Download LSPfix from
here
On the opening screen, click the "I know what I'm doing" checkbox. Check all instances of "inetadpt.dll" (and nothing else), and move them to the "Remove" pane. Then click Finish.
Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://allaboutsearching.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://allaboutsearching.com/searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = allaboutsearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
www.zestyfind.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://allaboutsearching.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://allaboutsearching.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://allaboutsearching.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant =
http://www.websearch.com/ie.aspx?tb_id=%tb_id
R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\Program Files\TV Media\TvmBho.dll
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O1 - Hosts: 207.36.196.189 auto.search.msn.com
O1 - Hosts: 207.36.196.189 search.netscape.com
O1 - Hosts: 207.36.196.189 ieautosearch
O1 - Hosts: ˜K1˜K1�1�1˜1˜1 1 1¨1¨1°1°1¸1¸1À1À1È1È1�1�1Ø1Ø1�*1�*1è1è1ð1ð1ø1ø1 ˆ1�1�1˜1˜1 1 1¨1¨1°1°1¸1¸1À1À1È1È1�1�1Ø1Ø1�*1�*1è1è1ð1ð1ø1ø1
O1 - Hosts: �1˜1˜1 1 1¨1¨1°1°1¸1¸1À1À1È1È1�1�1Ø1Ø1�*1�*1è1è1ð1ð1ø1ø1
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\twaintec.dll
O2 - BHO: (no name) - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\bxxs5.dll
O2 - BHO: (no name) - {00A0A40C-F432-4C59-BA11-B25D142C7AB7} - C:\WINDOWS\System32\mskceo.dll
O2 - BHO: (no name) - {0982868C-47F0-4EFB-A664-C7B0B1015808} - C:\WINDOWS\System32\mskhhe.dll
O2 - BHO: (no name) - {0BA1C6EB-D062-4E37-9DB5-B07743276324} - C:\WINDOWS\System32\msdaim.dll
O2 - BHO: (no name) - {25F7FA20-3FC3-11D7-B487-00D05990014C} - C:\WINDOWS\System32\mskpkc.dll
O2 - BHO: (no name) - {447160CD-ECF5-4EA2-8A8A-1F70CA363F85} - C:\WINDOWS\System32\msibkd.dll
O2 - BHO: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\Program Files\TV Media\TvmBho.dll
O2 - BHO: (no name) - {94927A13-4AAA-476A-989D-392456427688} - C:\WINDOWS\System32\msjfbl.dll
O2 - BHO: (no name) - {CC916B4B-BE44-4026-A19D-8C74BBD23361} - C:\WINDOWS\System32\msedah.dll
O2 - BHO: (no name) - {FCADDC14-BD46-408A-9842-CDBE1C6D37EB} - C:\WINDOWS\System32\msnkmi.dll
O3 - Toolbar: bits dog live - {2E2674FC-A56C-C54F-B4E1-A1F6E53FEB2D} - C:\PROGRA~1\MOREAN~1\listdelete.dll
O3 - Toolbar: zSearch Bar - {5886A6DC-AAF4-45E9-979A-8E5E6DEE30E7} - C:\Program Files\zSearch\zSearch.dll
O4 - HKLM\..\Run: [bxxs5] RunDLL32.EXE C:\WINDOWS\bxxs5.dll,DllRun
O4 - HKCU\..\Run: [msmc] C:\WINDOWS\System32\msgked.exe
O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm
O9 - Extra button: Sidesearch (HKLM)
O15 - Trusted Zone:
http://ad.searchsquire.com
O15 - Trusted Zone:
http://search.searchsquire.com
O15 - Trusted Zone:
http://update.searchsquire.com
O15 - Trusted Zone:
http://www.searchsquire.com
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} (F1 Organizer Class) -
http://www.addictivetechnologies.ne...ab/emCraft1.cab
O16 - DPF: {10000273-8230-4DD4-BE4F-6889D1E74167} -
http://download.abetterinternet.com...cab?id=58449091
O16 - DPF: {13197ACE-6851-45C3-A7FF-C281324D5489} -
http://www.2nd-thought.com/files/install011.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Fun Web Products Installer Start) -
http://ak.imgfarm.com/images/nocach...etup1.0.0.6.cab
O16 - DPF: {26E8361F-BCE7-4F75-A347-98C88B418322} -
http://download.websearch.com/Dnl/T_50038/QDow.cab
O16 - DPF: {2C38A62E-D257-40E8-8BB7-5624E38FEB0A} -
http://67.72.100.27/dialerhost/down...sexsoftware.cab
O16 - DPF: {907CA0E5-CE84-11D6-9508-02608CDD2846} (Squire Class) -
http://update.searchsquire.com/SearchSquire33.CAB
O16 - DPF: {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} (brdg Class) -
http://www2.flingstone.com/cab/2000XP/CDTInc/bridge.cab
O16 - DPF: {A16E6189-A1DD-4696-9806-0324C145D794} (KeyActivex Control) -
http://www.jraun.com/activex/src/KeyActivexTest.ocx
O16 - DPF: {BB0578ED-E672-4697-9663-EC5A0460B949} (SomaticCAB.Setup) -
http://downloads.searchcentrix.com/install/weblz.CAB
O16 - DPF: {EFB22865-F3BC-4309-ADFA-C8E078A7F762} (SysWebTelecomInt Class) -
http://www.sponsoradulto.com/es/SysWebTelecom.cab
Reboot into safe mode following the instructions
here & navigate to & delete
C:\Program Files\TV Media< this folder
C:\PROGRA~1\MOREAN~1< this folder
C:\Program Files\zSearch< this folder
C:\Program Files\WebSavingsfromEbates< this folder
C:\WINDOWS\bxxs5.dll< this file
C:\WINDOWS\System32\msgked.exe< this file
C:\WINDOWS\svchost.exe< this file WARNING!!!! Do not delete the svchost.exe file from the system32 folder.
Reboot normally.
Can you download the following app & run it, making sure to have one internet exploder window open. Save the log & paste the results back here.
VX2Finder
Next, type
javascript:navigator.userAgent or just copy and paste it in your IE Address bar then hit enter.
Post the log from VX2Finder here along with the results from the address bar.