Computing.Net > Forums > Security and Virus > hugesearch.net homepage hijack

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

hugesearch.net homepage hijack

Reply to Message Icon

Name: Klomp
Date: December 8, 2003 at 22:49:57 Pacific
OS: Win 98
CPU/Ram: Unknown
Comment:

Helo,
My IE homepage has recently been hijacked by the website hugesearch.net. I have tried spybot and ad aware, and while some items were found and deleted, it has not eradicated the problem. I have then tried HijackThis, which temporarily fixes the problem but when I restart my PC, it has all been reset. Can anyone see anything suspicious in the following.

Many thanks.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.hugesearch.net/bar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hugesearch.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hugesearch.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.hugesearch.net/bar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.hugesearch.net/bar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.hugesearch.net/bar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hugesearch.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.hugesearch.net/bar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.hugesearch.net/bar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.hugesearch.net/bar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.hugesearch.net/bar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [TPW95TB] C:\PROGRA~1\THINKPAD\UTILIT~1\TPW95TB.exe
O4 - HKLM\..\Run: [LexStart] Lexstart.exe
O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [IrMon] IrMon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.exe" -atboottime
O4 - HKLM\..\Run: [NAV DefAlert] C:\PROGRA~1\NORTON~1\NORTON~2\DEFALERT.exe
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NORTON~2\NAVAPW32.exe /LOADQUIET
O4 - HKLM\..\Run: [Norton CrashGuard Monitor] "C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CRASHGUARD\CGMenu.exe"
O4 - HKLM\..\Run: [Norton eMail Protect] C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON ANTIVIRUS\POProxy.exe
O4 - HKLM\..\Run: [Truefonts] C:\WINDOWS\FONTS\fonts.hta
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [CSINJECT.EXE] C:\Program Files\Norton SystemWorks\Norton CleanSweep\CSINJECT.exe
O4 - HKLM\..\RunServices: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.exe
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.exe
O4 - Startup: Norton System Doctor.lnk = C:\Program Files\Norton SystemWorks\Norton Utilities\SYSDOC32.exe
O4 - Startup: CleanSweep Smart Sweep-Internet Sweep.lnk = C:\Program Files\Norton SystemWorks\Norton CleanSweep\csinsm32.exe
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O13 - DefaultPrefix: http://www.hugesearch.net/search.php?qq=
O13 - WWW Prefix: http://www.hugesearch.net/search.php?qq=
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {5A3C6507-730A-43B2-8EAC-4C430F2EF35E} (PortfolioManager Class) - https://portfoliomanager.westpac.com.au/portfoliomanager/portfoliomanager.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37869.6534490741



Sponsored Link
Ads by Google

Response Number 1
Name: Spywareinfo.com
Date: December 8, 2003 at 23:19:11 Pacific
Reply:

Fix all R0 and R1 lines, this

O13 - DefaultPrefix: http://www.hugesearch.net/search.php?qq=
O13 - WWW Prefix: http://www.hugesearch.net/search.php?qq=

Reboot


0

Response Number 2
Name: Klomp
Date: December 8, 2003 at 23:41:54 Pacific
Reply:

Thanks. But unfortunately it didn't work. When I reboot, hugesearch.net has returned!!!


0

Response Number 3
Name: Spywareinfo.com
Date: December 8, 2003 at 23:55:33 Pacific
Reply:

Add this

O4 - HKCU\..\Run: [QuickTime Task] c:\windows\qttasks.exe
O4 - HKLM\..\Run: [Truefonts] C:\WINDOWS\Fonts\fonts.hta


0

Response Number 4
Name: sxshep
Date: December 9, 2003 at 14:57:06 Pacific
Reply:

Have you tried CoolWebShredder
Might not be a bad idea, seem to be missing the running processes, (the first part of the scan) C:\Windows.... etc.

hth
shep


0

Response Number 5
Name: PaulDadge
Date: December 11, 2003 at 10:48:29 Pacific
Reply:

Hi,

Any luck with this or more info please, I have a user with the same problem. He cannot access any pages at all ?

Thanks

Paul :)


0

Related Posts

See More



Response Number 6
Name: volker wohlfarth
Date: December 11, 2003 at 13:43:11 Pacific
Reply:

hi, i have the same problem and could not access any other page with ie any more. can anyone let me know how i can get rid of this and what can happen. I am now using netscape.
any link to a antivirus programm which solves this problem would be highly welcome.
thanks,
volker


0

Response Number 7
Name: EmJay
Date: December 11, 2003 at 13:55:37 Pacific
Reply:

I'm also having the same problem... I have tried several different things, but everytime the problem persists upon rebooting.

