Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Helo,
My IE homepage has recently been hijacked by the website hugesearch.net. I have tried spybot and ad aware, and while some items were found and deleted, it has not eradicated the problem. I have then tried HijackThis, which temporarily fixes the problem but when I restart my PC, it has all been reset. Can anyone see anything suspicious in the following.Many thanks.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.hugesearch.net/bar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hugesearch.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hugesearch.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.hugesearch.net/bar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.hugesearch.net/bar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.hugesearch.net/bar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hugesearch.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.hugesearch.net/bar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.hugesearch.net/bar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.hugesearch.net/bar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.hugesearch.net/bar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [TPW95TB] C:\PROGRA~1\THINKPAD\UTILIT~1\TPW95TB.exe
O4 - HKLM\..\Run: [LexStart] Lexstart.exe
O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [IrMon] IrMon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.exe" -atboottime
O4 - HKLM\..\Run: [NAV DefAlert] C:\PROGRA~1\NORTON~1\NORTON~2\DEFALERT.exe
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NORTON~2\NAVAPW32.exe /LOADQUIET
O4 - HKLM\..\Run: [Norton CrashGuard Monitor] "C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CRASHGUARD\CGMenu.exe"
O4 - HKLM\..\Run: [Norton eMail Protect] C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON ANTIVIRUS\POProxy.exe
O4 - HKLM\..\Run: [Truefonts] C:\WINDOWS\FONTS\fonts.hta
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [CSINJECT.EXE] C:\Program Files\Norton SystemWorks\Norton CleanSweep\CSINJECT.exe
O4 - HKLM\..\RunServices: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.exe
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.exe
O4 - Startup: Norton System Doctor.lnk = C:\Program Files\Norton SystemWorks\Norton Utilities\SYSDOC32.exe
O4 - Startup: CleanSweep Smart Sweep-Internet Sweep.lnk = C:\Program Files\Norton SystemWorks\Norton CleanSweep\csinsm32.exe
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O13 - DefaultPrefix: http://www.hugesearch.net/search.php?qq=
O13 - WWW Prefix: http://www.hugesearch.net/search.php?qq=
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {5A3C6507-730A-43B2-8EAC-4C430F2EF35E} (PortfolioManager Class) - https://portfoliomanager.westpac.com.au/portfoliomanager/portfoliomanager.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37869.6534490741

Fix all R0 and R1 lines, this
O13 - DefaultPrefix: http://www.hugesearch.net/search.php?qq=
O13 - WWW Prefix: http://www.hugesearch.net/search.php?qq=
Reboot

Add this
O4 - HKCU\..\Run: [QuickTime Task] c:\windows\qttasks.exe
O4 - HKLM\..\Run: [Truefonts] C:\WINDOWS\Fonts\fonts.hta

Have you tried CoolWebShredder
Might not be a bad idea, seem to be missing the running processes, (the first part of the scan) C:\Windows.... etc.hth
shep

Hi,
Any luck with this or more info please, I have a user with the same problem. He cannot access any pages at all ?
Thanks
Paul :)

hi, i have the same problem and could not access any other page with ie any more. can anyone let me know how i can get rid of this and what can happen. I am now using netscape.
any link to a antivirus programm which solves this problem would be highly welcome.
thanks,
volker

I'm also having the same problem... I have tried several different things, but everytime the problem persists upon rebooting.
I would love some info!
Thanks,
EmJay

The script writing changes to the registry is "C:\WINDOWS\FONTS\fonts.hta." Remove this from the Run section of the registry (or use msconfig and uncheck it), reboot, delete it. You will still need to fix the default settings for IE after this. Most of them are mentioned above.
Drop me an email if this helped you. I found no solution to this problem on the 'net while fixing my friend's computer.

This happened to my brother's 3-day old puter. After being on hold with the HP tech for about 30 mins, I found out that it is a new trojan, and the only way to completely remove it as of now is to do a destructive reinstall. You absolutely must wipe your entire drive. If your backups are on your drive already, you will need to have backup disks so that your entire drive can be wiped, else you won't get rid of it.

DON'T WIPE YOUR HARD DRIVE !!!!!
"Cool Web Shredder" in response # 4 works like a dream. I have my computer back!Run it twice, restarting each time. Hugesearch.net and cool web are trojans.

