»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 02-08-2004, 12:02 PM   #1 (permalink)
Naz
Registered User
 
Join Date: Nov 2001
Location: Florida
Posts: 184
Naz is on a distinguished road
IE address bar going crazy

when I type something into my address bar such as www.techimo.com it is automatically changed to http://www.smart-finder.biz/www.techimo.com
The only way around it is to type http://www.techimo.com then it goes to the site. why is it doing this and how can I fix it?
Thanks for you help! Naz

Naz is offline   Reply With Quote
Old 02-08-2004, 12:06 PM   #2 (permalink)
Registered User
 
Join Date: Apr 2002
Location: Albany, Ga.
Posts: 1,063
no1_vern is on a distinguished road
Download and run ad-aware Here: http://www.lavasoftusa.com/software/adaware/

And if that doesnt work try spybot (spyware removal tool):
http://www.emm.ie/freeware/Windows_N...ps_scripts.htm
no1_vern is offline   Reply With Quote
Old 02-08-2004, 12:07 PM   #3 (permalink)
Registered User
 
Join Date: Feb 2002
Location: midvale, utah
Posts: 1,296
Jeordiewhite is on a distinguished road
Send a message via ICQ to Jeordiewhite Send a message via AIM to Jeordiewhite Send a message via Yahoo to Jeordiewhite
Sounds like your browser was hijacked you will need to run Browser Hijack Blaster also try ad aware and spybot search and destroy
that should take care of your problems for now. just keep them updated and ran once weekly atleast, you should be fine
Jeordiewhite is offline   Reply With Quote
Old 02-08-2004, 12:10 PM   #4 (permalink)
Registered User
 
Join Date: Apr 2002
Location: Albany, Ga.
Posts: 1,063
no1_vern is on a distinguished road
Found out this has been seen before : http://www.computing.net/windowsme/w...rum/40497.html

Is your antivirus up to date?
no1_vern is offline   Reply With Quote
Old 02-08-2004, 12:14 PM   #5 (permalink)
Registered User
 
Join Date: Apr 2002
Location: Albany, Ga.
Posts: 1,063
no1_vern is on a distinguished road
Approx date first sighted: January 11, 2004
Log reference: http://forums.spywareinfo.com/index....73&hl=nkvd\.us
Symptoms: IE hijacked to nkvd.us and smart-finder.biz, redirections to nkvd.us and smart-finder.biz when typing incomplete URLs into address bar.
Cleverness: 10/10
Manual removal difficulty: Involves some registry editing, and renaming the trojan file, restarting, and deleting it
Identifying lines in HijackThis log:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.nkvd.us/s.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.nkvd.us/s.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.nkvd.us/s.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nkvd.us/1507/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nkvd.us/s.htm
O13 - DefaultPrefix: http://www.nkvd.us/1507/
O13 - WWW Prefix: http://www.nkvd.us/1507/
O13 - Home Prefix: http://www.nkvd.us/1507/
O13 - Mosaic Prefix: http://www.nkvd.us/1507/

Additional line in StartupList log:

Enumerating ShellServiceObjectDelayLoad items:

DDE Control Module: C:\WINDOWS\SYSTEM\mtwirl32.dll


This variant was surprisingly smart: it used two startup methods (ShellServiceObjectDelayLoad and SharedTaskScheduler) that have to be the absolutely rarely used ones seen ever - and it used them differently on Windows 9x/ME and Windows NT/2k/XP. On top of that, both methods ensure that the file is loaded when Explorer is loaded, making it always in memory like CWS.Msconfd. Additionally, the actual responsible files are invisible in HijackThis, and only one shows in a StartupList logfile (ShellServiceObjectDelayLoad). The responsible file is mtwirl32.dll, and to delete it manually you need to rename it (deleting is impossible since it is in use), restart the system, and then delete the file and its Registry key.

Thanks to cwshredder for the info,

(From page previously posted)

Good luck
no1_vern is offline   Reply With Quote
Old 02-09-2004, 06:55 AM   #6 (permalink)
Junior Member
 
Join Date: Jan 2004
Posts: 0
whitebeard21 is on a distinguished road
This fixed mine too.


-------------------------------------------------------------------------------
Originally posted by scotlandtb
I had a similar problem with one of the pcs I deal with here at work and I could not get rid of it with ad-aware. I eventually googled the problem and came up with this site

http://www.spywareinfo.com/~merijn/cwschronicles.html

go there download the shredder problem he has and it will solve your problem (it did for me and it cam up for 4-counter also so you should be set).

Hope this cures you

Steve
whitebeard21 is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 04:03 PM.