I downloaded hijackthis and CWshredder. I ran cwshredder in safe mode. then i went back to normal mode and ran hijackthis. here is the log. what do I do next?

Logfile of HijackThis v1.97.7
Scan saved at 10:50:27 PM, on 6/23/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\wizard\My Documents\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\wizard\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\wizard\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\wizard\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\wizard\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\wizard\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\wizard\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {B9D90B27-AD4A-413a-88CB-3E6DDC10DC2D} - C:\WINDOWS\msopt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

Dani AI

Generated

Good to see the immediate problem was cleared by with 's guidance. A quick cleanup can fix visible symptoms, but browser hijackers often leave hidden bits behind. The short checklist below helps verify the system is truly clean and reduces the chance of a repeat.

  1. Run up-to-date, second-opinion scanners (one on-boot and one offline). A current full scan with a tool like Malwarebytes plus Microsoftsafety tools will catch staying bits and newer variants (Microsoft Safety Scanner).
  2. Inspect autoruns and autostarts. Use Autoruns (Sysinternals) to review services, scheduled tasks, browser helpers and Run keys you might have missed. Disable or quarantine anything unknown rather than immediate deletion.
  3. Check for rootkits and persistence. If strange behavior continues after scans and autoruns looks clean, run a dedicated rootkit/boot-time scanner or rescue media (many vendors document these on their sites). BleepingComputer has solid step-by-step removal guides and tool references if a stubborn infection shows up (BleepingComputer).
  4. Harden the machine: move to a supported OS if possible, keep the system and all browsers/plugins patched, run as a non-admin account for daily work, enable real-time antimalware, and use a modern browser with script/blocking extensions. Keep regular backups or a system image so a reinstall is easy if needed.

A final note: if unknown executables or service entries persist after the above, a clean reinstall is often the safest option. Quarantining and ongoing tinkering can leave holes; a fresh image restores trust in the system state.

Recommended Answers

All 3 Replies

To start with, Have HJT fix the following:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\wizard\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\wizard\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\wizard\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\wizard\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\wizard\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\wizard\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {B9D90B27-AD4A-413a-88CB-3E6DDC10DC2D} - C:\WINDOWS\msopt.dll

Once done, reboot into safe mode and delete all of the files referenced in the above log entries. You might have to set WIndows Explorer's "View" options to show all files and folders, show hidden and system files, etc.

You might also want to have HJT whack these as well:

O9 - Extra button: Research (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)

Once all of that is done, purge your cookies, Temporary Internet FIles, and History. Empty your Recycle Bin after that.

It seems to be working and fixed now. Thanks. Now how do I prevent this from getting on my computer again?

There are general "best practice" steps you take to lessen your chance of reinfection, and there are also a couple of programs you can download which will actively block some spyware activity. All of this is described in the following article; give it a read:

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.