View previous topic :: View next topic |
Author |
Message |
fimoulia
Corporal
Joined: Apr 14, 2004
Posts: 50
Location: Belgium
|
Posted: Tue Jun 01, 2004 2:33 pm Post subject: Dancing URL SearchHook! |
|
|
Hello to all of you! Here is my story.
Once I had: R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file) in HijThis scan. Was told to fix it. Fixed - it doesn't go.
Shortly I took the value of this key out from HKCUser\Software\Microsoft\Internet Explorer\URL SearchHooks with help of the Registrar Lite. OK. Then run HijThis and it says: R3 - Default URL SearchHook is missing.
Have to fix it. I do. And this value is back right there where it was. I repeat the procedure and procedure repeats itself...
This value {CFBFAE00-17A6-11D0-99CB-00C04FD64497} is in CLSID list in HKCR and indicates as Microsoft URL Search Hook. Its InProcServer 32 shows its location as System32\Shdocvw.dll
...I Googled this value {CFBFAE00-17A6-11D0-99CB-00C04FD64497} and more than 5000 entries (all about the trouble) came up about HJT scan reads this value as (no name) ... (no file). I also noticed that quite often those troubled logs include infections with ad/spyware so called 'TV Media' which I also had. Many recomendations are to remove this value (for keeping it from comihg back) from the HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks like this one which I followed. http://www.computercops.biz/postt42340.html
Though my case is without any underscore after the value.
After that the new log showed again: R3 - Default URL SearchHook is missing.
Fixed. So this value is back in its place and recently doesn't show up in the new logs. But is this value a default value or a bad thing?
If this thing is lawful and doesn't show up in HJT logs then I can sleep quietly but if not then we better put it in fire. Is there the way to verify the legitimity of it?
I've received confirmation from Yellowhammer that my HJT log is clean.
http://www.computercops.biz/postt45888.html
What's now?
As 5000+ entries with troubles came up after Googling this Key Value, I think something is cooking here and not very Kocher. Would be interesting to have an opinion of others - mere mortals and Experts - on this issue.
Many thanks for your assistance and participation! |
|
Back to top |
|
|
satchick
1st Responder
Joined: Apr 29, 2004
Posts: 810
Location: Canada
|
Posted: Tue Jun 01, 2004 4:50 pm Post subject: |
|
|
Hi fimoulia,
That CLSID is lawful. It should be like a rash all over your registry. In the quote box is where I found it on my XP system.
Quote: |
[HKEY_CLASSES_ROOT\CLSID\{CFBFAE00-17A6-11D0-99CB-00C04FD64497}]
[HKEY_CLASSES_ROOT\CLSID\{CFBFAE00-17A6-11D0-99CB-00C04FD64497}\InProcServer32]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""
[HKEY_CURRENT_USER\Software\Resplendence Sp\Registrar Lite\Settings]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CFBFAE00-17A6-11D0-99CB-00C04FD64497}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CFBFAE00-17A6-11D0-99CB-00C04FD64497}\InProcServer32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
[HKEY_USERS\S-1-5-21-1871367453-176522532-3434827439-1004\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""
|
If you have this in your HJT log:
R3 - Default URL SearchHook is missing.
Then your probably missing this in your registry:
Quote: |
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="" |
Check that out and please let me know what you find.
|
|
Back to top |
|
|
fimoulia
Corporal
Joined: Apr 14, 2004
Posts: 50
Location: Belgium
|
Posted: Tue Jun 01, 2004 7:07 pm Post subject: |
|
|
Hi satchick,
Thank you for coming back to me. Nice to be with you again and to hear that probably we don't have to put anything in fire and peace will prevail.
I've checked all 8 entries you show me in my registries and should tell you they all look like yours exept the following two:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""
and
[HKEY_USERS\S-1-5-21-1871367453-176522532-3434827439-1004\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""
They don't have this "="" in the end.
In both cases the Type is REG_SZ and in place of the Data there is nothing - just empty space.
Quote: |
If you have this in your HJT log:
R3 - Default URL SearchHook is missing.
Then your probably missing this in your registry: |
I had this in my log:
R3 - Default URL SearchHook is missing.
But then I've fixed it in HJT. What I tell you now about what I have now it's after this fix.
satchick, what do you think about that?
Highly appreciate your help!
|
|
Back to top |
|
|
satchick
1st Responder
Joined: Apr 29, 2004
Posts: 810
Location: Canada
|
Posted: Tue Jun 01, 2004 8:35 pm Post subject: |
|
|
Sorry fimoulia, I didn't recognise your login name until just now. We had fun last time. I see your posts total is a lot higher. You've been busy!
To the problem at hand: You should repair your settings to look like mine. Somewhere along the line, either with HJT or the malware itself, the hooks settings have been damaged.
Copy and paste the following into notepad and save it as "hooks.reg". Then just double click to merge it into your registry:
Quote: |
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""
[HKEY_USERS\S-1-5-21-1871367453-176522532-3434827439-1004\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="" |
To be on the cautious side, I would first export those keys in your registry before importing the above. Just run REGEDIT and browse to each key and the use the File/Export function.
|
|
Back to top |
|
|
fimoulia
Corporal
Joined: Apr 14, 2004
Posts: 50
Location: Belgium
|
Posted: Tue Jun 01, 2004 9:33 pm Post subject: |
|
|
Hey satchick,
Hopefuly with your generous help things will get into their right place. And I'm glad I dug the problem. Seems that many people have it and I hope this thread will be of use for others. Only one thing...hmm.
