Hi,
Now reboot into safe mode by tapping your F8 key upon restart and safe mode screen appears, select safe mode and press enter.
While in safe mode disconnect from the internet...pull the plug, wire etc.
Run hijackthis and click on scan button and put checks next to these:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Me\LOCALS~1\Temp\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/...arch.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://uk.red.clientapps.yahoo.com/...arch.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/...arch.yahoo.com/
O4 - HKCU\..\Run: [Task manager] taskmngr.exe
Make sure no other window is open but hijackthis and click on fix checked.
Still in safe mode
Now run AboutBuster as many times as it takes to not find anything.
Then...
Now run CWShredder and click on fix
Hunt for and delete these files/folders:
If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.
taskmngr.exe
Then...
Start Ccleaner and click: Run Cleaner./use windows tab only
Reboot normal mode and go here below to get spybot S&D and Adaware SE if you don't already have them and run scans with both of those. I do not need to see those logs just run the scans.
http://www.d-a-l.com/help/showthread.php?t=32403
After the above give me a new Hijackthis log please.


