Windows 10: Google redirection localhost.world

Discus and support Google redirection localhost.world in AntiVirus, Firewalls and System Security to solve the problem; I wonder if this is related or not... Discussion in 'AntiVirus, Firewalls and System Security' started by flavien317, Oct 19, 2015.

  1. eLPuSHeR Win User

    Google redirection localhost.world


    I wonder if this is related or not...
     
    eLPuSHeR, Dec 21, 2015
    #61
  2. simrick Win User

    I don't think so, as TDSSKiller was run and did nothing on one infected system.
     
    simrick, Dec 21, 2015
    #62
  3. Grinler Win User
    Hey all,

    Just saw this post on BC and skimmed through the topic here.

    Anyone know if this is a common denominator in terms of programs installed? Will see if I can track down a sample and then figure out how this works.
     
    Grinler, Dec 21, 2015
    #63
  4. Grinler Win User

    Google redirection localhost.world

    More I read through the topic, this feel more like an adware.

    Anyone have any of folders/files associated with this? Preferably, the folder located at C:\Users\[me]\AppData\Roaming\Adobe Acrobat Pro DC. If you can grab that folder, zip it up and submit it here please:

    Submit a Malware Sample
     
    Grinler, Dec 21, 2015
    #64
  5. simrick Win User
    @mixolyd and @moraleja39
    Can either of you answer @Grinler 's posts above?

    EDIT: I grabbed the zip file from moraleja39 's post earlier and submitted it.
     
    simrick, Dec 21, 2015
    #65
  6. Grinler Win User
    Grinler, Dec 21, 2015
    #66
  7. simrick Win User
    simrick, Dec 21, 2015
    #67
  8. Grinler Win User

    Google redirection localhost.world

    I missed the javascript. Very clever way of obfuscating it.

    Will keep looking for a sample.
     
    Grinler, Dec 21, 2015
    #68
  9. The folder contained only the .ini file.

    I also thought that it could be adware. However, proxying the entire Google domain also affects things like the Google Store or Google Play, so they could get access to very sensitive data like credit cards, not to mention all the personal things an Android user like me has stored on his Google account...

    As to the sample, I am afraid I can't help you. I literally reinstalled Windows from scratch because of this and kept happening on the clean install. I have not installed Adobe Acrobat DC, just the regular Acrobat Reader. Windows and Office and so are legit, any cracks used. So I really have no idea where did this come from. But it has not returned, so at least it looks like there is not any binary infected file running in the background.
     
    moraleja39, Dec 22, 2015
    #69
  10. essenbe Win User
  11. Hi guys, just signed up to respond. I got hit with this a few weeks back, I quickly spotted the certs and the proxy change and removed them but it has since happened again so I started googling and found this post. Very helpful.

    However my version was a little different, the scheduled task is named "Microsoft Toolkit Update" and the ini file looks to have changed again but the actions are the same. It was schedules for Mondays, Wednesday and Saturdays of every week. And created these reg keys:

    HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoConfigURL
    HKEY_CURRENT_USER\\Software\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoConfigUR
    HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnableAutoProxyResultCache


    Thanks to the OP for the detailed info.
     
    ericbanner, Dec 23, 2015
    #71
  12. simrick Win User
    Hi Eric and welcome to Tenforums!
    Thanks for posting - everything we can get on this will help. @Grinler (Lawrence Abrams) over at Bleeping Computer is looking for the payload executable, which we have not yet been able to identify. I wonder if you wouldn't mind posting here in this thread, the BSOD requirements we have laid out for people with BSOD issues? One of our BSOD experts ( @essenbe ) has a post above with the links. He would like to have a look at the information, to see if he can identify anything related to this redirect. We'd like to get this permanently resolved and notify the AVs, etc., but we need to identify the payload first.

    If you can help, that would be great. Thanks.
     
    simrick, Dec 23, 2015
    #72
  13. sgauge Win User

    Google redirection localhost.world

    Hi guys, I also registered to tell that I finally found the source of my infection, in an AnyDVD update scheduled task :

    This was triggered 3 times a week at 18:00
    Code: C:\WINDOWS\system32\wscript.exe //nologo //B //E:jscript "C:\Users\(me)\AppData\Roaming\AnyDVD HD\settings.ini"[/quote] The malicious code is hidden in the ini file, as described in page 4.

