Hi all,
I've been trying to clean up a customers PC for over a day now. I've run many different cleaners and the IE still keeps getting hijacked. The latest hijackthis is below. AVG found download.agent.6 which I deleted, but I"ve deleted it before and it still keeps coming up. I know there is a hidden critter that keeps causing this. Please help!!! I need quick response as Ineed to get this pc back to my customer this morning! I thought I finally got it clean when I went to sleep last night, only to find this this morning...
Hijackthis log:
Logfile of HijackThis v1.97.7
Scan saved at 7:19:52 AM, on 1/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\LEXBCE
S.EXE
C:\WINDOWS\system32\spools
v.exe
C:\PROGRA~1\Grisoft\AVGFRE
~1\avgamsv
r.exe
C:\PROGRA~1\Grisoft\AVGFRE
~1\avgupsv
c.exe
C:\WINDOWS\System32\CTsvcC
DA.EXE
C:\PROGRAM FILES\Lexmark\NetPnP\LexPn
PAgent.exe
C:\WINDOWS\SYSTEM32\lexmvs
ervice.exe
C:\WINDOWS\SYSTEM32\LexWeb
Service.ex
e
C:\WINDOWS\System32\MsPMSP
Sv.exe
C:\WINDOWS\system32\apicq3
2.exe
C:\PROGRAM FILES\Lexmark\NetPnP\LexPn
PDef.exe
C:\WINDOWS\system32\devldr
32.exe
C:\Program Files\Handspring\HOTSYNC.E
XE
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Grisoft\AVG Free\avgcc.exe
C:\Documents and Settings\Jim Remley\Desktop\Wizard\Hija
ckThis.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar = res://C:\WINDOWS\kohwd.dll
/sp.html#3
7049
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page = res://C:\WINDOWS\kohwd.dll
/sp.html#3
7049
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant = res://C:\WINDOWS\kohwd.dll
/sp.html#3
7049
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar = res://C:\WINDOWS\kohwd.dll
/sp.html#3
7049
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page = res://C:\WINDOWS\kohwd.dll
/sp.html#3
7049
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL = about:blank
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL = res://C:\WINDOWS\kohwd.dll
/sp.html#3
7049
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant = res://C:\WINDOWS\kohwd.dll
/sp.html#3
7049
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: (no name) - {1168F197-9125-6D52-2D9D-C
BCE51B1F23
0} - C:\WINDOWS\mszl32.dll
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\b
in\DAMon.e
xe
O4 - HKLM\..\Run: [PnPDef] C:\PROGRAM FILES\Lexmark\NetPnP\LexPn
PDef.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE
~1\avgcc.e
xe /STARTUP
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc
.exe -startgui
O4 - HKLM\..\Run: [sdkrt32.exe] C:\WINDOWS\sdkrt32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Handspring\HOTSYNC.E
XE
O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.
dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O15 - Trusted Zone: *.frame.crazywinnings.com
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-C
C0A30F9028
C} -
http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-0
0608CEC297
C} -
http://download.weatherbug.com/minibug/tricklers/AWS/minibuginstaller.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-4
7A8489BB47
F} -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37792.5901388889O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabIve cleaned using hijack this, and the search bars keep reappearing as well as the trusted zone. I've run the following to clean:
ad-aware
spybot
noadaware
about buster
cwshredder
stinger
After I clean, (I've dont this in both safe mode and normal mode), IE main page keeps getting changed to about: blank. THIS IS DRIVING ME NUTS!!! PLEASE HELP QUICKLY!
Mb