FIX for W2K
1. save the following regscript file as "regfix.reg"
------
Windows Registry Editor Version 5.00[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=""
"Default_Search_URL"=""
"Search Page"=""
"Start Page"="about:blank"[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=""
"Default_Search_URL"="www.google.de"
"SearchAssistant"=""[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs]
"url1"=""
"url2"=""
"url3"=""[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=""
"Default_Search_URL"=""
"Search Bar"=""
"Search Page"=""
"Start Page"="about:blank"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=""
"Default_Search_URL"=""
"SearchAssistant"=""[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl]
@=""[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
@=""[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes]
"www"="http://"
2. run script at DOS prompt
"regedit /s regfix.reg"all hugesearch entries are removerd now. you can include this script into a logon script to avoid this (or similar) trojans.
cheers hoschie

DO NOT reformat your drive. This is an attempt by you hardware vendor to get you off their backs. It really isn't their problem so i can't really blame them for trying. This is a trojan virus as mentioned above . Hopefully you have a decent anti-virus program which came with your computer or you have purchased. Get the latest virus definitions from their update site and run the scan. This should catch this virus and quaranteen the file. Once it captures this , go ahead and run Cool Web Shredder, this shoulf restore you original IE home page info. If not, do it manually through Tools>>Internet Options in your IE tool bar. Hope this helps.

I have recently received this virus and I noticed that I was only redirected to the huge search site if I didn't type in the http. Example: typing www.yahoo.com would lead to the huge search site but typing http://www.yahoo.com would lead me to the yahoo site. At least you can still search the web while trying to fix your problem

Alright, im not too good with computers and im trying to get this off. Im stuck with the hugesearch b/s and im completly clueless as to what you guys are talking about half the time. I scanned my comp with McAfee(came with the dell) and i deleted it and it doesnt say any files are infected but its still friggin here. pleaseee help

Thanks everyone... I finally got it wiped out
I couldnt get the script to run in post11 but used regedit and did it maually... also dont forget to clean out the fonts.hta file in windows/fonts.. it would not delete so I just used edit and gutted it..thanks and merry xmas
dm

Got It out this way , Have windows 98
1- Start
2-Run
3-Type Msconfig
4-click on start up
5-Look for True Fonts C:\windows\fonts\fonts.hta6-uncheck True fonts
7- restart PCThis did it for me, Try Merry X-mas ! :)

Hi,
I had the same problem today:
REGEDIT -> HKLM->SOFTWARE->MICROSOFT->WINDOWS->CURRENT VERSION->URL
->DefaultPrefix remove all keys here
->WWW replace the "hugesearch.net" with a simple "http://".
Your Homepage/Startpage can be changed in the options menue of the IE.B.T.W., I got that b---tard who rented the domain "hugesearch.net":
He lives in Norway, his name is Ernesto Hans:
Gepplyngun 24
Alta NG 9514His private email is:
ernesto@zeos.net
The website email is:
support@hugesearch.netCome on guys, send him some mail and tell him what you think about this new type of SPAM !
If somebody lives close to this place, go over and kick his ass, the 10th time with best regards from me.

Dear guenter:
Your message from
Date: December 18, 2003 at 07:42:49 Pacific
solved my problem and made my X mas, so THANK YOU and merry xmas to you and all people on here that are spending your time and energy to help out.
much luv to u all
Mary

Still clueless .... did what vinnie M said, but couldnt find True fonts only fonts... unchecked it and restarted and its still here

I got the same prob. How many downloaded a Comet cursor lately. I think this is where it came from and after a bit of investigating I found out they were found to be full of spyware, etc.
I went to internet options and change my opening page to about:blank, hey AOL sucks but some times drastic measures are required. At least now it can't seem to change itself back to www.hugepaininthebutt.net

dear all,
halo guenter, i follow your suggestion :
REGEDIT -> HKLM->SOFTWARE->MICROSOFT->WINDOWS->CURRENT VERSION->URL
->DefaultPrefix remove all keys here
->WWW replace the "hugesearch.net" with a simple "http://".But when i reboot my Computer, the "Hugesearch" still my IE, .... any idea guenter, or i miss something in regedit ..??
cheers,

hello down_with_the_king,
extended version:
START->RUN->REGEDIT
search for "hugesearch" and delete the content of all keys that come up.I remember that there were also entries in the HKCU, but they were gone after a reboot on my PC.
Mr. Hans was reported to the Norwegian police, so this kind of SPAM should disappear soon...

