| View previous topic :: View next topic |
| Author |
Message |
fimoulia
Lieutenant

 Joined: Apr 14, 2004 Posts: 167
|
Posted: Thu May 27, 2004 11:27 pm Post subject: Dancing URL SearchHook! |
|
|
Hello to all! Here is my story.
Once I had: R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file) in HijThis scan. Was told to fix it. Fixed it - doesn't go.
Shortly I took the value of this key out from HKCUser\Software\Microsoft\Internet Explorer\URL SearchHooks with help of the Registrar Lite. OK. Then run HijThis and it says: R3 - Default URL SearchHook is missing.
Have to fix it. I do. And this value is back right there where it was. I repeat the procedure and procedure repeats itself...
This value {CFBFAE00-17A6-11D0-99CB-00C04FD64497} is in CLSID list in HKCR and indicates as Microsoft URL Search Hook. Its InProcServer 32 shows default location as System32\Shdocvw.dll
Is this thing legitimate? Can someone pour cold water on my head?
|
|
| Back to top |
|
 |
!Mariner
Colonel
 Premium Member
Joined: Aug 25, 2003 Posts: 1914
|
Posted: Fri May 28, 2004 1:27 pm Post subject: |
|
|
Hi fimoulia,
Tell you what, throw up a HJT log and lets get your system cleaned right out/up. I know you have been taking steps to secure your system but, if there is already bad stuff on it, it must be removed first for security applications to be effective.
You appear to have a bad and persistent 'Hook' buried in there, lets get rid of it.
OK, Standard instructions coming up, please follow carefully.
Please read these messages
Virus=Read This: /postt8864.html
HiJack= Read This: /t911-Before_You_Post_Read_Follow_These_Rules_and_Guidelines.html
Then
Download: HiJack This!
Create and Unzip to a folder not your Desktop or the Temp folder, doubleclick HijackThis.exe, and press "Scan".
Unzip the download (using a piece of software like: Winzip)
When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log in a text file, and post it in the CCSP "Spyware - Hijack Related" forum:
/f67-Trend_Micro_HijackThis_Logs.html
Most of what it lists will be harmless or even required, so do NOT fix anything yet.
Someone here will be happy to help you analyze the results.
*Please, be patient. An expert will examine your log and this does take time. Please, no 'Bumps' and no 'Dupes'. Thank you.*
|
|
| Back to top |
|
 |
fimoulia
Lieutenant

 Joined: Apr 14, 2004 Posts: 167
|
|
| Back to top |
|
 |
!Mariner
Colonel
 Premium Member
Joined: Aug 25, 2003 Posts: 1914
|
Posted: Sun May 30, 2004 1:44 am Post subject: |
|
|
Hi fimoulia,
Yes, to be absolutely certain, post another log. If there is nothing to worry about, it will not take long to work through. You've come this far and it would be a pity to have to leave one unknown item remaining, especially as it may come back to haunt you later.
No matter how good your defences might be they are of little use if they are helping keep a bad guy within your system.
If the CLISD is an unknown quantity, then it should be looked at as it may be a new one and it's discovery will be of help to others. So, go ahead and post a new log.
|
|
| Back to top |
|
 |
fimoulia
Lieutenant

 Joined: Apr 14, 2004 Posts: 167
|
Posted: Sun May 30, 2004 2:48 am Post subject: |
|
|
Mariner,
OK. I'll post the log right now in HijackThis forum. Under the subject hmm... 'Chasing the CLSID'. Will you move this thread over there? I don't know how it works. Anyway, the log will be there.
Thanks A LOT!
|
|
| Back to top |
|
 |
!Mariner
Colonel
 Premium Member
Joined: Aug 25, 2003 Posts: 1914
|
Posted: Sun May 30, 2004 3:11 am Post subject: |
|
|
No, i'll leave this thread where it is and your log will be treated separately.
Give it several days to gain some attention, please.
|
|
| Back to top |
|
 |
fimoulia
Lieutenant

 Joined: Apr 14, 2004 Posts: 167
|
|
| Back to top |
|
 |
!Mariner
Colonel
 Premium Member
Joined: Aug 25, 2003 Posts: 1914
|
|
| Back to top |
|
 |
|
|