Below is the HJT log, that I ran right before posting this.

You need to investigate what you see. It is a malware cleaning forum, and there is much more to cleaning malware than just HijackThis. To save changes, click OK . Note that 'unknown' files in the LSP stack will not be fixed by HijackThis, for safety issues. -------------------------------------------------------------------------- O11 - Extra group in IE 'Advanced Options' window

Create a Restore point: Click Start, point to All Programs, point to Accessories, point to System Tools, and then click System Restore.

The below registry key\\values are used: HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\\load HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\\run -------------------------------------------------------------------------- N1, N2, N3, N4 - Netscape/Mozilla Start & Search page What it looks like: N1 - Netscape 4: user_pref("browser.startup.homepage", "www.google.com"); To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there. Remove Links-yahoo.com from Firefox If the Firefox settings such as home page, newtab page and search provider by default have been replaced by the hijacker, then resetting it to the default

You need to clean all web-browser's shortcuts. That should remove the application. O7 - Regedit access restricted by AdministratorWhat it looks like:O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1What to do:Always have HijackThis fix this, unless your system administrator has put this restriction into place.O8 - Extra After reboot cancel scan as it is a quick scan, and pick full scan.

I will be researching the DDS Log that you post and any changes made to the system might interfere with the FIX that I prepare for you.

You can always have HijackThis fix these, unless you knowingly put those lines in your Hosts file. Click "Internet Options" as shown below.

You will however may need to disable your current installed Anti-Virus, how to do so can be read here. Information on A/V control HERE What to do: Most of the time only AOL and Coolwebsearch silently add sites to the Trusted Zone.

Please note that your topic was not intentionally overlooked. Please download GMER from one of the following locations and save it to your desktop:Main Mirror This version will download a randomly named file (Recommended)Zipped Mirror This version will download a

Browser hijack redirection- HJT Log Thanks very much for all the support and help so far Oh yeah, i have flushed my system restore as well now, thought that might be a good precausion.

Local time:10:45 PM Posted 22 January 2010 - 05:57 PM Hi jroberts613,With this type of infection, Backdoor/IRC Bot Trojan, I always recommend a Reformat and Reinstall of the Operating System.

This can be undone manually when we're finished. Scroll down again. The same goes for the 'SearchList' entries. Double click the AdwCleaner desktop icon.

Once it's finished it should reboot your machine. I then ran MBAM in Safe Mode and it found a Rootkit which Avast then jumped up and claimed to have found first and removed. For the 'NameServer' (DNS servers) entries, Google for the IP or IPs and it will be easy to see if they are good or bad.O18 - Extra protocols and protocol hijackersWhat

The standard registry backup options that come with Windows back up most of the registry but not all of it. Really appreciate the help and all the hard work you guys are doing for the community I have followed the instructions and attached the log Let me know what you think I should do in this situation

scanning hidden files ... Adaware was completely clean and spybot came up with around ten tracking cookies. Many thanks for all your help

It just gets redirected to silly entertainment and advertizing pages. When installed and updated, the Anti-malware will automatically scan and detect all threats present on the PC.