PDA

View Full Version : Google/Firefox re-direct - B00kmark


LChoy
04-22-2011, 12:14 PM
Hey CP

Was looking for some malware help. The Fiancée's computer has this annoying google/firefox redirect. Every search request on google goes to the B00kmark search site (hxxp://search.us.b00kmarks.com).
Normally, I would just run rkill and use Malwaerbytes in safe mode and it clears everything up. However, Malwarebytes haven't been able to find anything wrong. Google searches (using my clean computer) hasn't been able to dig up anything useful unless you count a half a dozen suspicious sites with fixes to download to solve the problem. I don't trust those sites, especially since all of have the same date stamp (Feb 21, 2011).
Wondering if anyone from CP have dealt with this particular malware

Thanks

OilKiller
04-22-2011, 12:53 PM
Try a Hitman Pro scan and see if it finds anything: http://www.surfright.nl/en

SuperAntiSpyware as well if that doesn't: http://www.superantispyware.com/superantispyware.html

Last but not least, Norton Power Eraser: http://us.norton.com/support/DIY/index.jsp

Crazy Bacon Legs
04-22-2011, 01:01 PM
There are a few similar topics on the Bleeping Computer forums. It appears you're not the only one with the problem, and you may want to either follow some of the advice there.

This thread seems to involve someone actually solving and removing the infection:

http://www.bleepingcomputer.com/forums/topic391685.html

I'm not sure if this will help, but some of the scanners and tools referred to in that thread may help you out.

LChoy
04-23-2011, 10:25 PM
Thanks guys
it's getting more frustrating with it. It made all her program files "hidden" so it looks like everything has disappeared.

Hack&Lube
04-23-2011, 10:31 PM
Dr. Web CureIt! has never failed me. Fixes host file too.

https://www.freedrweb.com/download+cureit+free/?lng=en

ken0042
04-23-2011, 10:38 PM
Once you fix the computer- you will also need to fix your computer's host file. I'm on my iPhone now so can't tell you where it is; but basically it is telling all google requests to go to a different IP address.

Edit- looks like it can be found in XP at C:\WINDOWS\system32\drivers\etc (Open with Notepad)
Mine has a bunch of REM statements (start with #) then the only line is:
127.0.0.1 localhost