Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
   
 
Reply to this topicStart new topic
How To Remove clickfraudmanager, adwarefeed, zfsearch Firefox Redirect, Using GooredFix
jpshortstuff
post Apr 14 2009, 04:10 AM
Post #1


Visiting Staff
Group Icon
Posts: 84
From: UK
OS: XP



This guide pertains to the removal of search engine redirects through domains like clickfraudmanager, v1.adwarefeed.com, ad4.doubleclick.net, google.goored, goougly.com, zfsearch.com and others.

Also known as the "goored" infection, this is a Firefox hijacker that targets a variety of search engines:
Google, Yahoo, Msn, AOL and Ask.

Usually, the first sign of infection is that upon starting Firefox, you receive a notification that "1 new Add-on has been installed", although you did not knowingly install anything. When using any of the above search engines, you may notice that during the search you see names like zfsearch.com, v1.adwarefeed.com flash past in your status bar, as depicted here with a Google search:


Search results appear normal, and hovering over the links shows the legitimate sites. However, after clicking the links, you are directed to other sites. Again, if you check the status bar, you will see the fake domain names that are directing you to these sites.




These domain names are different for each search engine, and some of the common ones are these:
Google - goougly.com, clickfraudmanager, v1.adwarefeed.com
Yahoo - a.l.yimg
MSN - msnooze.com
Ask - wzeu.ask.com

The following removal guide should be followed if and only if you are experiencing these symptoms. It is highly recommended that you post to our Malware Removal and Spyware Removal after following this guide so that we can make sure this and any other infections have been removed.

There are many other infections that cause redirects as well, so if GooredFix doesn't solve your problem please post to our Malware Removal forum for assistance.

Please read Malware how-to guides information before following any of our guides.

This is a self-help guide. Use at your own risk.

================

Step 1:

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear.


Step 2:

We recommend that you now post a HijackThis log to our Malware Removal Forum to complete the cleaning process.
>> Malware and Spyware Cleaning Guide (to be completed before posting a log) <<

Please include the results of the GooredFix log as well, so that we can see what had been removed. The log can also be found on your Desktop, entitled GooredLog.txt.

Please post any questions or comments about this guide as a reply to this topic. Any further Malware problems should be posted in the Malware Removal and Spyware Removal forum.
Go to the top of the page
 
+Quote Post
jpshortstuff
post Aug 13 2009, 05:14 AM
Post #2


Visiting Staff
Group Icon
Posts: 84
From: UK
OS: XP



Updated guide to use latest version of GooredFix.
Go to the top of the page
 
+Quote Post
p12op4n3
post Sep 6 2009, 05:25 PM
Post #3


Member
**
Posts: 29
OS: LaptopVista.MnPcXP



Hi, i was wondering if this type of virus has anything to do with identity theft/bank details, as i do a fair bit of internet shopping, although i have not yet come across this type of virus yet thankfully.
Also on the topic as a generalisation where and how do viruses start? Is it anything to do with the antivirus companies- creating a need for their product?
thanx
Go to the top of the page
 
+Quote Post
Octagonal
post Sep 6 2009, 10:17 PM
Post #4


Malware Moderator / Malware Staff
Group Icon
Posts: 2,436
From: The Land Down Under
OS: Windows XP pro



QUOTE (p12op4n3 @ Sep 7 2009, 09:25 AM) *
Hi, i was wondering if this type of virus has anything to do with identity theft/bank details, as i do a fair bit of internet shopping, although i have not yet come across this type of virus yet thankfully.

The infection mainly redirects you to specific sites in an attempt for you to view whatever advertising is shown there. Also, those sites that you are redirected to can have other malware associated with them.

QUOTE (p12op4n3 @ Sep 7 2009, 09:25 AM) *
Also on the topic as a generalisation where and how do viruses start? Is it anything to do with the antivirus companies- creating a need for their product?

Most infections today are about stealing your identity, banking details or goading you into purchasing rogue products with the intent of removing malware. I highly doubt that any legitimate anti-virus company would be actively pursuing the path of creating infections. The work we do here and at other malware removal sites often assists anti-virus companies in providing consumer protection that is needed today and in the future.
Go to the top of the page
 
+Quote Post
p12op4n3
post Sep 7 2009, 10:52 AM
Post #5


Member
**
Posts: 29
OS: LaptopVista.MnPcXP



Sorry, i did not mean that in an offensive way.
My train of thought was to question the purpose of creating a virus or if they can be created in another means. I was not implying that anyone here had ill intentions. Purposes often revolve around money so it was just a speculation on whether an antivirus company might want to do a thing like that and asking if you/others thought there was any logic/truth in that. Im sorry if i caused offence as i only meant it as a question.
Go to the top of the page
 
+Quote Post
Octagonal
post Sep 8 2009, 12:58 AM
Post #6


Malware Moderator / Malware Staff
Group Icon
Posts: 2,436
From: The Land Down Under
OS: Windows XP pro



No offence taken. smile.gif

I just wanted to point out that infections these days are mainly around gaining access to personal information etc in an effort to take advantage of a person's financial status. It would be a legitimate anti-virus company's downfall if ever such an infection was traced back to them as being the creator of such code. The topic of anti-virus companies doing that type of thing has been around for years and I highly doubt that there is any truth in it.
Go to the top of the page
 
