New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 24)
· Marcia's (CO8)
· Bill G's (CO12)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 1157
Comments: 21
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

Dancing URL SearchHook!

 
Post new topic   This topic is locked you cannot edit posts or make replies       Computer Cops Forum Index -> General Security
View previous topic :: View next topic  
Author Message
fimoulia

Corporal
Corporal



Joined: Apr 14, 2004
Posts: 50
Location: Belgium

PostPosted: Tue Jun 01, 2004 2:33 pm    Post subject: Dancing URL SearchHook!
Reply with quote

Hello to all of you! Smile Here is my story.

Once I had: R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file) in HijThis scan. Was told to fix it. Fixed - it doesn't go.
Shortly I took the value of this key out from HKCUser\Software\Microsoft\Internet Explorer\URL SearchHooks with help of the Registrar Lite. OK. Then run HijThis and it says: R3 - Default URL SearchHook is missing.
Have to fix it. I do. And this value is back right there where it was. I repeat the procedure and procedure repeats itself...

This value {CFBFAE00-17A6-11D0-99CB-00C04FD64497} is in CLSID list in HKCR and indicates as Microsoft URL Search Hook. Its InProcServer 32 shows its location as System32\Shdocvw.dll

...I Googled this value {CFBFAE00-17A6-11D0-99CB-00C04FD64497} and more than 5000 entries (all about the trouble) came up about HJT scan reads this value as (no name) ... (no file). I also noticed that quite often those troubled logs include infections with ad/spyware so called 'TV Media' which I also had. Many recomendations are to remove this value (for keeping it from comihg back) from the HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks like this one which I followed. http://www.computercops.biz/postt42340.html
Though my case is without any underscore after the value.
After that the new log showed again: R3 - Default URL SearchHook is missing.
Fixed. So this value is back in its place and recently doesn't show up in the new logs. But is this value a default value or a bad thing?

If this thing is lawful and doesn't show up in HJT logs then I can sleep quietly but if not then we better put it in fire. Is there the way to verify the legitimity of it?

I've received confirmation from Yellowhammer that my HJT log is clean.
http://www.computercops.biz/postt45888.html
What's now?
As 5000+ entries with troubles came up after Googling this Key Value, I think something is cooking here and not very Kocher. Would be interesting to have an opinion of others - mere mortals and Experts - on this issue.

Many thanks for your assistance and participation! Smile
Back to top
View users profile Send private message
satchick

1st Responder
1st Responder



Joined: Apr 29, 2004
Posts: 810
Location: Canada

PostPosted: Tue Jun 01, 2004 4:50 pm    Post subject:
Reply with quote

Hi fimoulia,

That CLSID is lawful. It should be like a rash all over your registry. In the quote box is where I found it on my XP system.

Quote:
[HKEY_CLASSES_ROOT\CLSID\{CFBFAE00-17A6-11D0-99CB-00C04FD64497}]

[HKEY_CLASSES_ROOT\CLSID\{CFBFAE00-17A6-11D0-99CB-00C04FD64497}\InProcServer32]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""

[HKEY_CURRENT_USER\Software\Resplendence Sp\Registrar Lite\Settings]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CFBFAE00-17A6-11D0-99CB-00C04FD64497}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CFBFAE00-17A6-11D0-99CB-00C04FD64497}\InProcServer32]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"

[HKEY_USERS\S-1-5-21-1871367453-176522532-3434827439-1004\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""

If you have this in your HJT log:
R3 - Default URL SearchHook is missing.

Then your probably missing this in your registry:

Quote:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""

Check that out and please let me know what you find. Very Happy
Back to top
View users profile Send private message Send email
fimoulia

Corporal
Corporal



Joined: Apr 14, 2004
Posts: 50
Location: Belgium

PostPosted: Tue Jun 01, 2004 7:07 pm    Post subject:
Reply with quote

Hi satchick, Very Happy

Thank you for coming back to me. Nice to be with you again and to hear that probably we don't have to put anything in fire and peace will prevail.
I've checked all 8 entries you show me in my registries and should tell you they all look like yours exept the following two:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""
and
[HKEY_USERS\S-1-5-21-1871367453-176522532-3434827439-1004\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""

They don't have this "="" in the end.
In both cases the Type is REG_SZ and in place of the Data there is nothing - just empty space.
Quote:
If you have this in your HJT log:
R3 - Default URL SearchHook is missing.
Then your probably missing this in your registry:
I had this in my log:
R3 - Default URL SearchHook is missing.
But then I've fixed it in HJT. What I tell you now about what I have now it's after this fix.

satchick, what do you think about that?

