Windows 10: Google redirection localhost.world

Discus and support Google redirection localhost.world in AntiVirus, Firewalls and System Security to solve the problem; Yep, and the same ini file. I deleted everything. Crazy how this went undetected Wow. What AV do you use? @moraleja39 is using ESET. Discussion in 'AntiVirus, Firewalls and System Security' started by flavien317, Oct 19, 2015.

  1. simrick Win User

    Google redirection localhost.world


    Wow. What AV do you use? @moraleja39 is using ESET.
     
    simrick, Dec 21, 2015
    #46

  2. No problem, I am glad I could help. If you need it I can write with greater detail what I did to remove it.
     
    moraleja39, Dec 21, 2015
    #47
  3. simrick Win User
    Yes please we need the detail. Thanks! *Thumbs
     
    simrick, Dec 21, 2015
    #48
  4. mixolyd Win User

    Google redirection localhost.world

    Windows Defender. I did a full scan with ESET and Comodo also. That's crazy nothing picked this up.

    That would be great. I deleted the task and ini file but not sure what registry changes to fix
     
    mixolyd, Dec 21, 2015
    #49
  5. simrick Win User
    I am thinking this needs to be reported to the AVs.
     
    simrick, Dec 21, 2015
    #50
  6. Here are all the things I had to wipe:

    • The scheduled task. Its name was "Adobe Acrobat Pro DC Update". You can open the task scheduler writing taskschd.msc on the start menu search bar and hitting enter.
    • A file named "settings.ini" located on %APPDATA%\Adobe Acrobat Pro DC". Full path could be "C:\Users\[username]\AppData\Roaming\Adobe Acrobat Pro DC\settings.ini".
    • In my case, two fake certificates. Open the certificate manager writing certmgr.msc on the start menu and hitting enter. The certificates are named "DO_NOT_TRUST_FiddlerRoot" and are under the folder "trusted root CAs" (or however it is in English)
    • Registry changes used to force proxy usage. In my case, I totally deleted the following values:
      • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
      • HKCU\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
      • HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnableAutoProxyResultCache
    • Just in case it is still enabled, disable the proxy. Go to control panel, internet settings, connections, LAN settings, and disable all checkboxes.

    I also will attach the removed INI and certificate files, just in case they could be of use to anybody reading this, as they are not dangerous per se.
     
    moraleja39, Dec 21, 2015
    #51
  7. Yeah, I think that too. Any idea on how to do that?
     
    moraleja39, Dec 21, 2015
    #52
  8. simrick Win User

    Google redirection localhost.world

    So, I am going through the thread, and noting everything that has been run by people infected with this:

    ESET
    Defender
    Malwarebytes Anti-rootkit
    Malwarebytes Antimalware
    TDSSKiller
    HitmanPro
    ZHPCleaner
    RogueKiller
    Comodo Rescue Disk
    Spybot
    ADWCleaner
    RKILL
    JRT
    Resetting all browsers/Flushing DNS

    Yes, I have info on how to report this to the AVs.
     
    simrick, Dec 21, 2015
    #53
  9. mixolyd Win User
    Looks like it did show up on Rkill but looked meaningless

    2015-12-09 11:30 - 2015-12-16 18:00 - 00000548 _____ C:\WINDOWS\Tasks\Adobe Acrobat Pro DC Update.job
    2015-12-09 11:30 - 2015-12-09 11:30 - 00003448 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Pro DC Update
    2015-12-09 11:30 - 2015-12-09 11:30 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Adobe Acrobat Pro DC
     
    mixolyd, Dec 21, 2015
    #54
  10. simrick Win User
    So RKILL temporarily stopped it, but everything goes back to status quo upon reboot. And because it's disguised as Acrobat update, it wasn't flagged by any of the AVs or other scanners.
     
    simrick, Dec 21, 2015
    #55
  11. simrick Win User
    @mixolyd Now that you are clean, I would recommend running CryptoPrevent on your system. This program was originally written to prevent encryption infections, but also includes protection for a whole host of other infections as well. It works by setting Group Policies, preventing malware from running executables from typical places such as the App Data folder. There's a free version, which you run once, set the protection, and then occasionally manually update.
     
