Computing.Net > Forums > Security and Virus > cannot change internet homepage

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

cannot change internet homepage

Reply to Message Icon

Name: ln187347
Date: February 6, 2004 at 05:29:40 Pacific
OS: XP
CPU/Ram: amd 256mb
Comment:

Hi there,

I have a frustrating problem and have searched for nformation on it. I cannot change my homepage. it is permanently stuck on http://www.magicsearch.ws. I have tried the hijackthis software, cwshredder, adware 6 and spybot. However i cannot get rid of the files which have buried into my computer. Hope you can help, many thanks inadvance!!



Sponsored Link
Ads by Google

Response Number 1
Name: mamabear
Date: February 6, 2004 at 05:54:03 Pacific
Reply:

If you've already tried cleaning up with AAW or SB, post your HijackThis scan log here and someone will look at it.



0

Response Number 2
Name: ln187347
Date: February 6, 2004 at 06:06:49 Pacific
Reply:

This is what was found with HijackThis

Logfile of HijackThis v1.97.7
Scan saved at 12:03:15, on 06/02/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\wt\updater\wcmdmgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Common Files\Services\sistem.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\DOCUME~1\dave\LOCALS~1\Temp\Rar$EX00.616\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://magicsearch.ws/?q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://magicsearch.ws/?q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://magicsearch.ws/?q=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://magicsearch.ws
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://magicsearch.ws
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://magicsearch.ws/?q=
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://magicsearch.ws/?q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://magicsearch.ws
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://magicsearch.ws/?q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://magicsearch.ws/?q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://magicsearch.ws
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://magicsearch.ws/?q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://magicsearch.ws/?q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://magicsearch.ws/?q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = wmplayer.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://magicsearch.ws/?q=
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://magicsearch.ws/?q=
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup
O4 - HKLM\..\Run: [MicrosoftWindows] C:\Program Files\Common Files\Services\sistem.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.exe" /background
O4 - HKCU\..\Run: [MicrosoftWindows] C:\Program Files\Common Files\Services\sistem.exe
O4 - HKLM\..\RunOnce: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" "+b1"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - DefaultPrefix: http://magicsearch.ws/?q=
O13 - WWW Prefix: http://magicsearch.ws/?q=
O16 - DPF: Win32 Classes -
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab


0

Response Number 3
Name: ln187347
Date: February 6, 2004 at 06:31:04 Pacific
Reply:

this site has also enabled websites in my favourites folder which when i try to delete, also just return as soon as they are deleted.


0

Response Number 4
Name: crazyoli
Date: February 6, 2004 at 08:02:35 Pacific
Reply:

Run a search on your hard drive for any files ending with *.hta or *.js. If you find any, open them in notepad or some other text editor and look for the URLs that you have been hijacked to. Any file with those URLs, delete them. Also delete all *.tmp files on your drive; some of them contain malicious code (for e.g. browser hijacks or malware (re)installations). Besides, deleting *.tmp files doesn't hurt, unlike dll's which are also used sometimes for this purpose.


3. HijackThis will list any BHO (Browser Helper Object) installed on your computer. Check the BHOs listed against the list of all known BHOs (http://www.spywareinfo.com/bhos/) maintained at this site by a member of our support forums. If you find one listed as some sort of spyware/malware/hijackware, run HijackThis again and find that BHO in the list. Check its box and have HT fix it.
If you find a BHO that is not included in the list, please make a post in the Browser Hijackings section of our support forums (http://www.spywareinfo.com/bhos/ ) with the HijackThis log pasted in along with an explanation of your problem. Please wait for replies before deleting this BHO, as it may be a new one which I can have added to various spyware/malware cleaning programs. It may also be an innocent file that is not causing your problem, so please wait for advice before deleting it.

