This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

cwshredder findings

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

this is a cwshredder scan of my computer. The cwsshredder software keeps finding and removing svchost32
and smartsearch. These seem to be preventing me from using hijackthis scan.

Can you help me resolve this?


**** Run Keys ****

RUN: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
RUN: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
RUN: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
RUN: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
RUN: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
RUN: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
RUN: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
RUN: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
RUN: [HostManager] C:\Program Files\Common Files\AOL\1137632844\ee\AOLSoftware.exe
RUN: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
RUN: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
RUN: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
RUN: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe
RUN: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
RUN: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
RUN: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
RUN: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
RUN: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
RUN: [winlogon] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
RUN: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
RUN: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
RUN: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
RUN: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
RUN: [PlaxoUpdate] C:\Program Files\Plaxo\2.11.1.5\PlaxoHelper.exe -a
RUN: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5746\GoogleToolbarNotifier.exe
RUN: [winlogon] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5746\GoogleToolbarNotifier.exe
RUN: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe


**** Browser Helper Objects ****

BHO: [] C:\PROGRA~1\SPYBOT~1\SDHelper.dll
BHO: [SSVHelper Class] C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
BHO: [Windows Live Sign-in Helper] C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: [Google Toolbar Helper] c:\program files\google\googletoolbar2.dll
BHO: [Windows Live Toolbar Helper] C:\Program Files\Windows Live Toolbar\msntb.dll


**** IE Toolbars ****

TOOLBAR: [Windows Live Toolbar] C:\Program Files\Windows Live Toolbar\msntb.dll
TOOLBAR: [Yahoo! Toolbar] C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll


**** IE Extensions ****

IEExt: []
IEExt: [Research]
IEExt: [AIM] C:\Program Files\AIM\aim.exe
IEExt: [Real.com] C:\Program Files\AIM\aim.exe
IEExt: [MUSICMATCH MX Web Player] C:\Program Files\AIM\aim.exe
IEExt: [MUSICMATCH MX Web Player] C:\Program Files\AIM\aim.exe
IEExt: [Messenger] C:\Program Files\Messenger\msmsgs.exe


**** Hosts File Entries ****

HOSTS: 1.1.1.1 f-secure.com
HOSTS: 1.1.1.1 www.f-secure.com
HOSTS: 1.1.1.1 ftp.f-secure.com
HOSTS: 1.1.1.1 ftp.sophos.com
HOSTS: 1.1.1.1 dispatch.mcafee.com
HOSTS: 1.1.1.1 download.mcafee.com
HOSTS: 1.1.1.1 rads.mcafee.com
HOSTS: 1.1.1.1 mast.mcafee.com
HOSTS: 1.1.1.1 my-etrust.com
HOSTS: 1.1.1.1 www.my-etrust.com
HOSTS: 1.1.1.1 nai.com
HOSTS: 1.1.1.1 www.nai.com
HOSTS: 1.1.1.1 networkassociates.com
HOSTS: 1.1.1.1 secure.nai.com
HOSTS: 1.1.1.1 www.sophos.com
HOSTS: 1.1.1.1 support.microsoft.com
HOSTS: 1.1.1.1 us.mcafee.com
HOSTS: 1.1.1.1 vil.nai.com
HOSTS: 1.1.1.1 viruslist.com
HOSTS: 1.1.1.1 www.viruslist.com
HOSTS: 1.1.1.1 grisoft.com
HOSTS: 1.1.1.1 www.grisoft.com
HOSTS: 1.1.1.1 free.grisoft.com
HOSTS: 1.1.1.1 trendmicro.com
HOSTS: 1.1.1.1 housecall.trendmicro.com
HOSTS: 1.1.1.1 www.trendmicro.com
HOSTS: 1.1.1.1 pandasoftware.com
HOSTS: 1.1.1.1 www.pandasoftware.com
HOSTS: 1.1.1.1 usa.kaspersky.com
HOSTS: 1.1.1.1 ewido.net
HOSTS: 1.1.1.1 www.ewido.net
HOSTS: 1.1.1.1 zonelabs.com
HOSTS: 1.1.1.1 www.zonelabs.com
HOSTS: 1.1.1.1 bitdefender.com
HOSTS: 1.1.1.1 www.bitdefender.com
HOSTS: 1.1.1.1 download.bitdefender.com
HOSTS: 1.1.1.1 upgrade.bitdefender.com
HOSTS: 1.1.1.1 sysinternals.com
HOSTS: 1.1.1.1 www.sysinternals.com
HOSTS: 1.1.1.1 onguardonline.gov
HOSTS: 1.1.1.1 www.onguardonline.gov
HOSTS: 1.1.1.1 avast.com
HOSTS: 1.1.1.1 www.avast.com
HOSTS: 1.1.1.1 safety.live.com
HOSTS: 1.1.1.1 www.paretologic.com
HOSTS: 1.1.1.1 paretologic.com
HOSTS: 1.1.1.1 virusscan.jotti.org
HOSTS: 1.1.1.1 virusscan.jotti.org
HOSTS: 1.1.1.1 virusscan.jotti.org


