IEXPLORE.EXE redirected to 0749.com or 13721.net

My internet explorer was re-directed to http://www.0749.com. I removed a few links in registry like: “…iexplore.exe” http://www.0749.com. Then I started IE, it was redirected to 13721.net instead. I deleted everything I found in registry about this address. But it still did that.

I have Norton Antivirus, but it can’t detect anything.

Finally, I found a suspicous file in the IE folder: 1802120223.dat. I changed the name. Then the problem was gone. Obviously, this file is called by IE, which is marked in registry.

Then I found a key in registry:

[HKEY_CLASSES_ROOT\CLSID\{18021223-2011-0295-951B-9EA34E34E8CC}\InprocServer32]
@=”1802120223.dat”

If I remove this key and have the file there, there won’t be any problem either.

That’s why people can’t recognize. But the antivirus software is supposed to recognize it.

view.atdmt.com spyware removal

I kept getting ‘Sorry, we couldn’t find http://view.atdmt.com/MSR/iview/yhxxxlam0010000079msr/direct%3Bwi.728%3Bhi.90/01/%3Ftime”  with IE7.

I found a few solutions. Check which one works for you.

1. Run regedit, search for atlassolutions. Remove it and that will fix the problem.

2. IE->Tools->Manage Add-ons->Enable or Disable Add-ons

Find CBrowserHelper under names and highlight it (the publisher should be Dell). Then select “disable” in the “Settings” box on the bottom left side. OK and close IE.

3. Window Key + E to oepn file browser -> Tools->Folder Options->Tab View->Show hidden files and folders. Then go to C:\Documents and Settings\User Name\Local Settings\Temp, delete all files. You can also go to the current user temp folder by run  %temp%.

4. Create a .reg file with the following content and run:

REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
“Do404Search”=hex:01,00,00,00
“Search Page”=”http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch”
“Search Bar”=”http://search.msn.com/spbasic.htm”
“Use Custom Search URL”= dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
“{CFBFAE00-17A6-11D0-99CB-00C04FD64497}”=””

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
“”=”http://home.microsoft.com/access/autosearch.asp?p=%s”
“provider”=””
” “=”+”
“&”=”%26”
“+”=”%2B”
“#”=”%23”
“?”=”%3F”
“=”=”%3D”

[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main]
“Search Page”=”http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch”
“Search Bar”=”http://search.msn.com/spbasic.htm”

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
“SearchAssistant”=”http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm”
“CustomizeSearch”=”http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm”
“Default_Search_URL”=”http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch”

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
“Default_Search_URL”=”http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch”
“Search Page”=”http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch”

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
@=”http://”

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL\Prefixes]
“ftp”=”ftp://”
“gopher”=”gopher://”
“home”=”http://”
“mosaic”=”http://”
“www”=”http://”

Source:

http://forums.techguy.org/malware-removal-hijackthis-logs/432534-view-atdmt-com-spyware-removal.html
http://forums.majorgeeks.com/showthread.php?t=62461

The 2nd solution for CBrowserHelper fixed my problem.

Show hidden files and folders

 

I got a problem with my computer. I can’t show hidden files and folders. If I choose “Show Hidden Files and Folders”, it will be change back to “Do Not …” . I did a search on the Net. The second solution solved my problem.

Solution 1:

  1. Start->Run->Regedit
  2. Go to:

//HKEY_CURRENT_USER//SoftWare//MicroSoft//Windows//CurrentVersion//Explorer//Advanced

  1. Set key Hidden = 1
  2. Refresh

Solution 2:

If you got RavMon virus etc, you may need this.

  1. Start->Run->Regedit
  2. Go to:
     

    HKEY_LOCAL_MACHINE//SoftWare//MicroSoft//Windows//CurrentVersion//Explorer//Advanced

  3. SET DWORD key CheckedValue = 1If it’s not DWORD value, delete it and recreate as DWORD value and set it to 1.
  4. Refresh