The short answer is:
- Have HJT fix this entry:
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load
- Reboot
- Delete the bridge.dll file if it does exist on your system.
The longer answer is this:
- Your log shows that you were running HJT from the desktop, and that IE was still open. You should run HJT from its own folder, not from a temp folder or the desktop. That will allow HJT to create backups in case you need them. You should also close all applications, including IE.
- Make sure you have the latest updates/definitions (not just the latest versions) of Ad Aware and SpyBot Search & Destroy. Run both of those programs consecutively, rebooting after each. Let them fix everything they find and then run HJT again and post the fresh log. For Ad Aware, you should set some custom scanning options; a short tutorial on that is here:
http://www.bleepingcomputer.com/forums/index.php?showtutorial=48
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
Have Hijack This fix the following by placing a check in the appropriate boxes and selecting fix checked. Make sure all browser and all Windows Explorer windows are closed before fixing.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us5.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us5.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us5.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us5.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us5.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us5.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us5.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://srch-us5.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://srch-us5.hpwis.com/
O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
This one isn't spyware but is a suggested fix as its a rescorce hogg and not needed in startup.
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
Now reboot into safe mode and delete the following files and folders if found .
C:\WINDOWS\sysupd.exe >>>> Delete file
to delete the above files and folder you will need to do the following
go to
Show hidden files & folders
"Fix Checked"...Reboot to SAFE mode to delete files
How to start computer in safe mode
reboot computer and post a new log
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812
This:
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 207.165.195.2:8000
Would indicate that you're using one of the United Community School District's proxy servers in Boone, Iowa. Is that the case?
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
@DMR: No.. that is really weird, I'm at UC Davis, using UCD T-1 connecting at the dorms.
Davis, eh? I'm down in San Rafael- drop in for a beer some time... :)
Have HJT fix that entry then- it can't be right.
I just called the computer person at that school and they said they're having blacklisting issues with that address- hmm... wonder why?
@caperjack: Would it be bad if I leave them unfixed? Are they doing something to my computer if I leave them be? Cause I'm afraid of messing things up again if I remove them, thanks!
If that URL doesn't look familiar to your, it shouldn't be there- fix them.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
" R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 207.165.195.2:8000"
What the heck is that still doing there? Did it come back, or did HJT not fix it?
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
this program is responsiable for you browse hijack problems ,i suggest removing it ,
O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\sysupd.exe
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812