Solved

spyware malware windows

Posted on 2011-09-26
3
552 Views
Last Modified: 2013-11-22
i dual boot my pc between win7 and ubuntu. on the windows side of things i notice google instant searches weren't working. and now i'm pretty sure i have some sort of malware, or spyware, despite the fact that my windows security essentials is running fine. i think i have something, because not only does google instant search not work, but search result always link to something else that is trying to sell me something. i also notice that the google instant search isn't working no matter which browser i try, ( IE8, chrome, firefox ). so i was going to look at my host file and ip settings, however, i would imagine that whatever is the problem is more complicated than just messing with the host file. also, i assume that since it doesn't matter what browser i use, this bit of malware must be in the windows system and not in internet explorer.
i mention the ubuntu thng because i thought i would use ubuntu to dig into the guts of wiindows to try and find this thing.
i know i could try malware bits, or combo fix, but i would like to try and dissect this to try and understand the mechanics of these things.
so any suggestions on how to start? up to this point i have mostly used combo fix or malware and i am not sure how to go about trying to de-constuct malware.
i don't care if i break windows.
0
Comment
Question by:JeffBeall
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 47

Accepted Solution

by:
rpggamergirl earned 250 total points
ID: 36598800
Try using TDSSKiller if searches are redirected. Then if the problem persists, followed with MalwareBytes and ComboFix and show us the CF log.

Download and run Kaspersky's TDSSKiller
http://support.kaspersky.com/viruses/solutions?qid=208280684


"Google Hijack" - Google Search Gets Redirected"      
http://www.experts-exchange.com/A_3299.html


0
 
LVL 34

Assisted Solution

by:Paul MacDonald
Paul MacDonald earned 250 total points
ID: 36598806
Take a look at the proxy settings in your browser(s) and see if they've been tampered with.  You can also try starting your browser(s) without addons/plugins to see if that helps.
0
 
LVL 1

Author Closing Comment

by:JeffBeall
ID: 36777959
ms security essential eventually found it. i wanted to try and poke around and learn about the mechanics of this, not use something like combofix or security essentials. oh well, maybe next time.
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recovering from what the press called "the largest-ever cyber-attack", IT departments worldwide are discussing ways to defend against this in the future. In this process, many people are looking for immediate actions while, instead, they need to tho…
This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

627 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question