4. Now you need to see if there is a startup entry for your hijacker file. The next time you reboot, the hijack might come right back. The reason for this would be an entry in the run section of the registry.
Look in HijackThis for 04 startup items. Check the entries listed against Pacman's List. (http://www.pacs-portal.co.uk/startup_content.php) Items listed as virus, malware, spyware, or something else that is undesirable, put a checkmark next to it and "fix" it.
If you find entries in your log that are not listed, you can report them at the forums (http://forums.spywareinfo.com/?showtopic=628) .
Again, it will be absolutely necessary for you to close all open Internet Explorer windows before any of these changes will take effect. That includes this window. Some changes may even require a log off or even a reboot before they have any effect.
Still not fixed?
I hope this helps anyone who has become a victim of a browser hijack. If it does, great.
If the problem still remains after doing all of the above, you can visit our support forums (http://www.spywareinfo.com/forums/) and post the specifics of your problem there and I or someone else can troubleshoot the problem. Before posting, please make sure you have followed all of the instructions above.



0

Response Number 5
Name: mamabear
Date: February 6, 2004 at 08:33:32 Pacific
Reply:

In addition to other things, you have new.net. Please follow these instructions to remove it completely.
You also have tons of stuff that a full Ad-aware scan (when you click on "scan now", make sure "custom" is checked, not "smart") should take care of. Make sure you're using Build 6.181 (look in the bottom right hand corner)and update your ref files before scanning.


0

Related Posts

See More



Response Number 6
Name: ln187347
Date: February 6, 2004 at 09:36:17 Pacific
Reply:

Hi again, i done everything which was advised, including updating the ref file of AD-aware. This time it found the "magicsearch" files which were buried in my computer. However when i deleted these and tried to run explorer the page is still defaulted to that web page. I checked the registry and the files have reappeared! what can i do now that Ad-aware has found the suspect files? many thanks once again


0

Response Number 7
Name: mamabear
Date: February 6, 2004 at 10:15:28 Pacific
Reply:

My suggestionn would be to post your AAW logfile at the Lavasoft forums explaining what's going on. You have to register there before you can post but it usually doesn't take too long to get a confirmation email. You can get to the forums by clicking on "Team Lavasoft" under my name. How To Post Your Logfile


0

Response Number 8
Name: beb
Date: February 8, 2004 at 01:28:56 Pacific
Reply:

Had the same problem.
A friend of mine who knows a bit more about computers than I do fixed it.

ther is an .exe somwhere that keeps changing your registry entries and favorites back as soon as you delete them or change them. you must delete this first or all your eforts are in vain.

Look here
C:\Program Files\Common Files\Services
if there are some .exe files with official looking names such as directx.exe or exploreer.exe these may be your culprits. I had 4 of them they were all 22K, and their date created was the same time the problem started. Sorry can't rember all the names. See if any of them are running in Proccesses in your task manager (ctrl+alt+del). Try ending any that are running. See if your registry and favorites still change themselves back now.

don't know if they will be in the same place for you.

hope this was helpful :-)



0

Response Number 9
Name: avkvprasad
Date: February 8, 2004 at 13:17:30 Pacific
Reply:

Here is what WORKED for me.
I downloaded StartupCPL from download.com It shows all the programs that are registered to start up with windows.
In that you will find "c:\Program Files\Common Files\Services\time.exe". But wait, even if you delete it, it comes back in 10 seconds. So, open up task manager, delete the process time.exe first. Then, go back and delete time.exe from all start up programs. Now if you restart the machine, the monitoring worm will not start. Now go back and revert all the entries like IE home page etc.,

This was one tough worm to get rid off.


0

Response Number 10
Name: gom
Date: February 8, 2004 at 16:34:32 Pacific
Reply:

I did a similar thing to Prasad. Like he said this was one biatch of a worm. The creator is lucky I'm no Leet hacker otherwise I'll be hacking his ass off! Anyways, access your currently running tasks (ALt Ctrl Del will also do) and close anything that you don't need. Also check your startup programs (run msconfig.sys on windows ME, or use third part programs. I use Spybot on XP) and uncheck all the stuff you don't need. If you are not sure find that particular file and check properties and see where it is from.

