It looks like CWS shredder; Spybot S&D cleaned things up but I still can't reset the internet options in the Tools, internet options area of IE 6.
It looks like I'm half way home....Thanks for your help.
Osandler
Main Topics
Browse All TopicsHello, I'm new here.
After reading a similar post I decided to run High Jack This and post my log. I can't reset IE 6 to my home page and sometimes after clicking on a hyperlink it points to some url in the form of: res://c:/documents&setting
Here is where the browser lands sometimes after launching IE or clicking a hyperlink:
res://mshp.dll/index.html#
and sometime it goes here:
http://www.runsearch.com/
Logfile of HijackThis v1.97.7
Scan saved at 3:51:36 PM, on 1/23/2004
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon
C:\WINNT\system32\services
C:\WINNT\system32\lsass.ex
C:\WINNT\system32\svchost.
C:\WINNT\system32\spoolsv.
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\System32\svchost.
C:\PROGRA~1\NORTON~1\NORTO
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINNT\System32\nvsvc32.
C:\WINNT\system32\regsvc.e
C:\WINNT\system32\MSTask.e
C:\PROGRA~1\NORTON~1\SPEED
C:\WINNT\System32\WBEM\Win
C:\WINNT\system32\svchost.
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SymTray.exe
C:\WINNT\System32\RUNDLL32
C:\WINNT\System32\PRPCUI.e
C:\Program Files\DELL\AccessDirect\da
C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.ex
C:\Program Files\Common Files\efax\HotTray.exe
C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
C:\Program Files\Common Files\efax\Dllcmd32.exe
C:\WINNT\System32\wuauclt.
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\WINZIP\wzqkpic
C:\PROGRA~1\WINZIP\winzip3
C:\Documents and Settings\Administrator\Loc
R0 - HKLM\Software\Microsoft\In
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: (no name) - {2E9CAFF6-30C7-4208-8807-E
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
O2 - BHO: . - {587DBF2D-9145-4c9e-92C2-1
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-F
O2 - BHO: (no name) - {FD9BC004-8331-4457-B830-4
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\DELL\AccessDirect\da
O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.ex
O4 - HKLM\..\Run: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtray.exe SetReg
O4 - HKLM\..\RunOnce: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtrdr.exe
O4 - Global Startup: eFax.com Tray Menu.lnk = C:\Program Files\Common Files\efax\HotTray.exe
O4 - Global Startup: Instant Wireless Configuration Utility.lnk = C:\Program Files\Linksys\WPC11 Config Utility\WPC11Cfg.exe
O4 - Global Startup: Live Menu.lnk = C:\Program Files\Common Files\efax\Dllcmd32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Mic
O6 - HKCU\Software\Policies\Mic
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
Any help on resetting my browser would be appreciated.
Osandler...the golden beagle dog...my pet.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
It sounds good, stevenlewis has you on the right track, listening further since this is a new one on me and interested in the outcome. I'm curious why the goto link you provided includes a pin number; and other entries look strange to me. I've seen numerous entries, though, on message boards stating they've found runsearch to be a spyware item, so likely linked. You may also need to clear any related items from your HOSTS file, since I'm unclear if the application you are using will check that as well. I'd definitely look at my autocomplete items, history and temp internet files including offline items and clear them as well, were I in your shoes. It always helps to keep your software updated (WindowsUpdate) as well as any Viruscan programs for current virus definition files, many of them include updates against spyware as well.
Here's a google result which I meant to include with my prior comment.
http://www.google.com/sear
Download and run: http://www.merijn.org/file
parasite (as Steven suggests above).
Then download and run:
http://www.kellys-korner-x
tabs and remove any restrictions that the parasite has put in place.
However, this also indicates that you may have acquired some other malware
along the way. If you go to this page at Jim Eshelman's site, here:
http://aumha.org/a/noads.h
of a number of possible parasites on your machine will be made to help you
identify and remove them. NOTE: You will need to disable Ad Blocking in Zone
Alarm 3.x, if present or any other Ad Blocking software which interferes
with Java Scripting for this scan to work. You should get a message between
the two lines of **** giving the results of the scan.
Ad-aware and SpyBot S&D you already know.
Once you get it all cleaned up, you might want to consider installing the
SpywareBlaster and SpywareGuard here to help prevent this kind of thing from
happening in the future:
http://www.wilderssecurity
X installs) (BTW, SpyWare Blaster is not memory resident ... no CPU or
memory load - but keep it updated) The latest version as of this writing
will prevent installation or prevent the malware from running if it is
already installed, and it provides information and fixit-links for a variety
of parasites.
http://www.wilderssecurity
install malware).
Both very highly recommended.
Zee
check these keys
User Key: [HKEY_CURRENT_USER\Softwar
see here
http://www.winguides.com/r
and here
http://www.winguides.com/r
Thank you for the share of points and the fine grade, but want to make sure that my technical information was helpful and that I didn't get these points erroneously. Was the HOSTS file checked and/or other technical insights from me helpful? I just don't want to get points I didn't deserve, but again, thank you.
Asta
XP Professional users who applied the latest patches will get the "Operation cancelled" message when clicking on hyperlinks on forms. Nothing to do with malware, everything to do with well intentioned security updates erring on the side of caution. Two places to go. Internet options and ** [HKEY_CURRENT_USER\Softwar
the latter provided by **steven lewis above.
Business Accounts
Answer for Membership
by: stevenlewisPosted on 2004-01-23 at 19:20:03ID: 10189496
try this program/co olwebshred der.html
CoolWebShredder
http://www.spychecker.com/