All these;
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
(obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
(obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
(obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Program%20Files/Internet%20Explorer/teachers.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
(obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
(obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
(obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
(obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
about:blank...;(obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
(obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
(obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
(obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
(obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer,Search =
(obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer,Search =
(obfuscated)
O13 - DefaultPrefix:
O13 -
O13 - WWW. Prefix:
and there may be more here....get rid of these first and see if the problem subsides
the ActiveX controls below allow code to run without you knowing.....
i know that most of all else is OK, however, there may be something in your log that is re-infecting the machine...
TT4U
Notification:
These are just "my" thoughts....and should be carefully measured against other opinions....I try very hard to impart correct info at all times.