I would love some info!

Thanks,
EmJay


0

Response Number 8
Name: markalso
Date: December 11, 2003 at 17:57:26 Pacific
Reply:

The script writing changes to the registry is "C:\WINDOWS\FONTS\fonts.hta." Remove this from the Run section of the registry (or use msconfig and uncheck it), reboot, delete it. You will still need to fix the default settings for IE after this. Most of them are mentioned above.

Drop me an email if this helped you. I found no solution to this problem on the 'net while fixing my friend's computer.


0

Response Number 9
Name: Sariss
Date: December 12, 2003 at 09:34:20 Pacific
Reply:

This happened to my brother's 3-day old puter. After being on hold with the HP tech for about 30 mins, I found out that it is a new trojan, and the only way to completely remove it as of now is to do a destructive reinstall. You absolutely must wipe your entire drive. If your backups are on your drive already, you will need to have backup disks so that your entire drive can be wiped, else you won't get rid of it.


0

Response Number 10
Name: jartoons
Date: December 13, 2003 at 06:57:17 Pacific
Reply:

DON'T WIPE YOUR HARD DRIVE !!!!!
"Cool Web Shredder" in response # 4 works like a dream. I have my computer back!

Run it twice, restarting each time. Hugesearch.net and cool web are trojans.


0

Response Number 11
Name: hoschie
Date: December 14, 2003 at 07:16:08 Pacific
Reply:

FIX for W2K

1. save the following regscript file as "regfix.reg"
------
Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=""
"Default_Search_URL"=""
"Search Page"=""
"Start Page"="about:blank"

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=""
"Default_Search_URL"="www.google.de"
"SearchAssistant"=""

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs]
"url1"=""
"url2"=""
"url3"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=""
"Default_Search_URL"=""
"Search Bar"=""
"Search Page"=""
"Start Page"="about:blank"


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=""
"Default_Search_URL"=""
"SearchAssistant"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl]
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes]
"www"="http://"


2. run script at DOS prompt
"regedit /s regfix.reg"

all hugesearch entries are removerd now. you can include this script into a logon script to avoid this (or similar) trojans.

cheers hoschie



0

Response Number 12
Name: Maverick1
Date: December 14, 2003 at 09:59:55 Pacific
Reply:

DO NOT reformat your drive. This is an attempt by you hardware vendor to get you off their backs. It really isn't their problem so i can't really blame them for trying. This is a trojan virus as mentioned above . Hopefully you have a decent anti-virus program which came with your computer or you have purchased. Get the latest virus definitions from their update site and run the scan. This should catch this virus and quaranteen the file. Once it captures this , go ahead and run Cool Web Shredder, this shoulf restore you original IE home page info. If not, do it manually through Tools>>Internet Options in your IE tool bar. Hope this helps.


0

Response Number 13
Name: somekid
Date: December 14, 2003 at 19:17:10 Pacific
Reply:

I have recently received this virus and I noticed that I was only redirected to the huge search site if I didn't type in the http. Example: typing www.yahoo.com would lead to the huge search site but typing http://www.yahoo.com would lead me to the yahoo site. At least you can still search the web while trying to fix your problem


0

Response Number 14
Name: Bill
Date: December 17, 2003 at 16:53:28 Pacific
Reply:

Alright, im not too good with computers and im trying to get this off. Im stuck with the hugesearch b/s and im completly clueless as to what you guys are talking about half the time. I scanned my comp with McAfee(came with the dell) and i deleted it and it doesnt say any files are infected but its still friggin here. pleaseee help


0

Response Number 15
Name: donM05
Date: December 17, 2003 at 21:59:41 Pacific
Reply:

Thanks everyone... I finally got it wiped out
I couldnt get the script to run in post11 but used regedit and did it maually... also dont forget to clean out the fonts.hta file in windows/fonts.. it would not delete so I just used edit and gutted it..

thanks and merry xmas
dm


0

Response Number 16
Name: deejedi
Date: December 18, 2003 at 00:25:54 Pacific
Reply:

Send email to deejedi@aol.com & I will send info how to fix them in the registry.

