEB1BAD-35AD-4A08-B6EC-E6D832F1ED4D}
    [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8F2B3016-17D4-447A-B207-FFA8957A834A}
    [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E66B63B0-49F8-47E3-A9BA-799287B59E87}
    [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F8FA5B48-B7A2-4BC6-8389-9587643A4660}
    [-] Key Deleted : HKCU\Software\SpeedBit
    [-] Key Deleted : HKCU\Software\Online video player


    ***** [ Web browsers ] *****


    [-] [C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : pbjikboenpfhbbejgkoklgkhjpfogcam
    [-] [C:\Users\nancy\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
    [-] [C:\Users\nancy\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com


    *************************


    :: "Tracing" keys removed
    :: Winsock settings cleared


    ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [4226 bytes] ##########
     
    mixolyd, Dec 17, 2015
    #29
  15. simrick Win User
    Okay, let's try this:


    Uninstall all Toolbars on the system. (all users)
    Uninstall all torrenting/P2P file sharing programs.
    Uninstall all downloader programs.
    Run RKILL - post the log. (RKILL will stop all malicious and suspect running items, reset hosts, etc. It is temporary. Anything that RKILL does is undone by a reboot.)
    Run ADWCleaner again and post the new log here.
    Run JRT
    Reset all browsers on the system...Reset Edge browser
    Flush DNS
    Set your network adapter(s) to Open DNS servers:
    IPv4 = 208.67.222.222 and 208.67.220.220
    IPv6 = 2620:0:ccc::2 and 2620:0:ccd::2
    Reboot the computer.
    Run RKILL again. Advise if anything is found on this run (check the log).
    Open Ccleaner to the TOOLS menu on the left and go to STARTUP ITEMS. Post a screenshot of the Google Chrome tab and the Scheduled Tasks tab.


    Google redirection localhost.world [​IMG]
     
    simrick, Dec 17, 2015
    #30
Thema:

Google redirection localhost.world

Loading...
  1. Google redirection localhost.world - Similar Threads - Google redirection localhost

  2. localhost

    in Windows 10 Gaming
    localhost: In my internet statistics appear several localhost conections that i can not explain. How can i remove them? https://answers.microsoft.com/en-us/windows/forum/all/localhost/adfacb60-c768-448b-b482-217ff884723a
  3. localhost

    in Windows 10 Software and Apps
    localhost: In my internet statistics appear several localhost conections that i can not explain. How can i remove them? https://answers.microsoft.com/en-us/windows/forum/all/localhost/adfacb60-c768-448b-b482-217ff884723a
  4. Localhost not redirecting to internal application - Windows 10

    in Windows 10 Network and Sharing
    Localhost not redirecting to internal application - Windows 10: Hello, Recently we upgraded OS Windows 7 to Windows 10, and since then, accessing internal application with localhost account/contact search is behaving little weird. On trying to access the URL, it doesn’t work on first click, but works on 2nd click. Example 1 We use...
  5. localhost

    in Windows 10 Customization
    localhost: Hello I am using xampp to set up my own web server. My problem is I think, not being able to access port 80, which I think is related to iisrid. Anyway if any one knows what is happening here and has any suggestions would be appreciated[ATTACH]...
  6. Google Chrome redirects to Microsoft Search/mynewtabs.

    in Windows 10 Customization
    Google Chrome redirects to Microsoft Search/mynewtabs.: I had this problem on my Acer Spin 1 Windows 10 where, a few months ago, out of the blue, about 70% of the time when I clicked a website after searching something on Google Chrome, it would redirect me to msearches.com, bing.com or mynewtabs.com. I couldn't figure out how to...
  7. The device or resource (localhost) is not set up to accept connections on port "The World...

    in Windows 10 Network and Sharing
    The device or resource (localhost) is not set up to accept connections on port "The World...: Every time i try to access my localhost through any of the browsers it shows that the connection is refused. i tried changing the proxy settings and firewalls setting but all in vain. i tried every possible solutions available on internet to get access to it but of no help....
  8. localhost

    in Windows 10 Network and Sharing
    localhost: I am still not able to configure localhost in windows 10. I am web developer https://answers.microsoft.com/en-us/windows/forum/all/localhost/ab2ec8c7-6da0-4753-b640-691c4254c5ac
  9. SSD reliability in the real world: Google's experience

    in Windows 10 News
    SSD reliability in the real world: Google's experience: Using data from millions of drive days in Google datacenters, a new paper offers production lifecycle data on SSD reliability. Surprise! SSDs fail differently than disks - and in a dangerous way. Here's what you need to know. SSDs are a new phenomenon in the datacenter. We...
  10. Google Drive: "The page isn't redirecting properly "

    in Windows 10 Support
    Google Drive: "The page isn't redirecting properly ": Hello, I just did a clean install of Windows 10, everything is working great. Only one issue that I am having, whenever I try to download a file from Google Drive, it will never load. In Firefox it will send me to a page saying "The page isn't redirecting properly "...