Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

fastSearch.cc autoset as homepage 6

Status
Not open for further replies.

maryWhite

Programmer
Nov 30, 2003
4
CA
Hi,
The site fastsearch.cc has setup itself as my home page in IE.
I already run Spybot and it removed some spyware, but still fastsearch remains as the home page and no the one I have set as home page.

Is there any other procedure I can execute to get ride of it?

Thanks
Mary
 
Did you try specifying your desired home page in Tools/Internet Options/General/Home Page?
 
Hi ski!
Yes, I already try specifying my home page. I get my specified home page until I reboot my PC.
Whe the PC restart and I access IE, fastsearch.cc has been reset as home page.

Thanks
Mary
 
Check your startup menu to see if there's anything there that loads that website.
If so, then just disable it.
 
Go here and read the "Hijack removal" section

Then download from here
(a mirror) and read on how to use...



TT4U

Notification:
These are just "my" thoughts....and should be carefully measured against other opinions....I try very hard to impart correct info at all times.
 
Hi!
Thank you all for you input.
I cleaned the little bugger :)

Thanks
Mary.
 
Hi Mary,

I'm not tech-savvy, and I've got the same problem from those pieces of scum at fastsearch.cc. Could you tell me exactly how you got rid of it? Thanks.
 
Let hijackthis take away theese:


R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank...;(obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = (obfuscated)
R1 - R1 - HKCU\Software\Microsoft\Internet Explorer,Search = (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = (obfuscated)
 
Tip to every body reading this thread!

Protect your PC , Only Antivirus isn't enough.

Download install/update spywareblaster.
Download/install/update spywareguard (protects from browser and homepage hijacks)

And
Spybots immunize feature
Download install/update spybot.
Configure it to enable the immunize feature.
 
All these;
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Program%20Files/Internet%20Explorer/teachers.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank...;(obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer,Search = (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = (obfuscated)


O13 - DefaultPrefix: O13 - O13 - WWW. Prefix:
and there may be more here....get rid of these first and see if the problem subsides

the ActiveX controls below allow code to run without you knowing.....
i know that most of all else is OK, however, there may be something in your log that is re-infecting the machine...


TT4U

Notification:
These are just "my" thoughts....and should be carefully measured against other opinions....I try very hard to impart correct info at all times.
 
I forgot to post the activeX

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) -

TT4U

Notification:
These are just "my" thoughts....and should be carefully measured against other opinions....I try very hard to impart correct info at all times.
 
I got this nasty hijacker about two weeks ago and have been pulling my hair out trying to get rid of it. I tried everything I could think of to get rid of it and everytime I thought I got rid of it, it would come back. I did a google search on fastsearch.cc and found this forum, and would like to thank all those who have posted all the valuable information that gave me the advantage to finally defeat this nasty thing. I finally got rid of it using CWSredder. Thanks to everyone who posted information. Oh, and this is a great web-site.
 
Thanks Carr. I found this page via a search engine. I had no idea this many people were having problems with this fastsearch crap.

I'd like meet one of those SOB's in an alley!

Thanks for your help.

 
Hello there,

I'm currently running Windows 2000, and have experienced similar problems to everyone else in this forum...
I downloaded HiJack This and removed the appropriate strings from the Scan result...

Still remaining however is the soundmx.exe file. I'm fairly certain this is linked in some way... My Virus Checker picks it up but cant delete/quarantine it.

Can someone help?
 
Does windows allow you to rename the extension of it .
(it usaully does).
This prevents load at next boot, so you can delete the
file and the run entry in registry .



 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top