Please help,
I have tried everything. My browser is hijacked and I cannot fix it. I have run ad-aware, spybot, and hijackthis. I have run all three of them in regular mode and safe mode. While in safe mode, once removed they don't come back, but when I reboot in regular mode, my homepage is reset along with other settings. Here is my hijack log:
Logfile of HijackThis v1.98.2
Scan saved at 9:26:44 AM, on 9/2/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\PROGRA~1\SYMANT~1\SYMAN
T~1\DefWat
ch.exe
C:\WINDOWS\System32\inetsr
v\inetinfo
.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\mysql\bin\mysqld-nt.exe
C:\PROGRA~1\SYMANT~1\SYMAN
T~1\Rtvsca
n.exe
C:\WINDOWS\System32\snmp.e
xe
C:\Program Files\RealVNC\WinVNC\WinVN
C.exe
C:\Program Files\Common Files\Microsoft Shared\DirectX Extensions\DXDebugService.
exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\khooke
r.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.e
xe
C:\PROGRA~1\SYMANT~1\SYMAN
T~1\vptray
.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.e
xe
C:\Program Files\SpamKiller\SpamKille
r.exe
C:\mysql\bin\winmysqladmin
.exe
C:\WINDOWS\System32\wuaucl
t.exe
C:\WINDOWS\System32\wuaucl
t.exe
C:\HiJackThis\HijackThis.e
xe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://try-this-search.bizR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://try-this-search.bizR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://try-this-search.bizR0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://try-this-search.bizR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://try-this-search.bizR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://try-this-search.biz/ie.htmlR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://try-this-search.biz/ie.htmlR0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://try-this-search.bizR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,First Home Page =
http://try-this-search.bizR0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Local Page =
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,First Home Page =
http://try-this-search.bizR0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Local Page =
http://try-this-search.bizO2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-0
0400523e39
a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
1.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-0
0400523e39
a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooke
r.exe
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.e
xe"
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\RealVNC\WinVNC\WinVN
C.exe" -servicehelper
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMAN
T~1\vptray
.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.e
xe"
O4 - Startup: SpamKiller 2.lnk = C:\Program Files\SpamKiller\SpamKille
r.exe
O4 - Startup: WinMySQLadmin.lnk = C:\mysql\bin\winmysqladmin
.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmse
arch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmca
che.html
O8 - Extra context menu item: Customize Menu &4 - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustom
izeIEMenu.
html
O8 - Extra context menu item: Fill Forms &] - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillFo
rms.html
O8 - Extra context menu item: Save Forms &[ - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePa
ss.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmsi
milar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmtr
ans.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C
5DBF3571F4
6} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillFo
rms.html
O9 - Extra 'Tools' menuitem: Fill Forms &] - {320AF880-6646-11D3-ABEE-C
5DBF3571F4
6} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillFo
rms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C
5DBF3571F4
9} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePa
ss.html
O9 - Extra 'Tools' menuitem: Save Forms &[ - {320AF880-6646-11D3-ABEE-C
5DBF3571F4
9} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePa
ss.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-0
0400523e39
a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowTo
olbar.html
O9 - Extra 'Tools' menuitem: RF Toolbar &2 - {724d43aa-0d85-11d4-9908-0
0400523e39
a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowTo
olbar.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093634755500O17 - HKLM\System\CCS\Services\T
cpip\..\{D
026D9BD-F8
DE-4D0A-9F
B4-2E486EE
07E8B}: NameServer = 89.89.150.3
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-0
0C04F8EC29
4} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O21 - SSODL: eplrr9 - {A3E057A8-65E7-40B5-8FC6-D
7131C2F951
F} - C:\WINDOWS\System32\eplrr9
.dll
I have even tried going in and manually deleting the registry entries. As soon as I do and press f5 to refresh, they are back. I am desperate, can someone please help?????????????
Thanks,
Kendal