Hi
With all browsers closed, run Hijackthis then tick and fix the below entries:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customi...ch/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customi....yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customi....yahoo.com]
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [loads.exe] C:\WINDOWS\medload.exe
Now reboot into Safe Mode then navigate to and delete the following:
C:\WINDOWS\medload.exe <Show hidden files and folders first.
Clear out your Temporary Internet Files, and everything in C:\Documents and Settings\Username\Local Settings\Temp but not the folder itself.
Empty your recycle bin, then reboot into normal mode.
I couldnt find any info on the below:
O4 - HKLM\..\Run: [jyfxhy] C:\WINDOWS\adncerk.exe
O4 - HKLM\..\Run: [suoo] C:\WINDOWS\oelfdydil.exe
Navigate to and right click on each of the below files and select properties, in the version tab you may find some information about where it came from.
adncerk.exe and oelfdydil.exe
Also have those files scanned by
Kaspersky , if they are infected then you can delete the files, also fix those lines in Hijackthis.
Post back a new log.