    Kudos to people that hinted to check scheduled tasks, this thing was driving me crazy !

    PC-SÉBASTIEN-29_12_2015__83417,50.zip
     
    sgauge, Dec 27, 2015
    #73
  14. simrick Win User
    The malicious code is hidden in the ini file, as described in page 4.

    Kudos to people that hinted to check scheduled tasks, this thing was driving me crazy ![/quote] Hi sgauge and welcome to Tenforums.
    Thanks for posting your information - every little bit helps.
    I wonder if you might help us further detect how this is happening, so we can get some tangible information to send out to Bleeping Computer and the AVs? If you would, please run the BSOD posting instructions found in this thread; even though this infection is not causing BSODs, we may be able to figure out the infection method of this thing, to block it in the future. Thanks.
     
    simrick, Dec 27, 2015
    #74
  15. essenbe Win User
Thema:

Google redirection localhost.world

Loading...
  1. Google redirection localhost.world - Similar Threads - Google redirection localhost

  2. localhost

    in Windows 10 Gaming
    localhost: In my internet statistics appear several localhost conections that i can not explain. How can i remove them? https://answers.microsoft.com/en-us/windows/forum/all/localhost/adfacb60-c768-448b-b482-217ff884723a
  3. localhost

    in Windows 10 Software and Apps
    localhost: In my internet statistics appear several localhost conections that i can not explain. How can i remove them? https://answers.microsoft.com/en-us/windows/forum/all/localhost/adfacb60-c768-448b-b482-217ff884723a
  4. Localhost not redirecting to internal application - Windows 10

    in Windows 10 Network and Sharing
    Localhost not redirecting to internal application - Windows 10: Hello, Recently we upgraded OS Windows 7 to Windows 10, and since then, accessing internal application with localhost account/contact search is behaving little weird. On trying to access the URL, it doesn’t work on first click, but works on 2nd click. Example 1 We use...
  5. localhost

    in Windows 10 Customization
    localhost: Hello I am using xampp to set up my own web server. My problem is I think, not being able to access port 80, which I think is related to iisrid. Anyway if any one knows what is happening here and has any suggestions would be appreciated[ATTACH]...
  6. Google Chrome redirects to Microsoft Search/mynewtabs.

    in Windows 10 Customization
    Google Chrome redirects to Microsoft Search/mynewtabs.: I had this problem on my Acer Spin 1 Windows 10 where, a few months ago, out of the blue, about 70% of the time when I clicked a website after searching something on Google Chrome, it would redirect me to msearches.com, bing.com or mynewtabs.com. I couldn't figure out how to...
  7. The device or resource (localhost) is not set up to accept connections on port "The World...

    in Windows 10 Network and Sharing
    The device or resource (localhost) is not set up to accept connections on port "The World...: Every time i try to access my localhost through any of the browsers it shows that the connection is refused. i tried changing the proxy settings and firewalls setting but all in vain. i tried every possible solutions available on internet to get access to it but of no help....
  8. localhost

    in Windows 10 Network and Sharing
    localhost: I am still not able to configure localhost in windows 10. I am web developer https://answers.microsoft.com/en-us/windows/forum/all/localhost/ab2ec8c7-6da0-4753-b640-691c4254c5ac
  9. SSD reliability in the real world: Google's experience

    in Windows 10 News
    SSD reliability in the real world: Google's experience: Using data from millions of drive days in Google datacenters, a new paper offers production lifecycle data on SSD reliability. Surprise! SSDs fail differently than disks - and in a dangerous way. Here's what you need to know. SSDs are a new phenomenon in the datacenter. We...
  10. Google Drive: "The page isn't redirecting properly "

    in Windows 10 Support
    Google Drive: "The page isn't redirecting properly ": Hello, I just did a clean install of Windows 10, everything is working great. Only one issue that I am having, whenever I try to download a file from Google Drive, it will never load. In Firefox it will send me to a page saying "The page isn't redirecting properly "...