I run a load of safety programs, yet it seems evil doers have a way of getting through.

Does my log look suspect to anyone.

I have an issue with

3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) I have 'fixed' this one more than once. It keeps coming back.

Here is my full log...

Thanks for any help!

Is the issue with that one entry the only problem you are experiencing?

Let's take a closer look at that entry.

Navigate to Start --> Run, and enter this command exactly as shown:

cmd /c regedit.exe /e "%userprofile%\DESKTOP\URLSearchHooks.txt" "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks"

Press Enter.

A text file on your Desktop called URLSearchHooks.txt will open; please post the contents of that document.


I have ran my HijackThis report through numerous automated checkers. This is the only one that seems to be of issue, and when I 'fix' it, the item returns a short time later, usually after rebooting or returning from sleep or hibernation.

Please look over the whole Hijack report to see if you notice anything else.

Thank you for your help!

Disable your real-time protection programs before continuing. Also disconnect from the Internet (physically unplug the cable).

First, please back your Registry with ERUNT.

  • Please use the following link and scroll down to ERUNT and download it.
  • For version with the Installer:
    Use the setup program to install ERUNT on your computer
  • For the zipped version:
    Unzip all the files into a folder of your choice.

Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe

Please open Notepad. Copy and paste the following text (starting with REGEDIT4) into the Notepad document.

Navigate to File --> Save As..., and save the file as Fix.reg (make sure the Save As Type is set to All Files).

Save it to your Desktop.


[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]


Now navigate to your Desktop, and double click fix.reg (Click Yes to the prompt)

Restart your computer, run HijackThis, and see if the entry is gone now.


:) Thanks!

Here it is....

Your log looks good to me.

Let's evaluate the security of your computer.

Download my Security Check from here or here.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.


Here it is...

Results of screen317's Security Check version 0.99.0

Windows XP Service Pack 3


Antivirus/Firewall Check:

Windows Firewall Enabled!

AVG Free 8.5

Antivirus up to date!


Anti-malware/Other Utilities Check:


Spyware Doctor 6.0

HijackThis 2.0.2

CCleaner (remove only)

COMODO System Cleaner 1.1.64946.38(32bit)

Java 6 Update 16

Adobe Flash Player 10

Adobe Reader 8.1.4

Out of date Adobe Reader installed!


Process Check:

objlist.exe by Laurent

Ad-Aware AAWService.exe

Ad-Aware AAWTray.exe is disabled!


DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

`````````End of Log```````````

Okay after you do that:

Navigate to Start --> Run, and type Combofix /u in the box that appears. Click OK afterwards. Notice the space between the X and the /u

This uninstalls all of ComboFix's components.

Delete SecurityCheck.

Restart your computer.

It is vital that you have a firewall. The one that comes with Windows XP is not sufficient in that it only checks incoming data. I recommend selecting one of the following free firewalls. Be sure to only install one.




Restart your computer again and let me know how things are running now.


Yikes. I meant to post that to a different user.

Gulp-- I should go find out who. >_<

Navigate to Start --> Control Panel --> Add or Remove Programs, and uninstall the following programs (if present):

Adobe Reader 8.1.4

Restart your computer.

Get the latest version of Adobe Reader.

But I teach on-line and open and close hundreds of files from others through Web/ct and Blackboard portals weekly.
Some of my professors use Blackboard too.. B)

Looks like you're set to go.

Now that your computer seems to be in proper working order, please take the following steps to help prevent reinfection:

1) Download and install Javacool's SpywareBlaster, which will prevent malware from being installed on your computer. A tutorial on it can be found here.

2) Download and install IE-Spyad, which will place over 5000 'bad' sites on your Internet Explorer Restricted List. A tutorial on it can be found here.

3) Go to Windows Update frequently to get all of the latest updates (security or otherwise) for Windows.

4) Make sure your programs are up to date! Older versions may contain security risks. To find out what programs need to be updated, please run Secunia's Software Inspector.

5) WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:

  • Green to go
  • Yellow for caution
  • Red to stop

WOT has an addon available for both Firefox and IE.

6) Be sure to update your Antivirus and Antispyware programs often!

Finally, please also take the time to read Tony Klein's excellent article on: So How Did I Get Infected in the First Place?

Safe surfing,


