-My explorer keeps adding porn sites to my favorites and hijacking my homepage while keeping my explorer window open or closed.

-I ran these spyware removal programs: X-Cleaner, clean out my IE options, ran CShrewder v1.47, ran Adware 6.0 and then SpybotS&D 1.2.

-CShrewder cleans out CWS:Winshow and restores IE pages. Adware Cleans out many CWS registries or all the malware and so does SpybotsS&D.

-I reboot pc and after a little while the same favorites are added on. I run the x-cleaner:find nothing new, clean out ie options history,pages,cookies,etc.: nothing new. But when i use CShrewder again, the same problems found and i hit fix again, the Winshow Removed and the IE pages restored. The Adware finds the same malware and fixes it again.

-Somewhere in there is something majorly wrong.

-Can you please help Any admin/moderator?

-This is my Hijackthis log after i run the applications above and after reboot. Thanks for the Help in advance.
LOG:

Dani AI

Generated

This thread shows a classic persistent browser-hijacker: favorites and homepage changes that come back after ordinary scans. and were on the right track — infections like this often leave registry/hosts edits and one or more autostart mechanisms behind, so removing visible items without checking persistence points will let the problem return. For a stable clean, follow a short, ordered checklist rather than rerunning the same tools over and over. (Browser hijacker overview and remediation)

Practical, minimal checklist:

  • Disconnect the PC from the internet, back up important files, then boot into Safe Mode (older Windows: F8; newer Windows: the appropriate recovery/safe-boot path).
  • Update signatures and run anti-malware first (AdwCleaner/Malwarebytes or equivalent), then a full AV scan.
  • Use Autoruns (run as administrator) to inspect and disable unknown items under Logon, Services, Scheduled Tasks, BHO/Toolbars and Browser Helper Objects; remove only items you can identify as malicious or clearly unwanted.
  • Inspect/reset the hosts file to default if it’s been altered (malware often redirects domains there).
  • If System Restore may hold infected snapshots, clear restore points (turn System Restore off then on, or delete shadow copies) after the system is clean.
    See the official tools/docs: Autoruns (Sysinternals) · Reset Hosts file (Microsoft) · AdwCleaner guide

If the infection survives those steps it’s often persisting via scheduled tasks or hidden autoruns, or living in backups/restore points; hunt tasks with Task Scheduler and treat hidden tasks as a serious indicator. For stubborn cases scan from clean media (rescue/rescue-ISO) or consider a clean reinstall if important persistence vectors remain. (Scheduled-task persistence – MITRE/CISA guidance) · (Bootable rescue disk options)

After cleaning, install all OS/security updates, remove risky apps (e.g., P2P clients), change passwords, and create a fresh restore point.

Recommended Answers

All 11 Replies

I cant add my log, for some reason it wont let me add it as a post or a postreply . . . sad. Any ideas?

GeneralPatton tried including his log file but got an error message. He then sent the file to me via email for me to post. Unfortunately I got the same message. I even got the message trying to include it as an attachment.

I'm looking into this right now. However, in the meantime, I've included his file as a zip - so that the forum software can handle it (since it's not handling the file contents directly).

Sorry for the inconvenience everyone!

C:\Program Files\KaZaA Lite\Kazaa.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O3 - Toolbar: (no name) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - (no file)
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: MktBrowser (HKLM)
O9 - Extra 'Tools' menuitem: MarketBrowser (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)


These are some of the things that I would get rid of just because you really don't need them and in my opinion kazaa is horrible.

-My explorer keeps adding porn sites to my favorites and hijacking my homepage while keeping my explorer window open or closed.

-I ran these spyware removal programs: X-Cleaner, clean out my IE options, ran CWShredder v1.47, ran Adware 6.0 and then SpybotS&D 1.2.

Your Ad-aware and CWShredder are both out-of-date. They are up to 6.18 and 1.50, respectively. I don't think that's the problem, though.

That having been said, there are no nasty processes running, it's all in the Registry. Delete the following keys:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant = ,

R1 - HKCU\Software\Microsoft\Internet Explorer,CustomizeSearch = ,

O1 - Hosts: verisign.com
*** This is likely where your redirection is coming from. ***

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)

O3 - Toolbar: (no name) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - (no file)

These two are optional, but highly recommended:

O4 - HKLM\..\Run: [QuickTime Task] "f:\quicktime\qttask.exe" -atboottime

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

One last question, though: Why do you have both Intel and SiS utilities installed on your system? They are mutually exclusive. They probably don't conflict, but one or the other is redundant. Post your exact HP model number, we'll figure out what you have and get rid of what you don't need.

-TallCool1, thank you for your help. I will delete those registries now to get rid of this annoyance and check back with you.

-my pc is a hp pavilion 552w desktop pc. About the SiS and Intel Utilities, I have no idea as to why I have both. I thank you in advance for this help too, since i was not aware of, and will come back to check what you have to say about this. Thanks again.

TallCool1,

-I took off all the registries(recomended too) and restarted my pc. The porn sites, 2 of them like before, are there again now. Any Other Suggestions? homepage is good.

-here is now an up to date hijackthis log file. I will add it as a zip file like the admin did before because the normal ways didn't work.
-can u give me specific links for the newest cwshredder, I looked for it and found broken links? thank you.

update your virus scanner and your CWShredder. Run Ad Aware then run SpyBot S&D. Run them Both. Finally run the CWShredder. I think it's for the newest one or just click the update button in the program. You may be getting it from a dropper trojan like Inor which is usually at porn sites check for link.exe or i.exe in your C:/ folder just the main drive folder. But delete the porn in your favorites they should just go. If you do have the virus you may need to boot into safe mode to get ride of it just hit F8 repeatedly at start up to make sure you don't miss it. Good Luck.

-=CodeMasterFlex=-

Thank you I will try that too now.

Thanks Code, I think that did it. The updated CWShredder and Adware seem to have taken everything off. Thanks for the help everyone. thanks.

thanks TallCool1 for the heads up on the updated adware and shredder. That took off all the malware completely. thank you.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.