Wzscnet.com/i/startm.html (Info and Removal)


Wzscnet.com/i/startm.html is a browser hijacker

Wzscnet.com/i/startm.html
If your browser is redirected to Wzscnet.com/i/startm.html, then your computer is infected with a browser hijacker. You should immediately check your PC using an antivirus or antispyware software.

Name: Wzscnet.com/i/startm.html
Type: Adware/Browser Hijacker
Danger Level: Low/Medium
Symptoms: browser opens wzscnet.com/i/startm.html, redirects to random websites, a lot of asnnoying ads
Distribution Method: Wzscnet.com/i/startm.html browser hijacker is integrated into the installation package of various free programs
HijackThis may show infection:

R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://wzscnet.com/i/startm.html/{param}
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://wzscnet.com/i/startm.html/{param}
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://wzscnet.com/i/startm.html/{param}
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://wzscnet.com/i/startm.html/{param}
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://wzscnet.com/i/startm.html/{param}
R0 – HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://wzscnet.com/i/startm.html/{param}
R0 – HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://wzscnet.com/i/startm.html/{param}
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://wzscnet.com/i/startm.html/{param}
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://wzscnet.com/i/startm.html/{param}
O4 – HKCU\..\Run: [xxx] explorer.exe http://wzscnet.com/i/startm.html/{param}

FRST may show infection:

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://wzscnet.com/i/startm.html/{param}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://wzscnet.com/i/startm.html/{param}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://wzscnet.com/i/startm.html/{param}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://wzscnet.com/i/startm.html/{param}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = http://wzscnet.com/i/startm.html/{param}
HKU\{clsid}\Software\Microsoft\Internet Explorer\Main,Start Page = http://wzscnet.com/i/startm.html/{param}
SearchScopes: HKU\{clsid} -> {clsid} URL = http://wzscnet.com/i/startm.html/{param}
StartMenuInternet: IEXPLORE.EXE – C:\Program Files\Internet Explorer\iexplore.exe http://wzscnet.com/i/startm.html/{param}
CHR HomePage: Default -> wzscnet.com/i/startm.html/{param}
CHR DefaultSearchURL: Default -> http://wzscnet.com/i/startm.html/{param}
CHR DefaultSearchKeyword: Default -> wzscnet.com/i/startm.html
CHR DefaultSuggestURL: Default -> http://wzscnet.com/i/startm.html/{param}

Detection and removal: To remove Wzscnet.com/i/startm.html browser hijacker use a free software such as AdwCleaner and Malwarebytes Anti-malware.

Comments are closed.