I then deleted ALL the exe files in c:\Program Files\Common Files\Services\, because there were more than one worm! ALL WERE ABOUT 22 kb. ALso stopped auto restore function in settings and cleaned the RESTORE folder as well and TMP folders. I then ran HijackThis, and removed all the magicserver entiries AND any reference to above folder. Change your homepage to other than Magicserver in explorer. CLoseprogram and restart computer. It should be GONE!


0

Response Number 11
Name: tgbg
Date: February 9, 2004 at 17:07:25 Pacific
Reply:

This was a hard one to get rid of.
It also hides itself in windows/system32/
under names such as:
sistem.exe
iexplorer.exe
and some other names, check dates and size and you will find them.

some are impossible to delete with ordinary methods. I renamed them to someting like 123.abc so as to prevent anything to start them.

If I ever get hold of the guy who made this; well I have frinds i low places.



0

Response Number 12
Name: wildmonkey182
Date: February 9, 2004 at 18:32:22 Pacific
Reply:

I've used this site to fix countless programs on my computer, and I had this same problem. I used your guys' suggestions, and got rid of the worm. I can't say thank you enough. I went into C:\Program Files\Common Files\Services and found 8 .exe files that were all 21 kb and were created the day that the problem started. I deleted them all (for some I had to CTRL+ALT+DEL and end the program) and emptied the trash. Then I went into the registry editor and searched for all files containing "magicsearch". I deleted all the files and the problem was gone.

THANK YOU THANK YOU THANK YOU!!!!!!!!!
The people on these forums are the best!

Reed Strickland


0

Response Number 13
Name: RobScott
Date: February 9, 2004 at 18:45:28 Pacific
Reply:

ok i have had the same problem for over a month and i cant seem to fix it. Im glad i finally found somepeople who have experienced what i am CUZ THIS IS SO ANNOYING!!!! but ya i looked in the C:\Program Files\Common Files\Services folder and i have NO .exe files!!! i am so upset cuz like i havent tried the first part of this discussion because it doesnt appear to be working for other people, now i havent done a registry search because unfortunately im unaware on how to do so. Im in university right now, first year, and i use my computer ALL THE TIME!! like not even norton anti virus or the rez anti virus have been much help whatsoever. What other folders could i check for these .exe files or how do i search my registry????

Anywayz i know misery loves company so im actually happy im not the only one who has gotten this although i feel for every one of u. Ive been coping but still there comes a point where i want to take a hammer to my computer and beat the living crap out of it hahahaha. anywayz if someone could please help me that would be great


0

Response Number 14
Name: s3000
Date: February 9, 2004 at 19:46:53 Pacific
Reply:

search folder: C:\Program Files\Common Files\Services
file : users32.exe
rename or delete it


0

Response Number 15
Name: Rei
Date: February 9, 2004 at 20:21:56 Pacific
Reply:

i have the same problem
theres actually a guy whos dedicated to killing this trojan. his homepage is here:

http://www.merijn.org/cwschronicles.html
or
http://216.180.233.162/~merijn/index.html



0

Response Number 16
Name: Carbide
Date: February 9, 2004 at 21:21:18 Pacific
Reply:

I had the same problem. Thanks for the help. I actually had 15 files in the … /Services directory, all 22K and Feb 3rd. There was no Time.exe running in the task manager though. Through a bit of trial and error I found the match between one of the 15 files. It was “window”. The 15 files included a lot of common looking files including, directx.exe, directx32.exe, explore.exe, iexplore.exe, time.exe, uninstall.exe, win32.exe, window.exe, winmngt.exe, win32e.exe, user32.exe, etc.

Finished it off by doing a search in regedit for the “magicsearch” URL and changed them back to my preferred page. Everything seems fine now.

Thanks again for the help.

rob


0

Response Number 17
Name: RobScott
Date: February 9, 2004 at 21:27:11 Pacific
Reply:

hahah u post the web page and i cant even go to it lol.

Anywayz as i said before. I HAVE NO FILES IN THE SERVICES FOLDER so i dont understand it, where could it be man???? this is annoying to no extent. Im going to search for those files and see if i can find them in the same folder, ill delete them from that one but i have no files in that folder man


0

Response Number 18
Name: tgbg
Date: February 10, 2004 at 15:04:07 Pacific
Reply:

They dont have to be in C:\Program Files\Common Files\Services

On my computer they where in c:\windows\system32

And I had to do the thing twice as there was one file that didnt show up until AFTER I got rid of all the others and had restarted.


0

Response Number 19
Name: sabyari
Date: February 11, 2004 at 07:52:16 Pacific
Reply:

thank you.I search the registry for "magicsearch" and delete all files and change the default in registry to "http://www.yahoo.com" and it works.


0

Response Number 20
Name: KevT
Date: February 11, 2004 at 18:21:56 Pacific
Reply:

Guys I need help. My homepage has become some porn site. No matter how i try to change it, it keeps coming back when I restart it. It also leaves some other sites in my favorites. How do I stop this? I'm a complete newb, can someone explain this slowly to me?


0

Response Number 21
Name: MC_C
Date: February 11, 2004 at 20:10:09 Pacific
Reply:

Man this stupid thing is a pain in my u know what. It is so fucturating that the day i uninstall Nortan Anti Virus, this stupid worm comes on my system. now reading through, maby Nortan wouldn't be as much help as i think. aneyways, i am still having problyms with this.. and as posted before, i cant find the accuall files in my computer. I inabled 'Custom' in Ad-adware and that didn't seem to do the trick. The funny thing is, the tec person who i was on the phone with told me to install SpyBot, and as soon as i searched and installed it to my computer, one of the posts said that SpyBot dosent work. I find that if you want to visit a website outside of 'magicsearch', then you have to type in the FULL URL. Such as Http:// just typing in WWW or the website.com wont let you go outside of the magicsearch site. Now I installed a game, accually a couple of games from Sharewareriver.com it was some simulation games, and they needed DirectX and DirectX3D and stuff like that, i dont know if they installed thoes behind the installation of the games, but maby thats another reason why we are gettin this..? Has aneybody recienlty installed any DirectX programs and came with this problym? Well As I read Through, i didn't quite understand what u guys are saying, i did a searh of the h..what ever files and the js ones too...deleted acually all of them... then manually searched my computer but came up with nothing...can any body help me with this, i may have brains, and have a ideal idea of computers, but when it comes to manually fixing WORMS, VIRUSES and other things without the click of just one butten, then i get lost.

Thanks


0

Response Number 22
Name: xandy
Date: February 11, 2004 at 23:46:34 Pacific
Reply:

http://magicsearch.ws/contactus.php

Anyone try their "instructions"? I'm afraid to do so. Been trying to get rid of this (followed all directions stated above - used adaware & spybot) & so far no luck!


0

Response Number 23
Name: Brigs
Date: February 12, 2004 at 01:36:06 Pacific
Reply:

i am willing to help!

i hav the same problem with you before dudes.

but i foud a way to kill this magicsearch.ws

Here is the steps.

***HOw to Kill Magicseach.ws SPYWARE****
by Brigs

Symptoms: your home cannot be set to any other site but www.magicsearch.ws

A.)
for XP:
Press ctrl+alt+del to run taskmgr.exe
Go to processes

for Other OS:
use any process viewer or killer


End or Kill every process named with the one of the following:

autorun.exe
clrssn.exe
directx32.exe
explore.exe
explorer32.exe
inetinf.exe
internet.exe
sistem.exe
uninstall.exe
systeem.exe
iexplorer.exe
exploreer.exe
directx.exe
time.exe
users32.exe
volume.exe
win32e.exe
window.exe
winmnt.exe

B.)

do this in the registry editor :

1.) HKLM\Software\Microsoft\Windows\CurrentVersion\Run

must delete string name "coolwebprogram"

2.) HKLM\Software\Microsoft\windows\currentVersion\URL\Prefixes\

Change the value of www from "http://www.magicsearch.ws/?q=" to "http://"

3.) HKLM\Software\Microsoft\windows\currentVersion\URL\DefaultPrefix\

Change the value of www from "http://www.magicsearch.ws/?q=" to "http://"


C.)