+Quote Post
p12op4n3
post Sep 8 2009, 10:32 AM
Post #7


Member
**
Posts: 29
OS: LaptopVista.MnPcXP



smile.gif thanx
Lol I hadnt thought of the tracing possibilty. How would you go about doing that? Iv heard its to do with your IP? can anyone trace the route of an item (virus,text,video,image etc) with a little know how?
I only asked because like you say the topic comes up, unless you know a bit about things it can seem feesable.
Thanx
Go to the top of the page
 
+Quote Post
Octagonal
post Sep 8 2009, 08:48 PM
Post #8


Malware Moderator / Malware Staff
Group Icon
Posts: 2,436
From: The Land Down Under
OS: Windows XP pro



This is not the topic that this issue should be discussed, so I won't take this any further than to add that you may be surprised what and how things can be traced. Maybe you would like to start a topic in this forum for some serious discussion between members about tracing abilities and computer forensics.
Go to the top of the page
 
+Quote Post
phammo
post Sep 23 2009, 11:44 AM
Post #9


New Member
*
Posts: 2
OS: xp



Hi,

I ran Gooredfix and then flushed my DNS.

Seems to have fixed the problem. Thanks yes.gif

Does my log confirm the presence of goored?

Cheers

P



GooredFix by jpshortstuff (12.07.09)
Log created at 18:30 on 23/09/2009 (xxxxxxxx)
Firefox version 3.0.14 (en-GB)

========== GooredScan ==========

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd} [20:49 20/06/2009]
{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} [16:44 27/03/2009]
{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [20:44 04/08/2009]

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{B7082FAA-CB62-4872-9106-E42DD88EDE45}"="C:\Program Files\McAfee\SiteAdvisor" [20:17 11/03/2009]
"jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [16:41 27/03/2009]

---------- Old Logs ----------
GooredFix[17.30.02_23-09-2009].txt

-=E.O.F=-
Go to the top of the page
 
+Quote Post
jpshortstuff
post Sep 24 2009, 03:31 PM
Post #10


Visiting Staff
Group Icon
Posts: 84
From: UK
OS: XP



That log looks clean, but you ran the tool twice by the looks of things:
---------- Old Logs ----------
GooredFix[17.30.02_23-09-2009].txt


For that section of the log to be showing, it means that GooredFix has previously found and removed something, so I think its safe to say GooredFix was successful in removing the problem smile.gif
Go to the top of the page
 
+Quote Post
phammo
post Sep 25 2009, 11:26 AM
Post #11


New Member
*
Posts: 2
OS: xp



Hi,

thanks for getting back so quickly.

I'm still getting the same redirecting problem with google search results in firefox. Do you know of any similar viruses/solutions?

Go to the top of the page
 
+Quote Post
Rorschach112
post Sep 25 2009, 11:28 AM
Post #12


GeekU Teacher
Group Icon
Posts: 34,358
From: Dublin
OS: XP



Please go to the malware forum and follow the instructions at the top....Especially the CLICK HERE.

That will give you several steps that will help you clean up 70 percent of all problems by yourself. If at the end of the process you are still having difficulty--and you may not be-- then post an OTListIt log in THAT forum.
Go to the top of the page
 
+Quote Post
downloadx
post Oct 22 2009, 09:53 PM
Post #13


New Member
*
Posts: 1
OS: Vista



QUOTE (phammo @ Sep 25 2009, 12:26 PM) *
Hi,

thanks for getting back so quickly.

I'm still getting the same redirecting problem with google search results in firefox. Do you know of any similar viruses/solutions?


I'm also still getting these problems. Goored did not find or remove any registry entry according to the logs.

Here's info on the problem:
I got this 6 months ago on my other PC and completely cleaned it back to new. But this time it's different, what worked last time no longer works. I was able to remove 90% of the problems with Malwarebytes, but not this one. I tried almost a dozen antivirus and anti spyware programs.

Reinstalling Firefox won't work. I noticed that there is a persistent profile (a horrible security decision) and other persistent data that don't get uninstalled. Deleting the profiles which contain extensions, etc.. does not work. In fact, I believe something is reinstalling the extension each time and it isn't part of the Firefox install but is possibly triggered by Firefox's startup. Possibly something in the registry or a background/startup tool that does this.

Workarounds that do work:
* When using google, never click on a lick to use it. Right click and copy the link to your clipboard and paste it into the url. This always works.
* Use Chrome or some other browser.

Any ideas on what will fix the redirect trojan this time? Reinstalling firefox doesn't work, there's something persistent I can't find.
Go to the top of the page
 
+Quote Post
chamber
post Oct 23 2009, 02:13 AM
Post #14


Trusted Helper
Group Icon
Posts: 1,703
From: ~/
OS: Linux all the way!



Please go to the malware forum and follow the instructions at the top....Especially the CLICK HERE.

That will give you several steps that will help you clean up 70 percent of all problems by yourself. If at the end of the process you are still having difficulty--and you may not be-- then post an OTListIt log in THAT forum.
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
2 User(s) are reading this topic (2 Guests and 0 Anonymous Users)
0 Members:

 

RSS Time is now: 7th November 2009 - 04:42 PM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising