This happend to me tonight, I've followed the suggestions in here and ran http://www.merijn.org/files/cwshredder.zip 1st, and this is my current HJT log.. I think I've cleared it up but I just want someone more in the know to make sure I didn't miss anything :) Thanks all!

Logfile of HijackThis v1.97.7
Scan saved at 2:07:48 AM, on 1/19/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\System32\CTsvcCDA.EXE
D:\Program Files\Norton AntiVirus\navapsvc.exe
D:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Documents and Settings\loki\Desktop\HijackThis.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NAV Agent] D:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

Dani AI

Generated

ran cwshredder and posted a HijackThis log that, as noted, shows no obvious active hijacker left behind. That combination (targeted remover + a clean HJT scan) usually means the immediate infection was removed, but several common leftovers can let the symptom return later. The short checklist below helps confirm full cleanup and harden the system so the hijack does not reappear.

  • Run updated full-system scans with an up-to-date antivirus and at least one current anti‑malware scanner (secondary scanners often find leftovers that one product misses).
  • Inspect the HOSTS file and IE proxy settings for redirects or proxy entries left behind.
  • Use an autorun/startup inspector (msconfig or Autoruns) to review scheduled tasks and startup DLLs that a remover might not have cleared.
  • Create a System Restore point or full backup before making manual removals.

Common quick fixes that are safe to run and verify:

netsh winsock reset
ipconfig /flushdns
notepad c:\windows\system32\drivers\etc\hosts

Run the two commands in an elevated command prompt, reboot, then open the HOSTS file with Notepad and check for unexpected entries.

Notes and cautions: HijackThis is great for identification but its “Fix” buttons should be used only on items that are clearly malicious or after getting confirmation; removing the wrong entry can break things. If the hijack returns, collect a fresh HijackThis log and check for changes in proxy/LAN settings, new scheduled tasks, new BHOs, or modified LSPs. Persistent or recurring infections on an old, unpatched OS often justify a clean reinstall or upgrading to a supported OS and browser to avoid repeated compromises.

Recommended Answers

All 2 Replies

Clean log

steam

Thanks a lot for looking steam!!!

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.