I've searched the web high and low, tried instructions found at EE like this:
http://www.experts-exchange.com/Security/Q_21135323.html?query=about+blank&clearTAFilter=trueBut still no luck.
I'll post my hijackthis log below, but first I wanted to post that there are two things that keep showing up in Spybot -- DSO Exploit and CoolWWWSearch.googlems:
DSO Exploit: Data source object exploit (Registry change, nothing done)
HKEY_USERS\S-1-5-18\Softwa
re\Microso
ft\Windows
\CurrentVe
rsion\Inte
rnet Settings\Zones\0\1004!=W=3
DSO Exploit: Data source object exploit (Registry change, nothing done)
HKEY_USERS\S-1-5-21-170853
7768-15204
9171-13430
24091-1003
\Software\
Microsoft\
Windows\Cu
rrentVersi
on\Interne
t Settings\Zones\0\1004!=W=3
DSO Exploit: Data source object exploit (Registry change, nothing done)
HKEY_USERS\S-1-5-20\Softwa
re\Microso
ft\Windows
\CurrentVe
rsion\Inte
rnet Settings\Zones\0\1004!=W=3
DSO Exploit: Data source object exploit (Registry change, nothing done)
HKEY_USERS\S-1-5-19\Softwa
re\Microso
ft\Windows
\CurrentVe
rsion\Inte
rnet Settings\Zones\0\1004!=W=3
DSO Exploit: Data source object exploit (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Softwa
re\Microso
ft\Windows
\CurrentVe
rsion\Inte
rnet Settings\Zones\0\1004!=W=3
Here's my hijack this log (by the way, I've posted it at
http://www.hijackthis.de/index.php?langselect=english several times, fixed what it tells me to, but then the cycle repeats itself):
Logfile of HijackThis v1.98.2
Scan saved at 10:20:59 AM, on 12/11/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\System32\Ati2ev
xx.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\System32\inetsr
v\inetinfo
.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\MICROS~3\MSSQL
\binn\sqls
ervr.exe
C:\WINDOWS\System32\tcpsvc
s.exe
C:\WINDOWS\System32\snmp.e
xe
C:\WINDOWS\system32\rundll
32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_05\bi
n\jusched.
exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\WINDOWS\System32\umaeli
b.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\SYSfit.exe
C:\WINDOWS\System32\vbstls
.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlma
ngr.exe
C:\WINDOWS\System32\wuaucl
t.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\notepa
d.exe
C:\WINDOWS\system32\notepa
d.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepa
d.exe
C:\hijackthis\hijackthis\H
ijackThis.
exe
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O1 - Hosts: earch
O1 - Hosts: earch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bi
n\jusched.
exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentr
y.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [tibs3] C:\WINDOWS\System32\tibs3.
exe
O4 - HKLM\..\Run: [575h3qj] umaelib.exe
O4 - HKLM\..\Run: [Windows ControlAd] C:\Program Files\Windows ControlAd\WinCtlAd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [SYSfit] C:\WINDOWS\SYSfit.exe
O4 - HKCU\..\Run: [KwunRkH9e] vbstls.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlma
ngr.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
0B0D0A1DE4
5} - C:\PROGRA~1\AIM\aim.exe
O15 - Trusted Zone: *.frame.crazywinnings.com
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-0
0C04F8EC29
4} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
I'd give 2000 points for this if it would let me. Thanks for any help.