Hi,
Trueth I have some recommendations.
Regarding the HijackThis:
C:\unzipped\hijackthis[1]\HijackThis.exe should look like this
C:\HJT\HijackThis.exe on your log. To make it that way: click
Start-->My Computer-->Hard Disk Drive C:\-->File-->New-->Folder and name it HJT. From where it is now:
Move To-->Browse-->select C:\HJT. In this way the program will save backups automatically to that folder and we may need them.
Please make sure to work through the fixes in the exact order that they're presented below. You should also print out or copy this page to Notepad. Sceenshots are included to help you.
Copy the contents of the Quote Box below to Notepad.
Click File menu -> Save and name the file as
fix.regChange the Save as Type to All FilesSave this file on the desktop.
Don't use it yet.REGEDIT4
[-HKEY_CLASSES_ROOT\Interface\{0D721150-AEF3-457B-B03A-5097B623CE45}]
[-HKEY_CLASSES_ROOT\Plugin6.DNSErrObj]
[-HKEY_CLASSES_ROOT\redalert.here]
[-HKEY_CLASSES_ROOT\TypeLib\{444A5674-FF85-45D4-9AE2-4199D8D70C85}]
You will need several tools on your desktop. Unlike HJT, you may run them from the desktop. All are .zip files,
shown after extraction. Please use these links to download them:
You will also need to install
Ad-Aware SE Personal 1.05 onto your PC. It will install normally, and please read
Using Ad-Aware SE to remove Spyware & Hijackers from Your ComputerExtract Killbox, open folder & choose
extract to your
desktop. "Finish". Open the folder and then double-click on
Killbox.exe to start the program.
Fill in the field with this:
C:\WINDOWS\System32\3dhgmuew13wwi.dll and select "delete on reboot". Click red circle to the right of the field.
(The file name will be confirmed in
blue.) click Yes to "process & Reboot now?".
Reboot will occur.
Start-->Add or Remove Programs-->Uninstall (if found) any instances of:
Ebates or
NaviSearch. Please check for a program involving
Iomega, also. One entry in your log shows an unrecognized .exe file and if you use an Iomega device or program it's probably OK. If not, or you used to, consider it for uninstalling. I will also mention it later as optional.
Set your PC to: show hidden files. Additional information
here.
Open your C:\HJT folder and double-click the icon. Close everything except HijackThis, nothing else on your desktop.
Run Hijackthis: click Scan, and put a checkmark next to each of the following objects.
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://super-spider.com/sp.htm?id=9R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://super-spider.com/sp.htm?id=9R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://super-spider.com/sp.htm?id=9R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://win-eto.com/hp.htm?id=9R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://super-spider.com/sp.htm?id=9R3 - Default URLSearchHook is missing
O2 - BHO: MxTargetObj Class - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\mxTarget.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
O4 - HKLM\..\Run: [ovpgldivlma] C:\WINDOWS\System32\liosuxr.exe
O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe
O4 - HKLM\..\Run: [EbatesMoeMoneyMaker0] C:\Program Files\Ebates_MoeMoneyMaker\EbatesMoeMoneyMaker0.exe
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://software-dl.real.com/01d2af68c4a3ab...ip/RdxIE601.cab netster
O20 - AppInit_DLLs: 3dhgmuew13wwi.dll
Then consider these files for deletion also. If you do not recognize them as ones you use & need, there is reason to eliminate them. You can re-install the ones starting with O16 by visiting the websites (
http://etc.com) again if you like.
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) -
http://activation.rr.com/install/download/tgctlcm.cab (if you use roadrunner high speed online. leave in)O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) -
http://jobs.tntlogistics.com/CFIDE/classes/CFJava.cab (Directory Listing Denied. This Virtual Directory does not allow contents to be listed.O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
fix unless you used Spybot's IE Tweaks & locked your start page.When you're sure that files marked for deletion are correct, click the
Fix button.
Reboot your computer into
Safe Mode by tapping F8 until the screen appears where you can use the up arrow to choose safe mode. Hit enter.
Search for, locate and delete these files or folders (Do not be concerned if they do not exist, the previous steps may have eliminated them.) Do not delete the main folders
C:\WINDOWS or
C:\Program Files. We just looking for sub-folders or individual files here. The best way to find them is to use:
Start-->Search-->select "all files & folders"-->select "more advanced options"-->
checkmark search "system folders", "hidden files & folders", "sub-folders" & perhaps "case sensitive" if you like.
c:\counter.cab
C:\WINDOWS\mxTarget.dll
C:\WINDOWS\System32\liosuxr.exe
C:\Program Files\NaviSearch\bin\nls.exe
C:\Program Files\Ebates_MoeMoneyMaker\EbatesMoeMoneyMaker0.exe
C:\PROGRA~1\Iomega\System32\ActivityDisk.exe (the optional one I mentioned. Keep it if you need it for any reason)
Delete Temp FilesTo clean out your temp files use:
Start-->Run-->type in: %temp% and press the ok button. This should open up the temp directory that your machine uses. Please delete all files and folders found in the temp folder. If you get an error when deleting a file, skip that file and delete all the others. Doing this in Safe Mode you should be able to delete all the files.
Reboot your computer to go back to normal mode.
Extract CWShredder 1.59.1, open folder & choose and choose to extract to your desktop. "Finish". Open the folder and doulble-click on the cwshredder.exe
Select FixReboot at least once, perhaps a couple of times to be sure it worked.
Run AdAware, press the "Start" button, uncheck "Scan for negligible risk entries", select "Perform full system scan" and press "Next". Let AdAware remove anything it finds.
Delete Temporary Internet FilesNow I want you to
Start-->Internet Explorer-->Tools-->Internet Options-->General tab-->Delete Files button and put a checkmark in Delete offline content. Then press the OK button. This may take quite a while, but when it is done your Temporary Internet Files will be deleted.
Double-click on the
fix.reg file you saved earlier on your desktop, and when it prompts to merge say
Yes, and this will clear some registry entries left behind by the process.
Extract Hoster, open folder and choose to extract to your desktop. "Finish".
Open the folder and double-click on the
hoster file. With the program open, click "restore original hosts".
Empty the recycle bin.You may choose to move the programs on your desktop to a permanant folder or simply delete them, perhaps when you're certain the PC is clean.
Run HijackThis again and post the new log as a reply to this post.
(Include comments regarding any problems you might have had, and let us know if its working better. Some additional options may exist)
I have confidence in your success, no problem posting again if you're unsure though. Sorry it too me so long