Explorer

Delete these files:

C:\Program Files\Common Files\Services

autorun.exe
clrssn.exe
directx32.exe
explore.exe
explorer32.exe
inetinf.exe
internet.exe
sistem.exe
uninstall.exe
systeem.exe
iexplorer.exe
exploreer.exe
directx.exe
time.exe
users32.exe
volume.exe
win32e.exe
window.exe
winmnt.exe
temp.txt
init.sys
network.sys

Wipe your hard drive's free space...

Brigs


0

Response Number 24
Name: RobScott
Date: February 12, 2004 at 03:03:36 Pacific
Reply:

OMFG!! ITS FINALLY GONE!!! yo thanks for that post brigs, i mean i had internet.exe hiding in WINDOWS/system folder and ocne i deleted that i just delete all 'magicsearch' in the registry and IT WAS GONE!! omfg its been like over 2 months about lol muahahaha blow me u f*cking virus


0

Response Number 25
Name: MC_C
Date: February 12, 2004 at 05:48:57 Pacific
Reply:

Whats the registry editor? :S???


0

Response Number 26
Name: iinfoque
Date: February 12, 2004 at 11:20:56 Pacific
Reply:

For magicsearch.ws, Nachi.A worm and search central removal see the solution by going to www.aameen.org, go to its forum by clicking the button of forum given on top row on website. There on forum there is complete and working solution of it given under Troubleshooting, Virus and adremoval topic/category.

iinfoque


0

Response Number 27
Name: KevT
Date: February 12, 2004 at 16:46:19 Pacific
Reply:

Thanks Brigs, but before i can try your method, i need to know.... what/how do I get to the registry editor? I'm sorry, but I'm computer illiterate.



0

Response Number 28
Name: nobug
Date: February 13, 2004 at 07:02:30 Pacific
Reply:

to: ln187347

I posted the solution to MY problem here:

http://bogesoft.bgfree.biz/magicsearch_fix_procedure.txt

As I can see from your first post, there seems to be very similar situations.

Hope it helps other people too.

Also take look at my post to the above mentioned forum:

http://forumer.com/index.php?mforum=aameenorg&showtopic=4&view=findpost&p=7

There is something important, that happened to me ;)


0

Response Number 29
Name: RobScott
Date: February 13, 2004 at 10:40:01 Pacific
Reply:

to get ur registry editor or atleast for win XP go to ur start menu and click run, then type 'regedit' and click ok. Then i went to 'edit' and then 'find' and typed magicsearch. I ended up combining a lot of the suggestions but endinng and deleting the program is the key to it all.

as far as the other windows u may hafta search the help files for how to change ur registry


0

Response Number 30
Name: o0o
Date: February 14, 2004 at 10:03:48 Pacific
Reply:

Hey i know i have the smae prob... try this it might work... start run type in msconfig and go to startup and take off tike mark for the names ex..

autorun.exe
clrssn.exe
directx32.exe
explore.exe
explorer32.exe
inetinf.exe
internet.exe
sistem.exe
uninstall.exe
systeem.exe
iexplorer.exe
exploreer.exe
directx.exe
time.exe
users32.exe
volume.exe
win32e.exe
window.exe
winmnt.exe
temp.txt
init.sys
network.sys
autorun.exe
clrssn.exe
directx32.exe
explore.exe
explorer32.exe
inetinf.exe
internet.exe
sistem.exe
uninstall.exe
systeem.exe
iexplorer.exe
exploreer.exe
directx.exe
time.exe
users32.exe
volume.exe
win32e.exe
window.exe
winmnt.exe


Or tehre might be.. some thing like
win32e that is one off then to... i beleave... u can see where the file is by jsut lookin at the command collume and restart... it it helps tehn use it ... if not then change it back to what ever... u had before..