8-)


0

Response Number 17
Name: Vinnie M
Date: December 18, 2003 at 07:12:51 Pacific
Reply:

Got It out this way , Have windows 98

1- Start
2-Run
3-Type Msconfig
4-click on start up
5-Look for True Fonts C:\windows\fonts\fonts.hta

6-uncheck True fonts
7- restart PC

This did it for me, Try Merry X-mas ! :)


0

Response Number 18
Name: guenter
Date: December 18, 2003 at 07:42:49 Pacific
Reply:

Hi,

I had the same problem today:

REGEDIT -> HKLM->SOFTWARE->MICROSOFT->WINDOWS->CURRENT VERSION->URL
->DefaultPrefix remove all keys here
->WWW replace the "hugesearch.net" with a simple "http://".
Your Homepage/Startpage can be changed in the options menue of the IE.

B.T.W., I got that b---tard who rented the domain "hugesearch.net":

He lives in Norway, his name is Ernesto Hans:
Gepplyngun 24
Alta NG 9514

His private email is:
ernesto@zeos.net
The website email is:
support@hugesearch.net

Come on guys, send him some mail and tell him what you think about this new type of SPAM !
If somebody lives close to this place, go over and kick his ass, the 10th time with best regards from me.


0

Response Number 19
Name: mary2004
Date: December 18, 2003 at 20:56:08 Pacific
Reply:

Dear guenter:
Your message from
Date: December 18, 2003 at 07:42:49 Pacific
solved my problem and made my X mas, so THANK YOU and merry xmas to you and all people on here that are spending your time and energy to help out.
much luv to u all
Mary



0

Response Number 20
Name: BillsBlaster
Date: December 20, 2003 at 19:55:03 Pacific
Reply:

Still clueless .... did what vinnie M said, but couldnt find True fonts only fonts... unchecked it and restarted and its still here


0

Response Number 21
Name: ovidduke
Date: December 20, 2003 at 21:17:11 Pacific
Reply:

I got the same prob. How many downloaded a Comet cursor lately. I think this is where it came from and after a bit of investigating I found out they were found to be full of spyware, etc.
I went to internet options and change my opening page to about:blank, hey AOL sucks but some times drastic measures are required. At least now it can't seem to change itself back to www.hugepaininthebutt.net


0

Response Number 22
Name: down_with_the_king
Date: December 21, 2003 at 12:30:41 Pacific
Reply:

dear all,

halo guenter, i follow your suggestion :

REGEDIT -> HKLM->SOFTWARE->MICROSOFT->WINDOWS->CURRENT VERSION->URL
->DefaultPrefix remove all keys here
->WWW replace the "hugesearch.net" with a simple "http://".

But when i reboot my Computer, the "Hugesearch" still my IE, .... any idea guenter, or i miss something in regedit ..??

cheers,


0

Response Number 23
Name: bullit120
Date: December 22, 2003 at 23:36:56 Pacific
Reply:

hello down_with_the_king,

extended version:

START->RUN->REGEDIT
search for "hugesearch" and delete the content of all keys that come up.

I remember that there were also entries in the HKCU, but they were gone after a reboot on my PC.

Mr. Hans was reported to the Norwegian police, so this kind of SPAM should disappear soon...


0

Response Number 24
Name: down_with_the_king
Date: December 31, 2003 at 01:34:03 Pacific
Reply:

thanks all,

Guenter, thanks for your help
my problem solved now, i use :
- Ad-Aware 6.1 and
- CoolWebShredder ...

and everything is back to normal, now ....

thanks all, & happy new year ...

cheers,


0

Response Number 25
Name: seek2bwise
Date: January 1, 2004 at 22:51:46 Pacific
Reply:

I got highjacked tonight. Responce # 11 by hoschie and responce #23 by guenter were perfectly effective and helpful in restoring my Win2K PC to normal. Thank you very much.


0

Response Number 26
Name: JohnnyBG
Date: January 5, 2004 at 10:33:39 Pacific
Reply:

Hi,

As an extra to this good news: I discovered the same combination of two things in the hijack-log above on my own system.

The first was the file "fonts.hta" in the [Windows]/Fonts/ -directory, which runs at every boot.
The second was the change into freshvideogals.com for the start/search/etc. page.
Looking into the file fonts.hta pointed out that this file was the reason of the hijack.