Highly appreciate your help! Thank You
Back to top
View users profile Send private message
satchick

1st Responder
1st Responder



Joined: Apr 29, 2004
Posts: 810
Location: Canada

PostPosted: Tue Jun 01, 2004 8:35 pm    Post subject:
Reply with quote

Sorry fimoulia, I didn't recognise your login name until just now. We had fun last time. Very Happy I see your posts total is a lot higher. You've been busy!

To the problem at hand: You should repair your settings to look like mine. Somewhere along the line, either with HJT or the malware itself, the hooks settings have been damaged.

Copy and paste the following into notepad and save it as "hooks.reg". Then just double click to merge it into your registry:

Quote:

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""

[HKEY_USERS\S-1-5-21-1871367453-176522532-3434827439-1004\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""


To be on the cautious side, I would first export those keys in your registry before importing the above. Just run REGEDIT and browse to each key and the use the File/Export function. Very Happy
Back to top
View users profile Send private message Send email
fimoulia

Corporal
Corporal



Joined: Apr 14, 2004
Posts: 50
Location: Belgium

PostPosted: Tue Jun 01, 2004 9:33 pm    Post subject:
Reply with quote

Hey satchick, Very Happy

Hopefuly with your generous help things will get into their right place. And I'm glad I dug the problem. Seems that many people have it and I hope this thread will be of use for others. Only one thing...hmm.
To be perfectly honest with you my HKEY_USERS number differs from yours. Mine is:
HKEY_USERS\S-1-5-21-1801674531-602162358-682003330-1004

Do I have to retype the number in the notepad? Maybe silly question but I am not much of experience in this.

I already owe you one Godzillion and two beers!
Back to top
View users profile Send private message
satchick

1st Responder
1st Responder



Joined: Apr 29, 2004
Posts: 810
Location: Canada

PostPosted: Tue Jun 01, 2004 9:50 pm    Post subject:
Reply with quote

Yes, keep your numbers. Not surprised they vary. I don't have another XP system here or I'd double check for you. Just back up your keys before making the change (just in case!)

Not sure what a Godzillion is, but I'll take all the beer I can get! Very Happy
Back to top
View users profile Send private message Send email
fimoulia

Corporal
Corporal



Joined: Apr 14, 2004
Posts: 50
Location: Belgium

PostPosted: Wed Jun 02, 2004 6:02 pm    Post subject:
Reply with quote

Hi satchick, Very Happy

Sorry for the break. Went out to town for family business. (No beer)
By now accomplished all moves according your instructions. And it's like this. I exported first these two existing keys into notepad. They look like this in notepad:
Quote:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="
and
[HKEY_USERS\S-1-5-21-1801674531-602162358-682003330-1004\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""

Look - they received in notepad in their ends this sign "="" which they didn't have in registry.
Then I imported new keys you gave me from 'hooks.reg' with adjusted key number as mine. I had a popup confirmihg that they are moved. Now I looked in registry and those two keys after this manipulation are exactly the same like they were in the right pane before the manipulation. After the value there is nothing. No this sign "="" And no any undervalue not before and not now. I guess this sign "="" only exist in the notepad. Can you have a look into your registry on those two keys if they have in the right pane after the value {CFBFAE00-17A6-11D0-99CB-00C04FD64497} something. Rolling Eyes
Then I run HJT and there was nothing abnormal.

