Windows 10: Google redirection localhost.world

Discus and support Google redirection localhost.world in AntiVirus, Firewalls and System Security to solve the problem; Found mine under C:\Users\username\AppData\Roaming\ConvertXtoDVD\settings.ini Discussion in 'AntiVirus, Firewalls and System Security' started by flavien317, Oct 19, 2015.

  1. Maintown Win User

    Google redirection localhost.world


    Found mine under C:\Users\username\AppData\Roaming\ConvertXtoDVD\settings.ini
     
    Maintown, Dec 28, 2015
    #76
  2. simrick Win User

    Thanks for letting us know. Would you mind uploading the info in post #73, so we can try to find the source of this infection? Thanks.
     
    simrick, Dec 28, 2015
    #77
  3. sgauge Win User
    sgauge, Dec 28, 2015
    #78
  4. simrick Win User

    Google redirection localhost.world

    *Thumbs Thanks!
     
    simrick, Dec 29, 2015
    #79
  5. rolibark Win User
    I was infected too. But only by its "localhost.world" script part.
    Looking at the latter part of post #39 (by moraleja39), the one contributed by "mtmyoq.se" part of this Maleware, decoding its base64 encoded string:
    ==========
    ZnVuY3Rpb24gRmluZFByb3h5Rm9yVVJMKHVybCwgaG9zdCkgeyBpZiAoc2hFeHBNYXRjaChob3N0LCAid3d3Lmdvb2dsZS4qIikp IHJldHVybiAiUFJPWFkgMTI3LjAuMC4xOjgwODAiOyAgcmV0dXJuICJESVJFQ1QiO30
    ==========


    Leads to :
    ==========
    function FindProxyForURL(url, host) { if (shExpMatch(host, "www.google.*")) return "PROXY 127.0.0.1:8080"; return "DIRECT";}
    ==========

    Which seems (I presume - not an expert on "localhost" ports) that another flavor of this Maleware HiJacks any access to Google sites to a NOT used port (unless you have some server responding at port 8080 - alike your own WEB server running).

    So it seems that this Maleware has 2 parts: the "localhost.world" script, and the "mtmyoq.se" part.
    And that folks are infected by only 1 of them. Not by both at the same time.
    Strange.
     
    rolibark, Dec 31, 2015
    #80
  6. simrick Win User
    Hi rolibark and welcome to Tenforums.

    Thanks very much for posting this info. Every little bit helps! Would you mind uploading the info in
    post #73, so we can try to find the source of this infection? Thanks! *Smile
     
    simrick, Jan 1, 2016
    #81
  7. rolibark Win User
    Hi,
    As I said - I was infected only by its "localhost.world" script part (not by its "mtmyop.se" part)
    And I had the same cause for this Malware (the Adobe Updater) as "moraleja39" had.
    So (I guess) there's no need for my system info.
     
    rolibark, Jan 1, 2016
    #82
  8. FBtje Win User

    Google redirection localhost.world

    Thank you very much. Now I also know what caused this. An illegal infected copy of Adobe *Sad
     
    FBtje, Jan 4, 2016
    #83
  9. FBtje Win User
    In my case it was an infected copy of Adobe. But this infection can also be hidden in other infected (cracked, illegal) software. The following is the content of my settings.ini file in C:\Users\Username\AppData\Roaming\Adobe Acrobat Pro DC.

    This might help to track other .ini files. A Windows index search might not be sufficient, because the content is not indexed by default. Just search for all settings.ini files on your system disk and open them.

    Code: [/quote]
     
    FBtje, Jan 4, 2016
    #84
  10. simrick Win User
    Hi FBtje and welcome to Tenforums.
    Thanks very much for letting us know this information. Very glad this thread has helped you. *Thumbs
     
    simrick, Jan 4, 2016
    #85
  11. rolibark Win User
    Thanks a lot !
    But, suppose we search & find all "settings.ini" files, how do we recognize an infected one ?
     
    rolibark, Jan 5, 2016
    #86
  12. FBtje Win User
    by opening them in notepad en look if the content matches the settings.ini I posted above *Smile
    try to look in the C:\Users\Username first
     
    FBtje, Jan 5, 2016
    #87
  13. rolibark Win User

    Google redirection localhost.world

    Reading thru this thread it is my understanding that people had reported they got infected by various different flavors of "*.ini" files.
    So it may be the case that your signature (for identifying the "smelly" *.ini file is not the same as theirs.
     