0

Response Number 31
Name: o0o
Date: February 14, 2004 at 10:11:36 Pacific
Reply:

I GOT ONE MORE answer if u do'nt see any files in C:\Program Files\Common Files\Services ............. Try Goin to C:\Program Files\Common Files\Services and go to tools->FolderOptions->Views->and Unable those ........Hiden Files.... That might help you... See all those hiden Files.... MAn... I AM THE BEST.. j/K lol U guys heldp me get through this much... thanx for telling me its at
C:\Program Files\Common Files\Services

Have a nice Life.. Bye


0

Response Number 32
Name: o0o
Date: February 14, 2004 at 15:10:28 Pacific
Reply:

do u have to remove initial & systemxp to form the C:\Program Files\Common Files\Services ??? plz replay me fast or email me some_911@hotail.com


0

Response Number 33
Name: tcrex2000
Date: February 15, 2004 at 14:08:25 Pacific
Reply:

Hey guys - I noticed another couple things this worm did to my computer - there is also a notepad32.exe that it puts in your windows directory. It takes notepad out of the Open with... right click menu and puts notepad32.exe in there (it has no icon). running this will revert everything back to the magicsearch.ws crap. just a warning. Also, since this has happened I haven't been able to go to have it open the program when I "Choose program..." in the Open with... menu. Does anyone know what's going on with this? Thanks.


0

Response Number 34
Name: KevT
Date: February 15, 2004 at 18:26:02 Pacific
Reply:

Guys... if i were to delete some text files in my Systems folder, would it mess up my PC?


0

Response Number 35
Name: nobug
Date: February 16, 2004 at 02:24:00 Pacific
Reply:

that last has nothing to do with the current problem.
Anyway: Yes! You are free to delete any *.txt file from your system folder (if you find any, there aren't much of them there)

tcrex2000,
if you had read all the posts here, you'll noticed my post above, where I already wrote about that extremely dangerous notepad32.exe file ;)


0

Response Number 36
Name: tadadam
Date: February 16, 2004 at 02:58:22 Pacific
Reply:

Hello everybody!

Need to ask for help. Have the same problem with "magicsearch" (WinXP, IE 6). Tried to look for 22 kb .exe files, look in .hta or .js files for "magicsearch" - found nothing. Instead, found some suspicious folder:

C:\WINNT\Prefetch

with a plenty of "unknown application .PF files"_ like this:

ALOGSERV.EXE-00FDB330.pf
START.EXE-2629DD07.pf; etc.

created near the time when this bloody "magicsearch" appeared... What kind of crap is this?

Please, teach me how to kill this crap. But just one more problem - I'm just user, not a pro...


0

Response Number 37
Name: nobug
Date: February 16, 2004 at 05:26:20 Pacific
Reply:

Probably you don't see the files, because they are hidden.

In Windows Explorer go to "Tool" -> "Folder Options..." and then to "View" tab.
There locate "Show hidden files and folders", select it and Apply/OK

After that try to search for the files again.

This Prefetch folder is system folder, where WinXP stores information about applications that are one ran. This information is not critical. It is there so XP can start the same applications faster the next time you run them.

Hope this helps!

Regards, Boian


0

Response Number 38
Name: tadadam
Date: February 16, 2004 at 06:07:54 Pacific
Reply:

Thank you for reply and the explanations concerning \Prefetch folder...

I had an option, where I could see hidden files and folders, but saw no suspicious 22 kb .exe files. I don't know, where they where hidden, and actualy don't care about that anymore, 'cause went on site, as it was advised in Responce #15, downloaded small program, which succesfully cleaned my comp out of this trojan. Only one thing had to do - re-assign proxy and check TCP/IP - somehow it was affected by cleaning, but that was not a problem.


0

Response Number 39
Name: rmchatton
Date: February 17, 2004 at 14:49:57 Pacific
Reply:

Hi I'm having a problem geting rid of a toolbar called enc I think. It appeared around the same time as Magicsearch. No one seems to have mentioned it yet.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: cannot change internet homepage

Cannot Change Browser Homepage www.computing.net/answers/security/cannot-change-browser-homepage/17039.html

Cannot change homepage at all!!!!! www.computing.net/answers/security/cannot-change-homepage-at-all/10105.html

cannot change homepage from dell4me www.computing.net/answers/security/cannot-change-homepage-from-dell4me/18793.html