    simrick, Dec 21, 2015
    #56
  12. simrick Win User
    Thank you very much for your efforts! *Thumbs
     
    simrick, Dec 21, 2015
    #57
  13. mixolyd Win User

    Google redirection localhost.world

    Will do. Thanks!
     
    mixolyd, Dec 21, 2015
    #58
  14. simrick Win User
    Here is the solution, found in post #49.
    Please perform the steps indicated and advise if that resolves things for you as well. If so, please mark the thread as solved, and modify your first post to show post #49 as the solution. Thanks.
     
    simrick, Dec 21, 2015
    #59
  15. simrick Win User
    Guys, here is the solution, found in post #49.
    Please perform the steps indicated and advise if that resolves things for you as well.

    Many thanks to @moraleja39 for the investigative work!
     
    simrick, Dec 21, 2015
    #60
Thema:

Google redirection localhost.world

Loading...
  1. Google redirection localhost.world - Similar Threads - Google redirection localhost

  2. localhost

    in Windows 10 Gaming
    localhost: In my internet statistics appear several localhost conections that i can not explain. How can i remove them? https://answers.microsoft.com/en-us/windows/forum/all/localhost/adfacb60-c768-448b-b482-217ff884723a
  3. localhost

    in Windows 10 Software and Apps
    localhost: In my internet statistics appear several localhost conections that i can not explain. How can i remove them? https://answers.microsoft.com/en-us/windows/forum/all/localhost/adfacb60-c768-448b-b482-217ff884723a
  4. Localhost not redirecting to internal application - Windows 10

    in Windows 10 Network and Sharing
    Localhost not redirecting to internal application - Windows 10: Hello, Recently we upgraded OS Windows 7 to Windows 10, and since then, accessing internal application with localhost account/contact search is behaving little weird. On trying to access the URL, it doesn’t work on first click, but works on 2nd click. Example 1 We use...
  5. localhost

    in Windows 10 Customization
    localhost: Hello I am using xampp to set up my own web server. My problem is I think, not being able to access port 80, which I think is related to iisrid. Anyway if any one knows what is happening here and has any suggestions would be appreciated[ATTACH]...
  6. Google Chrome redirects to Microsoft Search/mynewtabs.

    in Windows 10 Customization
    Google Chrome redirects to Microsoft Search/mynewtabs.: I had this problem on my Acer Spin 1 Windows 10 where, a few months ago, out of the blue, about 70% of the time when I clicked a website after searching something on Google Chrome, it would redirect me to msearches.com, bing.com or mynewtabs.com. I couldn't figure out how to...
  7. The device or resource (localhost) is not set up to accept connections on port "The World...

    in Windows 10 Network and Sharing
    The device or resource (localhost) is not set up to accept connections on port "The World...: Every time i try to access my localhost through any of the browsers it shows that the connection is refused. i tried changing the proxy settings and firewalls setting but all in vain. i tried every possible solutions available on internet to get access to it but of no help....
  8. localhost

    in Windows 10 Network and Sharing
    localhost: I am still not able to configure localhost in windows 10. I am web developer https://answers.microsoft.com/en-us/windows/forum/all/localhost/ab2ec8c7-6da0-4753-b640-691c4254c5ac
  9. SSD reliability in the real world: Google's experience

    in Windows 10 News
    SSD reliability in the real world: Google's experience: Using data from millions of drive days in Google datacenters, a new paper offers production lifecycle data on SSD reliability. Surprise! SSDs fail differently than disks - and in a dangerous way. Here's what you need to know. SSDs are a new phenomenon in the datacenter. We...
  10. Google Drive: "The page isn't redirecting properly "

    in Windows 10 Support
    Google Drive: "The page isn't redirecting properly ": Hello, I just did a clean install of Windows 10, everything is working great. Only one issue that I am having, whenever I try to download a file from Google Drive, it will never load. In Firefox it will send me to a page saying "The page isn't redirecting properly "...