thanks all,
Guenter, thanks for your help
my problem solved now, i use :
- Ad-Aware 6.1 and
- CoolWebShredder ...and everything is back to normal, now ....
thanks all, & happy new year ...
cheers,

I got highjacked tonight. Responce # 11 by hoschie and responce #23 by guenter were perfectly effective and helpful in restoring my Win2K PC to normal. Thank you very much.

Hi,
As an extra to this good news: I discovered the same combination of two things in the hijack-log above on my own system.
The first was the file "fonts.hta" in the [Windows]/Fonts/ -directory, which runs at every boot.
The second was the change into freshvideogals.com for the start/search/etc. page.
Looking into the file fonts.hta pointed out that this file was the reason of the hijack.Filext.com says it's a 'hypertext application file'. Me being no expert, I leave that for what it is worth and be just happy with the result... Finally.
JBG.

Note to RESPONSE 11
This key should properly read:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
@="http://"So that http:// will be prepended to all subdomains when typed in the address bar.

Hello!
I have a problem with hugesearch. I can't start regedit to clean the registry, I can't change the startside in IE and I can't change the desktop build whitch I want. When I do one of this things, my computer says: This is stopped by the administrator. What's this? What can I do, to delete this spyware???
Greetz Benson

Thanks Hoschie, Guenter and all of the others who found a way to get rid of this Hugesearch disease.
I used Start -> Run -> Regedit in XP and made all the suggested changes.
I just restarted my computer and it works great (fingers crossed the fix is permanent).
For anyone still having trouble, once you run Regedit you can go through all the recommended folders same as you would for a document search using Explore. Then right click on the items listed by Hoschie and click modify. Enter "=" or alternate such as yahoo. Either way you are clearing the previous value which is "hugesearch.net"
Probably the most important one to change is URL/Prefix, set "www" = http:// ; but it's worth going through all the suggested items to see what other sites have invaded your system.
Thanks again, and good luck!

@Tags - Response 27
I followed all of the necessary steps and cleaned both the registry and (hopefully) my weblife from hugesearch.
But...
Now whenever I type a non-www url without the http header, a pop up appears telling me that IE doesn't recognize the url.
Example:
Previously if I typed "doom9.org", IE automatically added "http:\\" and re-directed me to "http://doom9.org".
Now if I type "doom9.org" (without the http://) an "impossible to find doom9.org" IE pop-up appears.
I'm referring to Response 27, b/c the only registry change I wasn't able to do was this one:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
@="http://"At the moment, I just have one string: "Predefined" (sorry, don't know the right term in english; my XP is in italian). This "Predefined" string has no value.
What does "@" mean? "All" values? What exactly do I have to type into Regedit?
Excuse me for my newbieness. ^___^
Andrea

Thanks for all the tips Responce # 11 by hoschie worked very well and even sorted http:// www. errors
Can anyone recommed what will rpevent this happening in future. Should I invest in firewall software?

I found the answer to all my computer problems, including "Hugesearch". My brother's computer was infected, but I had previously set him up with a backup hard drive which I cloned from his main drive, using Norton "Ghost". He told me about his "Hugesearch" problem, so, I cloned his backup drive back to the main drive, and it restored everything back to the way it was before infection. I used to unplug the power cable to the backup drive to prevent infection(dead drive can't be infected), but now I use something called a "drive switch" which I bought for 20 bucks from an "ebay store" seller(Eureka Engineering), and I don't have to open the computer case to unplug the power cable. I just flip a switch at the back of my computer now(best thing I ever did!!!!!). Check out the switch at ebay stores and their info on how to do the clone thing. Unbelievable!!!!!!! My brother's computer was back up in 12 minutes flat!!! This idea will fix anything! I don't even run anti-virus software anymore. No more constant updating of dat files, etc. I know this doesn't help people who are already infected, but once you get "clean", get a backup hard drive and clone it. You'll love it!!!!

![]() |
Windows/Norton Woes
|
Cannot melda virus
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |