Very often the victim will appear to have a clean HJT log, no pnpsvc running service, but will be complaining about being redirected to a-search.biz/wmid=1010. Invariably this entry will be present:
|
||
|
F2 - REG:system.ini: UserInit=Userinit.exe, |
|
If you want to confirm
infection, checking Winlogon with Shadowwar's pv tool will reveal something
like this near the bottom of the log: Alternatively, use DllCompare to identify it. Removal Instructions:
|
||
Click here
to download Pocket Killbox by Option^Explicit. Extract it from the zip file
then double-click on Killbox.exe to run it. |
||