Filext.com says it's a 'hypertext application file'. Me being no expert, I leave that for what it is worth and be just happy with the result... Finally.

JBG.


0

Response Number 27
Name: Tags
Date: January 9, 2004 at 08:36:36 Pacific
Reply:

Note to RESPONSE 11

This key should properly read:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
@="http://"

So that http:// will be prepended to all subdomains when typed in the address bar.


0

Response Number 28
Name: Hardstyler
Date: January 11, 2004 at 15:49:07 Pacific
Reply:

Hello!

I have a problem with hugesearch. I can't start regedit to clean the registry, I can't change the startside in IE and I can't change the desktop build whitch I want. When I do one of this things, my computer says: This is stopped by the administrator. What's this? What can I do, to delete this spyware???

Greetz Benson


0

Response Number 29
Name: Free Again
Date: January 14, 2004 at 22:51:53 Pacific
Reply:

Thanks Hoschie, Guenter and all of the others who found a way to get rid of this Hugesearch disease.

I used Start -> Run -> Regedit in XP and made all the suggested changes.

I just restarted my computer and it works great (fingers crossed the fix is permanent).

For anyone still having trouble, once you run Regedit you can go through all the recommended folders same as you would for a document search using Explore. Then right click on the items listed by Hoschie and click modify. Enter "=" or alternate such as yahoo. Either way you are clearing the previous value which is "hugesearch.net"

Probably the most important one to change is URL/Prefix, set "www" = http:// ; but it's worth going through all the suggested items to see what other sites have invaded your system.

Thanks again, and good luck!


0

Response Number 30
Name: kamandi
Date: January 15, 2004 at 11:52:09 Pacific
Reply:

@Tags - Response 27

I followed all of the necessary steps and cleaned both the registry and (hopefully) my weblife from hugesearch.

But...

Now whenever I type a non-www url without the http header, a pop up appears telling me that IE doesn't recognize the url.

Example:

Previously if I typed "doom9.org", IE automatically added "http:\\" and re-directed me to "http://doom9.org".

Now if I type "doom9.org" (without the http://) an "impossible to find doom9.org" IE pop-up appears.

I'm referring to Response 27, b/c the only registry change I wasn't able to do was this one:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
@="http://"

At the moment, I just have one string: "Predefined" (sorry, don't know the right term in english; my XP is in italian). This "Predefined" string has no value.

What does "@" mean? "All" values? What exactly do I have to type into Regedit?

Excuse me for my newbieness. ^___^

Andrea


0

Response Number 31
Name: carlfox
Date: January 15, 2004 at 13:43:36 Pacific
Reply:

Thanks for all the tips Responce # 11 by hoschie worked very well and even sorted http:// www. errors

Can anyone recommed what will rpevent this happening in future. Should I invest in firewall software?


0

Response Number 32
Name: patrickxzxzxzx
Date: January 31, 2004 at 20:55:34 Pacific
Reply:

I found the answer to all my computer problems, including "Hugesearch". My brother's computer was infected, but I had previously set him up with a backup hard drive which I cloned from his main drive, using Norton "Ghost". He told me about his "Hugesearch" problem, so, I cloned his backup drive back to the main drive, and it restored everything back to the way it was before infection. I used to unplug the power cable to the backup drive to prevent infection(dead drive can't be infected), but now I use something called a "drive switch" which I bought for 20 bucks from an "ebay store" seller(Eureka Engineering), and I don't have to open the computer case to unplug the power cable. I just flip a switch at the back of my computer now(best thing I ever did!!!!!). Check out the switch at ebay stores and their info on how to do the clone thing. Unbelievable!!!!!!! My brother's computer was back up in 12 minutes flat!!! This idea will fix anything! I don't even run anti-virus software anymore. No more constant updating of dat files, etc. I know this doesn't help people who are already infected, but once you get "clean", get a backup hard drive and clone it. You'll love it!!!!


0

Sponsored Link
Ads by Google
Reply to Message Icon

Windows/Norton Woes Cannot melda virus



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: hugesearch.net homepage hijack

Global-Finder Homepage Hijack fix www.computing.net/answers/security/globalfinder-homepage-hijack-fix/6544.html

Homepage Hijack: in.webcounter.cc www.computing.net/answers/security/homepage-hijack-inwebcountercc/8174.html

Windows95 Homepage Hijack Solution www.computing.net/answers/security/windows95-homepage-hijack-solution/12543.html