I am trying to fix a computer. Everytime I open IE Explorer, I get a home page about:blank with some searh engine built in. I ran ad-aware, spybots&d, and cwshredder all with the latest updates. I've ran this normally and in safe mode. I am relatively certain it is coolwwwsearch, but cwshredder always comes up clean, as does spybot. Ad-aware keeps coming up with the coolwebsearch, even though I clean it. I also have three programs in add/remove I can't get rid of: home search assistant, search extender, and shopping wizard. I don't know if this is related to the same problem, or a different problem all together. Either way, I need help getting rid of them as well.
I ran hijack this as well. Here is the log file
Logfile of HijackThis v1.99.0
Scan saved at 10:54:20 PM, on 1/1/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\PANICW~1\POP-U
P~1\PSFree
.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\Q817606.log:bsr
qx
C:\WINDOWS\System32\wuaucl
t.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\LxrSG2
0s.exe
C:\WINDOWS\System32\LxrCon
fig.exe
C:\Documents and Settings\Owner\My Documents\HijackThis.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://qus10.hpwis.com/R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://srch-qus10.hpwis.com/R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page = res://C:\WINDOWS\system32\
gkolh.dll/
sp.html#37
049
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL = about:blank
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL = res://C:\WINDOWS\system32\
gkolh.dll/
sp.html#37
049
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\
gkolh.dll/
sp.html#37
049
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page = res://C:\WINDOWS\system32\
gkolh.dll/
sp.html#37
049
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant = res://C:\WINDOWS\system32\
gkolh.dll/
sp.html#37
049
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page_bak =
www.google.comR1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: (no name) - {5649FC80-401D-6577-0C0F-E
130C201E57
E} - C:\WINDOWS\ipfc32.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
1.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv
.old
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.
old
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.old
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-40
93-8EE8-61
64457517F0
}\hphupd05
.old
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon
05.old
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.old
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.old" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD
.old
O4 - HKLM\..\Run: [VTTimer] VTTimer.old
O4 - HKLM\..\Run: [LTMSG] LTMSG.old 7
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.old
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.ol
d
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\
drivers\w3
2x86\3\hpz
tsb08.old
O4 - HKLM\..\Run: [tibs3] C:\WINDOWS\System32\tibs3.
old
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-
UP~1\PSFre
e.exe"
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Progra
m\BackWeb-
1940576.ex
e
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmse
arch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmca
che.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1
\OFFICE11\
EXCEL.EXE/
3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmsi
milar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmtr
ans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\WINDOWS\System32\msjava
.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\WINDOWS\System32\msjava
.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MI1933~1\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted IP range: (HKLM)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-2
2031317559
2} (ZoneIntro Class) -
http://zone.msn.com/binFramework/v10/ZIntro.cab32846.cabO23 - Service: Lexar SG20 - Unknown - LxrSG20s.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc3
2.exe
O23 - Service: Network Security Service - Unknown - C:\WINDOWS\sdkyv32.exe (file missing)
I have a copy of ad aware log file too if it is needed. Any help would be great