To be perfectly honest with you my HKEY_USERS number differs from yours. Mine is:
HKEY_USERS\S-1-5-21-1801674531-602162358-682003330-1004
Do I have to retype the number in the notepad? Maybe silly question but I am not much of experience in this.
I already owe you one Godzillion and two beers! |
|
Back to top |
|
|
satchick
1st Responder
Joined: Apr 29, 2004
Posts: 810
Location: Canada
|
Posted: Tue Jun 01, 2004 9:50 pm Post subject: |
|
|
Yes, keep your numbers. Not surprised they vary. I don't have another XP system here or I'd double check for you. Just back up your keys before making the change (just in case!)
Not sure what a Godzillion is, but I'll take all the beer I can get! |
|
Back to top |
|
|
fimoulia
Corporal
Joined: Apr 14, 2004
Posts: 50
Location: Belgium
|
Posted: Wed Jun 02, 2004 6:02 pm Post subject: |
|
|
Hi satchick,
Sorry for the break. Went out to town for family business. (No beer)
By now accomplished all moves according your instructions. And it's like this. I exported first these two existing keys into notepad. They look like this in notepad:
Quote: |
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="
and
[HKEY_USERS\S-1-5-21-1801674531-602162358-682003330-1004\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="" |
Look - they received in notepad in their ends this sign "="" which they didn't have in registry.
Then I imported new keys you gave me from 'hooks.reg' with adjusted key number as mine. I had a popup confirmihg that they are moved. Now I looked in registry and those two keys after this manipulation are exactly the same like they were in the right pane before the manipulation. After the value there is nothing. No this sign "="" And no any undervalue not before and not now. I guess this sign "="" only exist in the notepad. Can you have a look into your registry on those two keys if they have in the right pane after the value {CFBFAE00-17A6-11D0-99CB-00C04FD64497} something.
Then I run HJT and there was nothing abnormal.
Cheers...
|
|
Back to top |
|
|
satchick
1st Responder
Joined: Apr 29, 2004
Posts: 810
Location: Canada
|
Posted: Wed Jun 02, 2004 6:24 pm Post subject: |
|
|
Sorry fimoulia, I just re-read our thread here and I can see now that I misunderstood one of your earlier posts. Those CLSID's should have a nul value (=""). I thought when I first read your posts that those CLSID's were missing in those reg locations, and what you are actually saying is that they wern't missing, but were there with a nul value.
This is the crucial info from your post that I somehow missed:
Quote: |
They don't have this "="" in the end.
In both cases the Type is REG_SZ and in place of the Data there is nothing - just empty space. |
So they were correct all this time! I must of had too much beer!
You can dunk the next one over my head.
|
|
Back to top |
|
|
fimoulia
Corporal
Joined: Apr 14, 2004
Posts: 50
Location: Belgium
|
Posted: Wed Jun 02, 2004 7:56 pm Post subject: |
|
|
satchick, ua-ua-ua-ua...aaaaaa...
If they were correct all the time then why this value was getting that disorientated. 5000 entries in Google. May look yourself. Showing like (no name) ... (no file) and comming back like that and after being deleted (many recomendations like that) and then with fixing in HJT: R3 - Default URL SearchHook is missing... seems like it regenerates itself into right shape. Well, too twisting...I'm loosing line myself...need some more beer.
I just thought that I was missing some Data or Undervalue for this value in the right pane. Anyway looks like were no trouble. And I don't have to know too much. I can sleep quietly now but before I go I need some more ...
Quote: |
I must of had too much beer! |
It's never too much...
Quote: |
You can dunk the next one over my head. |
No, I better do it over my own... Cheers...
|
|
Back to top |
|
|
satchick
1st Responder
Joined: Apr 29, 2004
Posts: 810
Location: Canada
|
Posted: Wed Jun 02, 2004 8:39 pm Post subject: |
|
|
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file) is a pretty common kind of 'damage' left over by hijackers (hense the 5000+ hits by google). Usually just removing all the entries in the HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks key and putting in the right one (with the null value) will clear them from your HJT log and fix the problem. In fact, I've never seen this not work before, but then I haven't been working in an anti-malware forum for very long either
I love this weird stuff though! Glad your system is OK, and have a beer on me! |
|
Back to top |
|
|
fimoulia
Corporal
Joined: Apr 14, 2004
Posts: 50
Location: Belgium
|
Posted: Wed Jun 02, 2004 9:55 pm Post subject: |
|
|
satchick,
Looks like case is close. It's a pity. Was nice to be with you again! And we had some more fun Next time I'll try to come with tougher topic. To stay longer with you.
Anyway. I'd like to express my highest appreciation of your asistance and dedication to help others! You are worth your weight in gold!
Now let's party. Champagne pour tout le monde!
PS. I'd rather stop drinking my money up and go to donate. |
|
Back to top |
|
|
satchick
1st Responder
Joined: Apr 29, 2004
Posts: 810
Location: Canada
|
Posted: Thu Jun 03, 2004 8:11 am Post subject: |
|
|
That would be great and you're most welcome. It has been a joy to share ideas with you again. |
|
Back to top |
|
|
lilliebet65
Site Moderator
Premium Member
Joined: Dec 03, 2003
Posts: 2225
Location: UK
|
Posted: Fri Jun 04, 2004 8:27 am Post subject: |
|
|
Glad we were able to help.
NOTE: This thread is now closed. Should you need it reopened, please PM a mod.
Everyone else having a similar issue, please launch a new topic for yourselves.
To reduce the chances of future Spyware/Hijacking problems, please follow the suggestions here: http://www.computercops.biz/postt7736.html
_________________
I'm Spartacus! |
|
Back to top |
|
|
|