**** IE Settings ****

Default Page: http://go.microsoft.com/fwlink/?LinkId=69157
Default Search: http://go.microsoft.com/fwlink/?LinkId=54896
Search Bar: http://www.google.com/ie
Search Page: http://www.google.com


**** IE Context Menu (Right click) ****

IEContext: [&AIM Search] res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
IEContext: [&Windows Live Search] res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
IEContext: [E&xport to Microsoft Excel] res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IEContext: [Open in new background tab] res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?f5d38ff0ac994bbdab39ab39de9b775c
IEContext: [Open in new foreground tab] res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?f5d38ff0ac994bbdab39ab39de9b775c


**** Layered Service Providers ****

LSP: MSAFD Tcpip [TCP/IP]
LSP: MSAFD Tcpip [UDP/IP]
LSP: RSVP UDP Service Provider
LSP: RSVP TCP Service Provider
LSP: MSAFD Tcpip [TCP/IPv6]
LSP: MSAFD Tcpip [UDP/IPv6]
LSP: MSAFD nwlnkipx [IPX]
LSP: MSAFD nwlnkspx [SPX]
LSP: MSAFD nwlnkspx [SPX] [Pseudo Stream]
LSP: MSAFD nwlnkspx [SPX II]
LSP: MSAFD nwlnkspx [SPX II] [Pseudo Stream]
LSP: MSAFD NetBIOS [\Device\NwlnkNb] SEQPACKET 5
LSP: MSAFD NetBIOS [\Device\NwlnkNb] DATAGRAM 5
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{516B2F50-913D-44BA-A773-6749245C7467}] SEQPACKET 10
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{516B2F50-913D-44BA-A773-6749245C7467}] DATAGRAM 10
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{649717FF-5D56-4BC5-B59A-7CAB7A124583}] SEQPACKET 8
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{649717FF-5D56-4BC5-B59A-7CAB7A124583}] DATAGRAM 8
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{FF275D06-6808-450E-85DF-03463FC60E15}] SEQPACKET 6
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{FF275D06-6808-450E-85DF-03463FC60E15}] DATAGRAM 6
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{3050E54C-D2C9-4C4F-BCDA-B04380738C35}] SEQPACKET 3
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{3050E54C-D2C9-4C4F-BCDA-B04380738C35}] DATAGRAM 3
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{0C4982B4-1147-43F8-AFDB-49E8E9FD0B96}] SEQPACKET 4
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip6_{0C4982B4-1147-43F8-AFDB-49E8E9FD0B96}] DATAGRAM 4
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{516B2F50-913D-44BA-A773-6749245C7467}] SEQPACKET 11
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{516B2F50-913D-44BA-A773-6749245C7467}] DATAGRAM 11
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{649717FF-5D56-4BC5-B59A-7CAB7A124583}] SEQPACKET 9
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{649717FF-5D56-4BC5-B59A-7CAB7A124583}] DATAGRAM 9
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{FF275D06-6808-450E-85DF-03463FC60E15}] SEQPACKET 7
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{FF275D06-6808-450E-85DF-03463FC60E15}] DATAGRAM 7
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{3050E54C-D2C9-4C4F-BCDA-B04380738C35}] SEQPACKET 0
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{3050E54C-D2C9-4C4F-BCDA-B04380738C35}] DATAGRAM 0
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{2810EB22-763D-4D0C-9450-64BBD1758685}] SEQPACKET 1
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{2810EB22-763D-4D0C-9450-64BBD1758685}] DATAGRAM 1
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{531D3D38-B38F-4A40-9052-52EFBA55506B}] SEQPACKET 2
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{531D3D38-B38F-4A40-9052-52EFBA55506B}] DATAGRAM 2


**** Blocked Control Panel Items ****

BLOCKED: [ncpa.cpl] No
BLOCKED: [odbccp32.cpl] No


**** Downloaded Program Files ****

{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} [http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab]
{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} [http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab]
{17492023-C23A-453E-A040-C7C580BBF700} [http://download.microsoft.com/download/3/9/8/398422c0-8d3e-40e1-a617-af65a72a0465/LegitCheckControl.cab] C:\WINDOWS\system32\GWFSPidGen.DLL C:\WINDOWS\system32\LegitCheckControl.DLL
{1F2F4C9E-6F09-47BC-970D-3C54734667FE} [https://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab]
{2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} [http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab] C:\WINDOWS\Downloaded Program Files\navapi32.dll C:\WINDOWS\Downloaded Program Files\avsniffdlgs.dll C:\WINDOWS\Downloaded Program Files\avsniff.dll
{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} [http://office.microsoft.com/officeupdate/content/opuc3.cab]
{4F1E5B1A-2A80-42CA-8532-2D05CB959537} [http://spaces.msn.com//PhotoUpload/MsnPUpld.cab]
{5F8469B4-B055-49DD-83F7-62B522420ECC} [http://upload.facebook.com/controls/FacebookPhotoUploader.cab]
{644E432F-49D3-41A1-8DD5-E099162EEEC5} [http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab]
{8AD9C840-044E-11D1-B3E9-00805F499D93} [http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab]
{9600F64D-755F-11D4-A47F-0001023E6D5A} [http://web1.shutterfly.com/downloads/Uploader.cab]
{A30FBBDC-FA29-4606-8565-14AADCCA6708} [https://photos.riteaid.com/control/RiteAidOneHourPhotoOnline.cab]
{B38870E4-7ECB-40DA-8C6A-595F0A5519FF} [http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab]
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} [http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab]
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab]
{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} [https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab]
{D27CDB6E-AE6D-11CF-96B8-444553540000} [http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab]