Cheers...
Back to top
View users profile Send private message
satchick

1st Responder
1st Responder



Joined: Apr 29, 2004
Posts: 810
Location: Canada

PostPosted: Wed Jun 02, 2004 6:24 pm    Post subject:
Reply with quote

Sorry fimoulia, I just re-read our thread here and I can see now that I misunderstood one of your earlier posts. Those CLSID's should have a nul value (=""). I thought when I first read your posts that those CLSID's were missing in those reg locations, and what you are actually saying is that they wern't missing, but were there with a nul value.

This is the crucial info from your post that I somehow missed:
Quote:
They don't have this "="" in the end.
In both cases the Type is REG_SZ and in place of the Data there is nothing - just empty space.

So they were correct all this time! Embarassed I must of had too much beer! Wink

You can dunk the next one over my head. Very Happy
Back to top
View users profile Send private message Send email
fimoulia

Corporal
Corporal



Joined: Apr 14, 2004
Posts: 50
Location: Belgium

PostPosted: Wed Jun 02, 2004 7:56 pm    Post subject:
Reply with quote

satchick, Rolling on the floor laughing... ua-ua-ua-ua...aaaaaa...

If they were correct all the time then why this value was getting that disorientated. 5000 entries in Google. May look yourself. Showing like (no name) ... (no file) and comming back like that and after being deleted (many recomendations like that) and then with fixing in HJT: R3 - Default URL SearchHook is missing... seems like it regenerates itself into right shape. Well, too twisting...I'm loosing line myself...need some more Bow beer.

I just thought that I was missing some Data or Undervalue for this value in the right pane. Anyway looks like were no trouble. And I don't have to know too much. I can sleep quietly now but before I go I need some more Bow ...
Quote:
I must of had too much beer!
It's never too much...
Quote:
You can dunk the next one over my head.
No, I better do it over my own... Very Happy Cheers...
Back to top
View users profile Send private message
satchick

1st Responder
1st Responder



Joined: Apr 29, 2004
Posts: 810
Location: Canada

PostPosted: Wed Jun 02, 2004 8:39 pm    Post subject:
Reply with quote

R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file) is a pretty common kind of 'damage' left over by hijackers (hense the 5000+ hits by google). Usually just removing all the entries in the HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks key and putting in the right one (with the null value) will clear them from your HJT log and fix the problem. In fact, I've never seen this not work before, but then I haven't been working in an anti-malware forum for very long either Very Happy

I love this weird stuff though! Glad your system is OK, and have a beer on me! Wine
Back to top
View users profile Send private message Send email
fimoulia

Corporal
Corporal



Joined: Apr 14, 2004
Posts: 50
Location: Belgium

PostPosted: Wed Jun 02, 2004 9:55 pm    Post subject:
Reply with quote

satchick,
Looks like case is close. It's a pity. Crying or Very sad Was nice to be with you again! And we had some more fun Wink Next time I'll try to come with tougher topic. To stay longer with you.
Anyway. I'd like to express my highest appreciation of your asistance and dedication to help others! Thumbs Up You are worth your weight in gold!
Now let's party. Bananas Wine Bananas Wine Bananas Wine Champagne pour tout le monde!

PS. I'd rather stop drinking my money up and go to donate.
Back to top
View users profile Send private message
satchick

1st Responder
1st Responder



Joined: Apr 29, 2004
Posts: 810
Location: Canada

PostPosted: Thu Jun 03, 2004 8:11 am    Post subject:
Reply with quote

That would be great Very Happy and you're most welcome. It has been a joy to share ideas with you again. Thumbs Up
Back to top
View users profile Send private message Send email
lilliebet65

Site Moderator
Site Moderator
Premium Member
Premium Member


Joined: Dec 03, 2003
Posts: 2225
Location: UK

PostPosted: Fri Jun 04, 2004 8:27 am    Post subject:
Reply with quote

Glad we were able to help. Smile

NOTE: This thread is now closed. Should you need it reopened, please PM a mod.
Everyone else having a similar issue, please launch a new topic for yourselves.

To reduce the chances of future Spyware/Hijacking problems, please follow the suggestions here: http://www.computercops.biz/postt7736.html

_________________
I'm Spartacus!
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       Computer Cops Forum Index -> General Security All times are GMT - 5 Hours
Page 1 of 1

 
 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops