Favorite addresses being modified

P

paul

When choosing any favorite address, for example:
http://www.microsoft.com, the address gets immediately
changed to: res://C:\DOCUME~1\PAULKA~1\LOCALS~1
\Temp\Peak.res/error.htm#http://www.microsoft.com.

It does no matter which favorite address I chose, or
whether it is the homepage, this insert (res://C:\DOCUME~1
\PAULKA~1\LOCALS~1\Temp\Peak.res/error.htm#) always
occurs.

How do I get rid of this?
 
T

Touch Base

Your infection could be a new CoolWebSearch (CWS) hijack infection and is
hard to remove. It may be related to the 'lop' hijack too.

Note: Every time you reboot the files multiply and change names. This
process is like exterminating cockroaches.

Please download the tool called about:buster from:
http://www.downloads.subratam.org/AboutBuster.zip
or
http://www.majorgeeks.com/download4289.html

Unzip it to your desktop.
In WinME/XP turn off System Restore.
http://www.arnoldco.com/help/html/disable_restore.html

Important steps to getting this tool to work properly:

First unzip all files from the zip folder to a folder or your desktop. Run
AboutBuster.exe.
Then hit Ok, note that there is now an update button. Hit update and 'Check
for Update'.
If there is a newer version hit 'Download Update'. Wait while it downloads.

Then reboot into Safe Mode by tapping F8 key repeatedly during bootup.
Enable System Restore after the infection is removed.

Now for the scanning part. Run AboutBuster.exe Hit start and then Ok. The
program should start scanning.
This will scan your computer for the bad files and delete them. Then hit
exit and reboot into safe mode.

Run about:Buster again in safe mode to check that no remaining files remain.

The database will be updated very frequently so check your versions once a
day.

Install the prevention protection below:

Download and install WinPatrol.
http://www.winpatrol.com

Browser settings for increased security:
http://bshagnasty.home.att.net/browsersettings.htm

Install IE-SPYAD then run the install.bat in the ie-spyad folder and
download SpywareBlaster
https://netfiles.uiuc.edu/ehowes/www/resource.htm#IESPYAD
http://www.javacoolsoftware.com/spywareblaster.html

Report back here on any outcome.
 
P

paul

Used AboutBuster but "No ADS found on system". Problem
still remains. Thanks for you help. Any other ideas?
 
T

Touch Base

Some more archived tools and info re: Spyware/Malware infection.

IMPORTANT: Before trying to remove spyware, download a copy of LSPFIX from
the URL below - some malware can kill your internet connection when it is
removed, and this software should get things going for you again:
http://www.cexx.org/lspfix.htm

IMPORTANT: After obtaining the software below, make sure you check for
updates and then run the programmes in safe mode.

You can go to the link below to check your system for parasites (supplied by
Doxdesk.com):
http://inetexplorer.mvps.org/parasite.htm

Malware removal (beginners guide):

First, go to Control Panel, add/remove programs. Check for malware entries
and use the uninstall programs.

Second, get AdAware. [..Warning: AdAware is now version 6.181. All previous
versions are NO LONGER SUPPORTED and will not be updated...]

AdAware is available at www.lavasoft.de. Make sure you check for updates
every time you use it.

To be most effective, you must run AdAware while Windows is in safe mode,
and you must shut down as many suspect processes as possible.

This can be tricky, but nothing is impossible. Modern malware uses more than
one process, and these processes are 'co-dependent'. In other words, when
one processes detects that the other has been shut down, it automatically
restarts its sibling, often using a different name. Using Task Manager
(ctrl, alt, del) doesn't work because you can only shut down one process at
a time.

Disable suspect processes using MSCONFIG before booting into safe mode. Use
the information at the URL below as a guide:

http://www2.whidbey.com/djdenham/Uncheck.htm

After you are in safe mode, check to make sure the suspect processes did not
start up. Then start AdAware. Make sure 'activate in depth scan' is
enabled. Select 'use custom scanning options' and then click on the
'customize' button. Turn on the following scan options - scan within
archives, active processes,
registry (including deep scan), IE favorites and hosts file. You must also
turn on the following option via the 'tweak' button:

Cleaning engine: 'automatically try to unregister objects prior to deletion'

IMPORTANT: Before letting AdAware delete malware, write down on a piece of
paper exactly where the malware is stored. You will need to delete those
directories after AdAware has done its work, but ONLY IF IT IS NOT A
STANDARD WINDOWS DIRECTORY.

After running AdAware, run it again, this time using the option 'select
drives/folders to scan'. Click on 'select'. Scan your entire hard drive.
Also do the following:

Empty your IE cache and your other temporary file folders, eg:
c:\windows\temp (if using Windows 98) or C:\Documents and
Settings\<name>\Local Settings\Temp (the path to your temp folder will
change depending on your name) - sometimes programmes can be hidden in
there - watch out for mysterious *.exe files or *.dll files in those
folders.

Go to IE Tools, Internet Options, Temporary Internet Files {Settings
Button}, View Objects, Downloaded Programme Files. Check for unusual objects
there.

Go to IE Tools, Internet Options, Accessibility. Make sure there is no
style sheet chosen (under User Style Sheet - format documents using my style
sheet). If the option is turned on, turn it OFF.

It is possible to turn off third party extensions (Enable third-party
browser extensions (requires restart) at IE tools, internet options,
advanced) to disable *all* plug-ins but troubleshooting will be difficult
and it is only a BANDAID. Nothing gets fixed. There is software that
depends on 'third party browser extensions" to work, including Acrobat,
Microsoft Money, and many other programmes.

If you are still having problems:

You can go to the link below to check your system for parasites and
hopefully identify your problem (supplied by Doxdesk.com):

http://inetexplorer.mvps.org/parasite.htm

Download and run the latest version of "Cool Web Shredder"
http://www.merijn.org/files/CWShredder.exe

The more experienced user can try Spybot. Again, it is a free programme
which can be downloaded from: http://spybot.eon.net.au/. Warning: it is NOT
a good programme for the inexperienced. If you want to use this programme,
please get the advice of those more experienced before 'fixing' anything
that it finds.

Another excellent programme that allows you to examine your system and
*create a results log for experts to examine* is HijackThis, available from:
http://www.tomcoyote.org/hjt/

An experienced computer technician can use programme such as AutoStart
Viewer for in-depth diagnosis:
http://www.diamondcs.com.au/index.php?page=asviewer

MS have released a limited KB article regarding what they call 'deceptive
software'.
http://support.microsoft.com/default.aspx?scid=kb;EN-US;827315

Here is advice specific to:

home page hijackings
http://inetexplorer.mvps.org/answers.htm#home_page

pop-up ads
http://inetexplorer.mvps.org/data/popup.htm

search engine hijackings
http://inetexplorer.mvps.org/answers4.htm#search_engine

IMPORTANT: The above programmes are excellent, and a lot of credit goes to
those who authored and update the programmes, but they can NOT detect
everything that is out there - as time goes on the programmes will become
more and more unwieldy if they try to maintain a standard of positive
identification for as much spyware as possible, and it will be harder and
harder for the programmes to catch everything that is out there. More and
more spyware uses RANDOM names as part of their programme making it
impossible for positive identification to occur, therefore....

It is VERY IMPORTANT that you learn how to examine your system for potential
problems as well as using 'fixit' programme such as AdAware or Spybot.

Check your startup folder and MSCONFIG (startup tab). You can also check
the following registry keys and edit as appropriate (if you have experience
with same).

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runonce

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonce

The following link will lead you to some Microsoft KB articles about the
basics of the Registry and working with it:
http://inetexplorer.mvps.org/answers.htm#Registry
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

HELP HELP redirect of address bar 1
Please Help. 1
IEsp.mht 1
IE7 hangs 7
IEXPLORE.exe.dpmp and accompat.txt 1
hijacked browser - help!!! 2
Can anyone explain this!?! 6
roxio easy cd/dvd creator 6 basic 10

Top