This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ie Hijacked By Url: - A-search.biz/?wmid=1010

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here is my log. My IE home page has been hijacked on start up only and replaced with a-search.biz/?wmid=1010 If I click home after this my proper home page will come up. Other/ funny things happening to computer since this - i.e. Page freezing, etc. PLEASE HELP StartupList report, 15/10/2004, 3:24:24 PM StartupList version: 1.52 Started from : C:\Documents and Settings\Scott Scarrow\Desktop\HijackThis.EXE Detected: Windows XP SP1 (WinNT 5.01.2600) Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106) * Using default options ================================================== Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Netscape\Netscape\Netscp.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\System32\CTsvcCDA.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\wuauclt.exe C:\Documents and Settings\Scott Scarrow\Desktop\HijackThis.exe ————————————————– Checking Windows NT UserInit: [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] UserInit = C:\WINDOWS\SYSTEM32\Userinit.exe, ————————————————– Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run (Default) = mswspl = ————————————————– Shell & screensaver key from C:\WINDOWS\SYSTEM.INI: Shell=*INI section not found* SCRNSAVE.EXE=*INI section not found* drivers=*INI section not found* Shell & screensaver key from Registry: Shell=Explorer.exe SCRNSAVE.EXE=C:\WINDOWS\System32\logon.scr drivers=*Registry value not found* Policies Shell key: HKCU\..\Policies: Shell=*Registry key not found* HKLM\..\Policies: Shell=*Registry value not found* ————————————————– Enumerating Task Scheduler jobs: Norton AntiVirus - Scan my computer.job Symantec NetDetect.job ————————————————– Enumerating ShellServiceObjectDelayLoad items: PostBootReminder: C:\WINDOWS\system32\SHELL32.dll CDBurn: C:\WINDOWS\system32\SHELL32.dll WebCheck: C:\WINDOWS\System32\webcheck.dll SysTray: C:\WINDOWS\System32\stobject.dll ————————————————– End of report, 2,864 bytes Report generated in 0.047 seconds Command line options: /verbose - to add additional info on each section /complete - to include empty sections and unsuspicious data /full - to include several rarely-important sections /force9x - to include Win9x-only startups even if running on WinNT /forcent - to include WinNT-only startups even if running on Win9x /forceall - to include all Win9x and WinNT startups, regardless of platform /history - to list version history only
Here's how to post a Hijack This log

Download "HijackThis" here
When downloading, choose "save to disk" and NOT open!

Now create a new folder for it, C:\Hijackthis, for example.
After unzipping the file. to C:\Hijack This, you'll end up with the file itself, which is Hijackthis.exe, and that's the one you'll need to doubleclick.'

When the program launches, hit the "Scan" button
When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, and save the log anywhere you like.

Now if you doubleclick the log file.Go to Edit > Select all, then to Edit > copy.
Now you've copied the entire text to the Windows Clipboard (this happens behind your back.)

Next, go back to this forum thread, and click "Add Reply".
In an empty area click your RIGHT mouse button, and choose 'Paste' from the context menu.
There's your Hijack This log.
Thanks Little Eagle Is this better? Can you help me out? Thanks in advance. Logfile of HijackThis v1.97.7 Scan saved at 10:52:14 AM, on 17/10/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\System32\CTsvcCDA.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Netscape\Netscape\Netscp.exe C:\Documents and Settings\Scott Scarrow\Desktop\HijackThis.exe N3 - Netscape 7: user_pref("browser.startup.homepage", "http://sympatico.msn.ca/"); (C:\Documents and Settings\Scott Scarrow\Application Data\Mozilla\Profiles\default\5gwlde8y.slt\prefs.js) N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\Scott Scarrow\Application Data\Mozilla\Profiles\default\5gwlde8y.slt\prefs.js)
Logfile of HijackThis v1.98.2 Scan saved at 12:00:56 PM, on 17/10/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\System32\CTsvcCDA.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Netscape\Netscape\Netscp.exe C:\PROGRA~1\WINZIP\winzip32.exe C:\Documents and Settings\Scott Scarrow\Local Settings\Temp\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank N3 - Netscape 7: user_pref("browser.startup.homepage", "http://sympatico.msn.ca/"); (C:\Documents and Settings\Scott Scarrow\Application Data\Mozilla\Profiles\default\5gwlde8y.slt\prefs.js) N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\Scott Scarrow\Application Data\Mozilla\Profiles\default\5gwlde8y.slt\prefs.js) O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O18 - Protocol: intu-res - {9CE7D474-16F9-4889-9BB9-53E2008EAE8A} - C:\Program Files\Common Files\Intuit\intu-res.dll
http://securityresponse.symantec.com/avcen…moval.tool.html
Run this scan, save the log.And post it also.

