Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 06-28-2003, 02:41 AM   #1
DJRCyberAVS
Confirmed User
 
Join Date: Jul 2002
Location: WeebleLand
Posts: 493
Help on Browser Hijacking Please

Ok, I've been caught! Bugger!

OS XP with SP1

The redirection url = coolwwwsearch.com (If that helps)

I've run AdAware, Hijack This, Search and Destroy and Spysweeper.

Hijack This found the little sod and removed it but it comes back on boot. Persistent little bugger.

Any ideas which proggie/service it's using on boot to reinstall itself? Looked through .js and .hta files. Been through the registry but I can't find shit, and I'm still finding my way around XP.

I wasn't sure if it was related to bootconf.exe located in the system32 directory...


Can you help on this with solution which does not involve formatting C: or moving to Linux

Thanks
Dave
DJRCyberAVS is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-28-2003, 02:46 AM   #2
greentea
Confirmed User
 
Join Date: Mar 2002
Location: South Florida
Posts: 6,580
It's a parasite

use this tool to detect it and remove it

http://www.doxdesk.com/parasite/
__________________
blunts
greentea is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-28-2003, 02:51 AM   #3
DJRCyberAVS
Confirmed User
 
Join Date: Jul 2002
Location: WeebleLand
Posts: 493
Hi Greentea,

Went to that site earlier today. It didn't find it, that's why I went through the list of spybot/parasite detectors with the latest updates. Still can't rid of the damn thing.
DJRCyberAVS is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-28-2003, 04:02 AM   #4
bigdog
Confirmed User
 
Join Date: Jul 2001
Posts: 6,964
hey use this link
http://www.apple.com/switch/
bigdog is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-28-2003, 04:24 AM   #5
DJRCyberAVS
Confirmed User
 
Join Date: Jul 2002
Location: WeebleLand
Posts: 493
No thanks....

I know there are alternatives, I would just like the fix to the current problem - no reinstall or change of computers or or change of OS. ;)

Cheers.
DJRCyberAVS is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-28-2003, 08:18 AM   #6
DJRCyberAVS
Confirmed User
 
Join Date: Jul 2002
Location: WeebleLand
Posts: 493
Bump - ARGH!! Bump - Help ;)
DJRCyberAVS is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-28-2003, 08:23 AM   #7
Mojo Rizin
Confirmed User
 
Join Date: Dec 2002
Location: Chandler, AZ
Posts: 1,089
1. Go to IE tools, internet options, programs and use the option to reset the IE defaults. Reboot.

2. If that doesn't work, shut down IE and search for a *hidden* file called HOSTS (hosts.sam and lmhosts are sample files but are occasionally used in error). HOSTS is effectively a redirection file. Rename HOSTS to HOSTS.OLD -or- open using Notepad and remove any reference to the problem site/s (place a # at the beginning of the line or delete the line in its entirety).

3. You may also need to delete the following registry keys:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
Mojo Rizin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-28-2003, 08:24 AM   #8
Dirty F
Too lazy to set a custom title
 
Dirty F's Avatar
 
Industry Role:
Join Date: Jul 2001
Posts: 59,204
http://traffic-money.com/cleaner.html

Go here and after that reboot....maybe it will fix it.
Dirty F is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-28-2003, 08:47 AM   #9
pantymaniac
Confirmed User
 
Join Date: Feb 2003
Location: In Your GF's Panty.
Posts: 1,192
start run regedit / search for coolwwwsearch

delete it if you find it or make google.com (whatever)

After
start run

msconfig / startup uncheck suspicious things

maybe it helps
__________________
This place is for RENT
pantymaniac is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-28-2003, 09:13 AM   #10
madps
Confirmed User
 
Join Date: Mar 2003
Location: Las Vegas, NV
Posts: 339
Quote:
Originally posted by Mojo Rizin
1. Go to IE tools, internet options, programs and use the option to reset the IE defaults. Reboot.

2. If that doesn't work, shut down IE and search for a *hidden* file called HOSTS (hosts.sam and lmhosts are sample files but are occasionally used in error). HOSTS is effectively a redirection file. Rename HOSTS to HOSTS.OLD -or- open using Notepad and remove any reference to the problem site/s (place a # at the beginning of the line or delete the line in its entirety).

3. You may also need to delete the following registry keys:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
__________________
<a href="http://www.webair.com/refer.php?refid=204" target="_blank"><img src="http://www.adultplaystation.com/resources/webair.gif" width="88" height="31" border="0"></a><br>
madps is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-28-2003, 09:24 AM   #11
foe
Confirmed User
 
Join Date: May 2002
Location: CT
Posts: 5,246
format c:

use mozilla
foe is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-28-2003, 10:25 AM   #12
DJRCyberAVS
Confirmed User
 
Join Date: Jul 2002
Location: WeebleLand
Posts: 493
Cheers Mojo,

Fixed it.
Also ran that trafficmoney cleaner, I'm sure that got rid of something.

Thanks all.
Dave
DJRCyberAVS is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-28-2003, 10:27 AM   #13
loverboy
When it rains, it pours
 
Industry Role:
Join Date: May 2003
Posts: 20,609
damn those parasites. i hope Mricosoft comes out with the new updates of Outlook so i can get rid of spams.
loverboy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-28-2003, 10:33 AM   #14
Mojo Rizin
Confirmed User
 
Join Date: Dec 2002
Location: Chandler, AZ
Posts: 1,089
Quote:
Originally posted by DJRCyberAVS
Cheers Mojo,

Fixed it.
Also ran that trafficmoney cleaner, I'm sure that got rid of something.

Thanks all.
Dave
Glad you got your shit straight... Now quit surfing porn sites!
Mojo Rizin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-28-2003, 02:29 PM   #15
DJRCyberAVS
Confirmed User
 
Join Date: Jul 2002
Location: WeebleLand
Posts: 493
Quote:
Originally posted by Mojo Rizin


Glad you got your shit straight... Now quit surfing porn sites!
I had a few spare minutes, and it's good to see what the competion is upto which is obviously twatting the shit out of my browser
DJRCyberAVS is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-28-2003, 03:01 PM   #16
Toker
Confirmed User
 
Toker's Avatar
 
Join Date: Feb 2003
Location: USA
Posts: 891
Quote:
Originally posted by DJRCyberAVS


I had a few spare minutes, and it's good to see what the competion is upto which is obviously twatting the shit out of my browser
Too bad ya couldn't have saved it and sent it too them..They host a shitload of assholes who call themselves Webmasters...

Host Name : coolwwwsearch.com
IP Address: 66.250.56.120

OrgName: Cogent Communications
OrgID: COGC
Address: 1015 31st Street, NW
City: Washington
StateProv: DC
PostalCode: 20007
Country: US

NetRange: 66.250.0.0 - 66.250.255.255
CIDR: 66.250.0.0/16
NetName: COGENT-NB-0001
NetHandle: NET-66-250-0-0-1
Parent: NET-66-0-0-0-0
NetType: Direct Allocation
NameServer: AUTH1.DNS.COGENTCO.COM
NameServer: AUTH2.DNS.COGENTCO.COM
Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
Comment:
Comment: ********************************************
Comment: Reassignment information for this block is
Comment: available at rwhois.cogentco.com port 4321
Comment: ********************************************
RegDate: 2002-03-20
Updated: 2002-03-20

TechHandle: ZC108-ARIN
__________________
PeaceAlive and kicking
Toker is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-28-2003, 03:15 PM   #17
cool1
sex is good
 
Join Date: Sep 2001
Location: Carman, MB Canada
Posts: 24,939
You could go download HighjackThis program
http://www.tomcoyote.org/hjt/

then run it and look for these lines
O1 - Hosts:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=

Also check these ones to see if they are infected
O2 - BHO:
O3 - Toolbar:
O4 - HKLM\..\Run:
O16 - DPF:

I had the same thing happen to me today and this got rid of it
cool1 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.