**** Windows Services ****

[6to4] %SystemRoot%\system32\svchost.exe -k netsvcs
[Alerter] %SystemRoot%\system32\svchost.exe -k LocalService
[ALG] %SystemRoot%\System32\alg.exe
[AppMgmt] %SystemRoot%\system32\svchost.exe -k netsvcs
[aspnet_state] %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
[AudioSrv] %SystemRoot%\System32\svchost.exe -k netsvcs
[BITS] %SystemRoot%\system32\svchost.exe -k netsvcs
[Browser] %SystemRoot%\system32\svchost.exe -k netsvcs
[ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
[ccPwdSvc] "C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe"
[ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
[CiSvc] %SystemRoot%\system32\cisvc.exe
[ClipSrv] %SystemRoot%\system32\clipsrv.exe
[COMSysApp] C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
[CryptSvc] %SystemRoot%\system32\svchost.exe -k netsvcs
[CWShredder Service] C:\Documents and Settings\Grays\Desktop\CWShredder.exe service
[DcomLaunch] %SystemRoot%\system32\svchost -k DcomLaunch
[DefWatch] "C:\Program Files\Symantec AntiVirus\DefWatch.exe"
[Dhcp] %SystemRoot%\system32\svchost.exe -k netsvcs
[dmadmin] %SystemRoot%\System32\dmadmin.exe /com
[dmserver] %SystemRoot%\System32\svchost.exe -k netsvcs
[Dnscache] %SystemRoot%\system32\svchost.exe -k NetworkService
[ERSvc] %SystemRoot%\System32\svchost.exe -k netsvcs
[Eventlog] %SystemRoot%\system32\services.exe
[EventSystem] C:\WINDOWS\system32\svchost.exe -k netsvcs
[ewido anti-spyware 4.0 guard] C:\Program Files\ewido anti-spyware 4.0\guard.exe
[FastUserSwitchingCompatibility] %SystemRoot%\System32\svchost.exe -k netsvcs
[Fax] %systemroot%\system32\fxssvc.exe
[helpsvc] %SystemRoot%\System32\svchost.exe -k netsvcs
[HidServ] %SystemRoot%\System32\svchost.exe -k netsvcs
[HTTPFilter] %SystemRoot%\System32\svchost.exe -k HTTPFilter
[IDriverT] "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"
[ImapiService] C:\WINDOWS\system32\imapi.exe
[iPod Service] "C:\Program Files\iPod\bin\iPodService.exe"
[lanmanserver] %SystemRoot%\system32\svchost.exe -k netsvcs
[lanmanworkstation] %SystemRoot%\system32\svchost.exe -k netsvcs
[LmHosts] %SystemRoot%\system32\svchost.exe -k LocalService
[Messenger] %SystemRoot%\system32\svchost.exe -k netsvcs
[mnmsrvc] C:\WINDOWS\system32\mnmsrvc.exe
[MSDTC] C:\WINDOWS\system32\msdtc.exe
[MSIServer] C:\WINDOWS\system32\msiexec.exe /V
[NetDDE] %SystemRoot%\system32\netdde.exe
[NetDDEdsdm] %SystemRoot%\system32\netdde.exe
[Netlogon] %SystemRoot%\system32\lsass.exe
[Netman] %SystemRoot%\System32\svchost.exe -k netsvcs
[NetSvc] C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
[Nla] %SystemRoot%\system32\svchost.exe -k netsvcs
[NtLmSsp] %SystemRoot%\system32\lsass.exe
[NtmsSvc] %SystemRoot%\system32\svchost.exe -k netsvcs
[NwSapAgent] %SystemRoot%\system32\svchost.exe -k netsvcs
[ose] "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
[PlugPlay] %SystemRoot%\system32\services.exe
[PolicyAgent] %SystemRoot%\system32\lsass.exe
[ProtectedStorage] %SystemRoot%\system32\lsass.exe
[RasAuto] %SystemRoot%\system32\svchost.exe -k netsvcs
[RasMan] %SystemRoot%\system32\svchost.exe -k netsvcs
[RDSessMgr] C:\WINDOWS\system32\sessmgr.exe
[RemoteAccess] %SystemRoot%\system32\svchost.exe -k netsvcs
[RpcLocator] %SystemRoot%\system32\locator.exe
[RpcSs] %SystemRoot%\system32\svchost -k rpcss
[RSVP] %SystemRoot%\system32\rsvp.exe
[SamSs] %SystemRoot%\system32\lsass.exe
[SavRoam] "C:\Program Files\Symantec AntiVirus\SavRoam.exe"
[SCardSvr] %SystemRoot%\System32\SCardSvr.exe
[Schedule] %SystemRoot%\System32\svchost.exe -k netsvcs
[seclogon] %SystemRoot%\System32\svchost.exe -k netsvcs
[SENS] %SystemRoot%\system32\svchost.exe -k netsvcs
[SharedAccess] %SystemRoot%\system32\svchost.exe -k netsvcs
[ShellHWDetection] %SystemRoot%\System32\svchost.exe -k netsvcs
[SNDSrvc] "C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"
[SPBBCSvc] "C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"
[Spooler] %SystemRoot%\system32\spoolsv.exe
[srservice] %SystemRoot%\system32\svchost.exe -k netsvcs
[SSDPSRV] %SystemRoot%\system32\svchost.exe -k LocalService
[stisvc] %SystemRoot%\system32\svchost.exe -k imgsvc
[SwPrv] C:\WINDOWS\system32\dllhost.exe /Processid:{A445BD1E-49EE-4607-B370-5CCA447377C4}
[Symantec AntiVirus] "C:\Program Files\Symantec AntiVirus\Rtvscan.exe"
[SysmonLog] %SystemRoot%\system32\smlogsvc.exe
[TapiSrv] %SystemRoot%\System32\svchost.exe -k netsvcs
[TermService] %SystemRoot%\System32\svchost -k DComLaunch
[Themes] %SystemRoot%\System32\svchost.exe -k netsvcs
[TrkWks] %SystemRoot%\system32\svchost.exe -k netsvcs
[upnphost] %SystemRoot%\system32\svchost.exe -k LocalService
[UPS] %SystemRoot%\System32\ups.exe
[usnsvc] C:\WINDOWS\system32\svchost.exe -k usnsvc
[vsmon] C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe -service
[VSS] %SystemRoot%\System32\vssvc.exe
[w32time] %SystemRoot%\system32\svchost.exe -k netsvcs
[WebClient] %SystemRoot%\system32\svchost.exe -k LocalService
[WinDefend] "C:\Program Files\Windows Defender\MsMpEng.exe"
[winmgmt] %systemroot%\system32\svchost.exe -k netsvcs
[WmdmPmSN] %SystemRoot%\System32\svchost.exe -k netsvcs
[WmiApSrv] C:\WINDOWS\system32\wbem\wmiapsrv.exe
[wscsvc] %SystemRoot%\System32\svchost.exe -k netsvcs
[wuauserv] %systemroot%\system32\svchost.exe -k netsvcs
[WZCSVC] %SystemRoot%\System32\svchost.exe -k netsvcs
[xmlprov] %SystemRoot%\System32\svchost.exe -k netsvcs


**** Custom IE Search Items ****

SEARCH: [SearchAssistant] http://www.google.com/ie
SEARCH: [CustomizeSearch] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
SEARCH: [SearchAssistant] http://www.google.com/ie
SEARCH: [Default_Search_URL] http://www.google.com/ie


