Great news! A few things still to do...
1) Please run HijackThis, perform a scan and place a check next to the following items :
O2 - BHO: HomepageBHO - {3e9b951e-6f72-431b-82cf-4a9fbf2f53bc} - C:\WINDOWS\System32\hp48C7.tmp (file missing)
O17 - HKLM\System\CCS\Services\Tcpip\..\{0BAF7226-7D9B-42E4-B9B8-8487894B00CD}: NameServer = 172.3.5.255 193.219.193.191
O17 - HKLM\System\CS1\Services\Tcpip\..\{0BAF7226-7D9B-42E4-B9B8-8487894B00CD}: NameServer = 172.3.5.255 193.219.193.191
O18 - Filter hijack: text/webviewhtml - (no CLSID) - (no file)
O18 - Filter hijack: text/xml - (no CLSID) - (no file)
Then close all other windows & browsers other than HJT and click Fix Checked. Close HJT.
2) Reboot your computer.
3) Launch Notepad :
- Copy/paste the content of the codebox below into a new text file.
- Save it as Options.txt on your Desktop and as type"All Files"
RegSearch Options File
[Search]
text/webviewhtml
text/xml
[Exclude]
[Options]
Filter=KVDLU
4) Download Registry Search.zip by Bobbi Flekman and Save it to your desktop.
- Extract it to your desktop.
- Click on the Registry Search.zip icon on your desktop to open the program.
- Click regsearch.exe to start the program.
- Click on "Import" and Select the file "Options.txt" that you created above.
- Click "OK" and Registry Search will search the Registry and report what it finds. Please be patient - this can take a long time
- Post the results into your next reply.