    rolibark, Jan 5, 2016
    #88
  14. zsedan Win User
    Hi,

    I just got this host.world fellow too through downloading the latest microsoft toolkit.
    Defender reacted immediately, though other programs did not find anything, I normally use Defender, Malwarebytes Antimalware and Anti-exploit premium, CCleaner.
    I tried every other program mentioned in this topic, none of them found anything.
    My only symptom is the fake google site which is annoying as it is.
     
    zsedan, Jan 5, 2016
    #89
  15. FBtje Win User
    Try this and see comments below:

    • The scheduled task. Its name was "Adobe Acrobat Pro DC Update". You can open the task scheduler writingtaskschd.msc on the start menu search bar and hitting enter.
    • A file named "settings.ini" located on %APPDATA%\Adobe Acrobat Pro DC". Full path could be "C:\Users\[username]\AppData\Roaming\Adobe Acrobat Pro DC\settings.ini".
    • In my case, two fake certificates. Open the certificate manager writing certmgr.msc on the start menu and hitting enter. The certificates are named "DO_NOT_TRUST_FiddlerRoot" and are under the folder "trusted root CAs" (or however it is in English)
    • Registry changes used to force proxy usage. In my case, I totally deleted the following values:
      • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
      • HKCU\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
      • HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnableAutoProxyResultCache
    • Just in case it is still enabled, disable the proxy. Go to control panel, internet settings, connections, LAN settings, and disable all checkboxes.

    But in your case the scheduled task is: "Microsoft Toolkit Update". Delete this task
    And your *.ini file could be in C:\Users\[username]\AppData\Local\Microsoft Toolkit. Delete this folder completely
     
    FBtje, Jan 5, 2016
    #90
Thema:

Google redirection localhost.world

Loading...
  1. Google redirection localhost.world - Similar Threads - Google redirection localhost

  2. localhost

    in Windows 10 Gaming
    localhost: In my internet statistics appear several localhost conections that i can not explain. How can i remove them? https://answers.microsoft.com/en-us/windows/forum/all/localhost/adfacb60-c768-448b-b482-217ff884723a
  3. localhost

    in Windows 10 Software and Apps
    localhost: In my internet statistics appear several localhost conections that i can not explain. How can i remove them? https://answers.microsoft.com/en-us/windows/forum/all/localhost/adfacb60-c768-448b-b482-217ff884723a
  4. Localhost not redirecting to internal application - Windows 10

    in Windows 10 Network and Sharing
    Localhost not redirecting to internal application - Windows 10: Hello, Recently we upgraded OS Windows 7 to Windows 10, and since then, accessing internal application with localhost account/contact search is behaving little weird. On trying to access the URL, it doesn’t work on first click, but works on 2nd click. Example 1 We use...
  5. localhost

    in Windows 10 Customization
    localhost: Hello I am using xampp to set up my own web server. My problem is I think, not being able to access port 80, which I think is related to iisrid. Anyway if any one knows what is happening here and has any suggestions would be appreciated[ATTACH]...
  6. Google Chrome redirects to Microsoft Search/mynewtabs.

    in Windows 10 Customization
    Google Chrome redirects to Microsoft Search/mynewtabs.: I had this problem on my Acer Spin 1 Windows 10 where, a few months ago, out of the blue, about 70% of the time when I clicked a website after searching something on Google Chrome, it would redirect me to msearches.com, bing.com or mynewtabs.com. I couldn't figure out how to...
  7. The device or resource (localhost) is not set up to accept connections on port "The World...

    in Windows 10 Network and Sharing
    The device or resource (localhost) is not set up to accept connections on port "The World...: Every time i try to access my localhost through any of the browsers it shows that the connection is refused. i tried changing the proxy settings and firewalls setting but all in vain. i tried every possible solutions available on internet to get access to it but of no help....
  8. localhost

    in Windows 10 Network and Sharing
    localhost: I am still not able to configure localhost in windows 10. I am web developer https://answers.microsoft.com/en-us/windows/forum/all/localhost/ab2ec8c7-6da0-4753-b640-691c4254c5ac
  9. SSD reliability in the real world: Google's experience

    in Windows 10 News
    SSD reliability in the real world: Google's experience: Using data from millions of drive days in Google datacenters, a new paper offers production lifecycle data on SSD reliability. Surprise! SSDs fail differently than disks - and in a dangerous way. Here's what you need to know. SSDs are a new phenomenon in the datacenter. We...
  10. Google Drive: "The page isn't redirecting properly "

    in Windows 10 Support
    Google Drive: "The page isn't redirecting properly ": Hello, I just did a clean install of Windows 10, everything is working great. Only one issue that I am having, whenever I try to download a file from Google Drive, it will never load. In Firefox it will send me to a page saying "The page isn't redirecting properly "...