**** Complete IE Options ****

IEOPT: [NoUpdateCheck]
IEOPT: [NoJITSetup]
IEOPT: [Disable Script Debugger] yes
IEOPT: [Show_ChannelBand] No
IEOPT: [Anchor Underline] yes
IEOPT: [Cache_Update_Frequency] Once_Per_Session
IEOPT: [Display Inline Images] yes
IEOPT: [Do404Search]
IEOPT: [Save_Session_History_On_Exit] no
IEOPT: [Show_FullURL] no
IEOPT: [Show_StatusBar] yes
IEOPT: [Show_ToolBar] yes
IEOPT: [Show_URLinStatusBar] yes
IEOPT: [Show_URLToolBar] yes
IEOPT: [Start Page] http://www.messengersite.net/forum/portal.htm
IEOPT: [Use_DlgBox_Colors] yes
IEOPT: [Search Page] http://www.google.com
IEOPT: [Default_Page_URL] http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IEOPT: [FullScreen] no
IEOPT: [AutoSearch]
IEOPT: [NotifyDownloadComplete] no
IEOPT: [Search Bar] http://www.google.com/ie
IEOPT: [Error Dlg Displayed On Every Error] no
IEOPT: [Use FormSuggest] no
IEOPT: [Use Search Asst] no
IEOPT: [AddToFavoritesExpanded]
IEOPT: [Error Dlg Details Pane Open]
IEOPT: [Expand Alt Text] no
IEOPT: [Move System Caret] no
IEOPT: [NscSingleExpand]
IEOPT: [DisableScriptDebuggerIE] yes
IEOPT: [NoWebJITSetup]
IEOPT: [Page_Transitions]
IEOPT: [FavIntelliMenus] no
IEOPT: [Enable Browser Extensions] yes
IEOPT: [UseThemes]
IEOPT: [Force Offscreen Composition]
IEOPT: [AllowWindowReuse]
IEOPT: [Friendly http errors] yes
IEOPT: [ShowGoButton] yes
IEOPT: [SmoothScroll]
IEOPT: [Enable AutoImageResize] yes
IEOPT: [Enable_MyPics_Hoverbar] yes
IEOPT: [Play_Animations] yes
IEOPT: [Play_Background_Sounds] yes
IEOPT: [Display Inline Videos] yes
IEOPT: [Show image placeholders]
IEOPT: [Print_Background] no
IEOPT: [FormSuggest PW Ask] no
IEOPT: [Window_Placement] ,
IEOPT: [Use Custom Search URL]
IEOPT: [XMLHTTP]
IEOPT: [UseClearType] yes
IEOPT: [CompatibilityFlags]
IEOPT: [SearchMigrated]
IEOPT: [SearchMigratedDefaultName] Google
IEOPT: [SearchMigratedDefaultURL] http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IEOPT: [SearchMigratedInstalled]
IEOPT: [RunOnceHasShown]
IEOPT: [Secondary Start Pages]
IEOPT: [RunOnceComplete]
IEOPT: [Default_Page_URL] http://go.microsoft.com/fwlink/?LinkId=69157
IEOPT: [Default_Search_URL] http://go.microsoft.com/fwlink/?LinkId=54896
IEOPT: [Search Page] http://go.microsoft.com/fwlink/?LinkId=54896
IEOPT: [Enable_Disk_Cache] yes
IEOPT: [Cache_Percent_of_Disk]
IEOPT: [Delete_Temp_Files_On_Exit] yes
IEOPT: [Anchor_Visitation_Horizon]
IEOPT: [Use_Async_DNS] yes
IEOPT: [Placeholder_Width]
IEOPT: [Placeholder_Height]
IEOPT: [Start Page] http://go.microsoft.com/fwlink/?LinkId=69157
IEOPT: [CompanyName] Microsoft Corporation
IEOPT: [Custom_Key] MICROSO
IEOPT: [Wizard_Version] 6.0.2600.0000
IEOPT: [FullScreen] no
IEOPT: [SearchAssistant] http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IEOPT: [IEWatsonEnabled]
IEOPT: [Search Bar]
IEOPT: [Default_Secondary_Page_URL]
IEOPT: [Extensions Off Page] about:NoAdd-ons
IEOPT: [Local Page] %SystemRoot%\system32\blank.htm
IEOPT: [Security Risk Page] about:SecurityRisk
IEOPT: [Check_Associations] yes
Sorry for the delay :oops:
If you still need help and haven't posted at another forum.

Download and install AVG Anti-Spyware (ewido). Then scan and save the log from the scan.
Instructions and download link can be found here.

Then run this online scan. Save the report.

Rescan with HJT and post a new log with the results from AVG .
Also please describe how your computer behaves at the moment.
This problem has been resolved. I got around the problem of cwshredder internet connection hijacking by using a usb flash drive to download fixes. I thought this thread was closed out.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI