Categorized | Antivirus, Commtouch

Search Engine Redirection Malware – How it works (and how to fix it)

Search engine redirection is usually one of the side effects of malicious software. This problem remains even after Trojans or fake antivirus are removed from the infected system.  No matter what site they search for, users experience a redirection of search results and web pages to affiliated websites.

In the infected system shown below, all the results from Google searches redirect to one of these domains:

  • “00ee.r.google.com”
  • “cbdd.r.google.com”
  • “cab7.r.google.com”
  • “99db.r.google.com”

Note that the redirection also affects other search engines such as Yahoo, Bing and others.

redirect-malware-Google-search-results-with-fake-URLs

Users who notice the Google link will probably assume that this is some form of legitimate Google redirect.  In addition most URL filtering solutions will allow access to any URL that is part of the Google domain.  The links lead to sites hosting malware or spam.

How does this work?

The remnants of the Trojan infections found in the computer are the following registry entries:

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\ <CLSID of the network card>
  • NameServer = 93.188.163.130,93.188.160.80
  • DhcpNameServer = 93.188.163.130,93.188.160.80

Effectively all domains are resolved into IP addresses by the rogue DNS server defined in the registry entries above.  The DNS server IP address above belongs to Promnet Ltd. in the Ukraine.  We recommend blocking DNS traffic to: 93.188.163.0 – 93.188.164.255 and 93.188.160.0 – 93.188.160.255.

The search redirection process happens like this:

  1. User does a search at Google.com
  2. The “rogue DNS” causes the search request to go to “bad server”
  3. “Bad server” does a real Google search on behalf of the original requesting PC
  4. “Bad server” sends back the real Google results page but switches the real URLs with fake destination URLs like 00ee.r.google.com
  5. User clicks on link and goes to 00ee.r.google.com (resolved by “rogue DNS”).  On this page there is malware or spam

The URLs listed above such as 00ee.r.google.com do not really exist and will not be resolved by genuine DNSs.

Querying the Google public DNS shows no result:

  • ;; QUESTION SECTION:
  • ;00ee.r.google.com.             IN      A
  • ;; Got answer:
  • ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 16615
  • ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0

But, querying the rogue DNS (93.188.163.130) does provide a result:

  • ;; QUESTION SECTION:
  • ;00ee.r.google.com.             IN      A
  • ;; Got answer:
  • ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 58738
  • ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
  • ;; ANSWER SECTION:
  • 00ee.r.google.com.      600     IN      A       67.210.15.54

In other words the rogue DNS entry results in:

  • “Damaged” search results with fake URLs
  • Resolution of those fake URLs to send users to sites with malware or spam

Restoring the DNS setting is the solution to the problem:

1.  Go to the “Network Connections” window

For Windows 7

  • Go to Start > Control Panel > Network and Internet > Network and Sharing Center.
  • In the left-hand column, click Change adapter settings.
  • A new screen will open with a list of network connections.

For Windows Vista

  • Go to Start > Control Panel > Network and Internet > Network and Sharing Center.
  • In the left-hand column, click Manage network connections.
  • A new screen will open with a list of network connections.

For Windows XP

  • Go to Start > Control Panel > Network Connections.

2.  Right-click Local Area Connection or Wireless Network Connection and select “Properties”.

3.  Select Internet Protocol (TCP/IP), and then click Properties.

4.  If you want to obtain DNS server addresses from a DHCP server, click “Obtain DNS server address

automatically”.

5. If you want to manually configure DNS server addresses, click “Use the following DNS server

addresses”, and then type the preferred DNS server and alternate DNS server IP addresses in the

Preferred DNS server” and “Alternate DNS server” boxes.

Related Posts

enaricles com redirect problem

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago