Hijacked IE. Looking for troubleshooting advice

C

ColKurtz

Hi. I'm currently having a problem of Internet Explorer defaulting to
a hijacked website whenever I launch it. Opening an IE browser window
briefly (almost unnoticably) brings up the site
http://out.true-counter.com/a/?101 about:blank , then
ends up at an annoying search site http://global-finder.com/ .

I did a little reading, and discovered I had some possible trashapps
on my machine. Specifically, I found and removed/deleted the
following items:

1) In my Startup folder, I had POWERREG SCHEDULER V3.EXE.
2) In my HLM/Software/Microsoft/Windows/Currentversion/Run, I had an
entry for bootconf.exe. Deleted both the registry entry and .exe
file.

I'm STILL getting sent to global-finder.com when I launch IE (yes, I
rebooted). Here's what I've looked at so far:

1) I checked the WIN.INI. The only Run= entry there is MSINFO.EXE,
which I think is benign. No Load= entries.
2) I checked the other entries in my Run section of registry. I
believe they are OK, as well (Norton AV agent, Nero agent, Video card
util, PC support agent).
3) Nothing in RunOnce.
4) I uninstalled the only app that has been installed recently.
Didn't solve the problem, and wife claims the IE problem was arleady
present before she installed it.
5) Searched registry and disks for all instances of bootconf* and
powerreg*. Nothing was present except for some oddly named similar
files in c:\windows\prefetch (ex: POWERREG SCHEDULER
V3.EXE-0438D182.PF). Deleted the 2 prefetch files.
6) Rebooted and made sure that some other app was not reinstalling the
startup/registry entries.
7) Default IE home page is set to about:blank.
8) Virus scan clean
9) Adware v.6 and doxdesk.com find nothing.

I'm at a loss as to where else to look, and how to fix. Any
suggestions would be appreciated.

Thanks!
 
Y

YoKenny

ColKurtz said:
Hi. I'm currently having a problem of Internet Explorer defaulting to
a hijacked website whenever I launch it. Opening an IE browser window
briefly (almost unnoticably) brings up the site
http://out.true-counter.com/a/?101 about:blank , then
ends up at an annoying search site http://global-finder.com/ .

I did a little reading, and discovered I had some possible trashapps
on my machine. Specifically, I found and removed/deleted the
following items:

1) In my Startup folder, I had POWERREG SCHEDULER V3.EXE.
2) In my HLM/Software/Microsoft/Windows/Currentversion/Run, I had an
entry for bootconf.exe. Deleted both the registry entry and .exe
file.

I'm STILL getting sent to global-finder.com when I launch IE (yes, I
rebooted). Here's what I've looked at so far:

1) I checked the WIN.INI. The only Run= entry there is MSINFO.EXE,
which I think is benign. No Load= entries.
2) I checked the other entries in my Run section of registry. I
believe they are OK, as well (Norton AV agent, Nero agent, Video card
util, PC support agent).
3) Nothing in RunOnce.
4) I uninstalled the only app that has been installed recently.
Didn't solve the problem, and wife claims the IE problem was arleady
present before she installed it.
5) Searched registry and disks for all instances of bootconf* and
powerreg*. Nothing was present except for some oddly named similar
files in c:\windows\prefetch (ex: POWERREG SCHEDULER
V3.EXE-0438D182.PF). Deleted the 2 prefetch files.
6) Rebooted and made sure that some other app was not reinstalling the
startup/registry entries.
7) Default IE home page is set to about:blank.
8) Virus scan clean
9) Adware v.6 and doxdesk.com find nothing.

I'm at a loss as to where else to look, and how to fix. Any
suggestions would be appreciated.

It is the CWS browser hijacker parasite. It is very hard to get rid of
manually and can kill your Internet connection if removed incorrectly.

Get Ad-Aware and update to the latest reference file.
Select all items detected and remove.
You may have to reboot and rerun to completely remove the nasties.
Lavasoft/Ad-aware home: http://www.lavasoftusa.com

Get SpyBot Search & Destroy and update to the latest reference
file.
SpyBot home: http://security.kolla.de/
SpyBot How-To: http://www.tomcoyote.org/SPYBOT/

If these do not work then you will need CWS shredder available from this
site.
http://www.spywareinfo.com/~merijn/cwschronicles.html

SpywareBlaster to prevent these nasties installing.
http://www.javacoolsoftware.com/spywareblaster.html

You should update and run these at least once a week.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top