Then then unzip and run CWShredder to clean up clicking "FIX" to have it remove all it finds.

CWShredder available from these places :-

http://www.zerosrealm.com/downloads.php
Or this as a full download without any unzipping required
http://www.downloads.subratam.org/CWShredder.exe

We have found that some of the CWS infections can be removed better from safe mode, rather than normal mode.
To get to safe mode use the F8 key while booting the machine. Detailed instructions from here :-
http://service1.symantec.com/SUPPORT/tsgen…001052409420406

Close all Browser and Program Windows and have HijackThis fix the following.
Do this by checking the box beside each and then clicking on Fix checked.
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

Then post another log.
Thanks again Little Eagle. Please post the security response url as the page comes up "file not found". Thanks Currently CWShredder comes up emtpy. S
The backdoor removal tool did not locate anything. Here is my current Hijack log. Logfile of HijackThis v1.98.2 Scan saved at 2:56:15 PM, on 19/10/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\CTsvcCDA.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Netscape\Netscape\Netscp.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Microsoft Office\Microsoft Office\Office10\EXCEL.EXE C:\Program Files\Adobe\Illustrator 10\Support Files\Contents\Windows\Illustrator.exe C:\Palm\palm.exe C:\Program Files\Microsoft Office\Microsoft Office\Office10\WINWORD.EXE C:\Documents and Settings\Scott Scarrow\Desktop\HijackThis.exe N3 - Netscape 7: user_pref("browser.startup.homepage", "http://sympatico.msn.ca/"); (C:\Documents and Settings\Scott Scarrow\Application Data\Mozilla\Profiles\default\5gwlde8y.slt\prefs.js) N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\Scott Scarrow\Application Data\Mozilla\Profiles\default\5gwlde8y.slt\prefs.js)
I have two viruses 1. cocinbcj.dll - Trojan Start Page Virus that I can not figure out how to delete from my System file 2. aifind.info Logs look good - sure… but I still have the homepage hijack and other issues. THANKS ALOT S
I managed to get rid of cocinbcj.dll by using KillBot. aifind.info remains. Can you help with this??? Even if I use adware to delete it… it comes back. Here is what it says about adaware: Possible Browser Hijack attempt RegKey Vulnerability HKEY_CURRENT_USER:Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\aifind.info\ Trusted zone presumably compromised : aifind.info Thanks. S
1. Please download DllCompare here

2. Start the Program with its default settings and put a check mark in the include subdirectories. Click the Run Locate.com and wait until the scan says complete.

3. Click the Compare button to start the next process.

4. Files in the upper portion have been verified to "exist", Files in the bottom section were not able to be accessed. Very few files should be listed in the bottom section when the Compare scan is complete.

5. Click on each of the listed entries in the lower section to select them. Right-click on the file and use the Option Rescan.

6. This will cause Windows Find to see if the file does exist, and then it will be removed from the list (to reduce the number of identified files)

7. Click the Make a Log of what was found button, and post the log here in this thread using Add Reply
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.


To help keep you clean follow the recommendations in Tony's article here:
So how did I get infected in the first place?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI