Hi, Don't mean to take up too much of anyone's time. When I log into Hotmail the screen keeps switching to ''

I can't seem to find anything. Reading your posts for the last few days so i loaded HijackThis and here are my logs. Any help appreciated.


Logfile of HijackThis v1.98.2
Scan saved at 9:56:42 PM, on 26/09/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
D:\Trend Micro\Internet Security\Tmntsrv.exe
C:\WINDOWS\System32\pctspk.exe
D:\Trend Micro\Internet Security\tmproxy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\BENQMA~1\QtEiBenQ.EXE
C:\Program Files\BenQ\QMusic\QMAgent.exe
C:\Program Files\Ulead Systems\Ulead Photo Explorer 7.0\Monitor.exe
C:\Program Files\BenQ\Q-MediaBar\QBar.exe
C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
D:\Trend Micro\Internet Security\pccguide.exe
D:\Trend Micro\Internet Security\PCClient.exe
D:\Trend Micro\Internet Security\TMOAgent.exe
C:\Program Files\Messenger\msmsgs.exe
D:\Trend Micro\Internet Security\PccPfw.exe
C:\Program Files\BestPopUpKiller\BestPopupKiller.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\Documents and Settings\Marks\Desktop\Copied stuff\CWShredder.exe
C:\Documents and Settings\Marks\Desktop\Copied stuff\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://WWW.BenQ.COM/
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe
O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINDOWS\System32\UW7MFY~1.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QtEiBenQ] C:\PROGRA~1\BENQMA~1\QtEiBenQ.EXE
O4 - HKLM\..\Run: [o2cd] C:\Program Files\O2Micro\SuperDJ\o2mdj.exe
O4 - HKLM\..\Run: [QMusic] "C:\Program Files\BenQ\QMusic\QMAgent.exe"
O4 - HKLM\..\Run: [Ulead Memory Card Detector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 7.0\Monitor.exe
O4 - HKLM\..\Run: [Q-MediaBar] "C:\Program Files\BenQ\Q-MediaBar\QBar.exe" Minimize
O4 - HKLM\..\Run: [Check Mplayer] C:\windows\runoncew.exe
O4 - HKLM\..\Run: [WheelMouse] C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [pccguide.exe] "D:\Trend Micro\Internet Security\pccguide.exe"
O4 - HKLM\..\Run: [PCClient.exe] "D:\Trend Micro\Internet Security\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "D:\Trend Micro\Internet Security\TMOAgent.exe" /run
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [uninstal] regsvr32 /u /s image.dll
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: winlogin.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://WWW.BenQ.COM/
O15 - Trusted Zone: *.
O16 - DPF: {0B682CC1-FB40-4006-A5DD-99EDD3C9095D} (vbiewer control) - http://www.thepaymentcentre.com/build/vbiewer.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} - http://www.pestscan.com/scanner/axscanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AEE9BB0C-6C64-4676-8062-3888581FF456}: NameServer =
O20 - AppInit_DLLs: hwdb4sodslt.dll

Dani AI

Generated

posted a clear redirect symptom and a HijackThis scan that points to a persistent browser injector plus altered networking settings. The problem is not just a temporary popup — it uses multiple persistence points so a layered, careful cleanup is required: isolate the machine, remove injected DLLs and dodgy startup entries, repair the network/DNS, then validate with up-to-date scanners.

Start by disconnecting the PC from the Internet and booting to Safe Mode (no networking). Make a full backup of important files and export the registry keys you will change. Use an autorun/startup inspector to disable unknown startup items and Browser Helper Objects, and use a process inspector to find which running process is loading a suspicious DLL so it can be stopped before file removal. Export any Run/RunOnce keys before deleting entries. When editing the registry, save a copy first.

Repair the network so redirects do not persist after file removal. Reset the Winsock and TCP/IP stacks and flush DNS like this:

ipconfig /flushdns
netsh winsock reset
netsh int ip reset

Check the hosts file and restore it to default content if entries are present. Once the stack and hosts are clean, set DNS to a trusted resolver (ISP or public DNS) and reboot.

After rebooting on a clean network, run at least two updated scanners (an on-demand anti-malware plus a full antivirus scan) from a cleaned state. Change any online account passwords (Hotmail) using a different, clean computer. If items persist after manual removal and rescans, consider an offline rescue disk or a clean Windows reinstall. Back up before major operations and apply all critical security updates and service packs once the system is confirmed clean.

This follows the initial troubleshooting already suggested by other members and adds manual inspection, network repair, safe password practices, and a recovery escalation path.

Recommended Answers

All 2 Replies

Well try reinstalling internet explorer and install ad-aware

Download CWShredder from here & run it. Select the fix button & it will fix everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including Internet Explorer, before running CWShredder. Reboot.

To help prevent this from happening again, install the patches for the vulnerabilities that this hijacker exploits by going here for your critical updates.

Reboot after doing this & post another log please.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.